Resource exhaustion in PowerDNS - CVE-2019-10203
Published: November 22, 2019 / Updated: July 28, 2020
Vulnerability identifier: #VU32013
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10203
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to perform service disruption.
PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a serial between 2^31 and 2^32-1 while trying to notify a slave leads to DoS.
Affected software
PowerDNS
pdns (Alpine package)
SUSE Package Hub for SUSE Linux Enterprise
SUSE Linux
Opensuse
pdns (Alpine package)
SUSE Package Hub for SUSE Linux Enterprise
SUSE Linux
Opensuse
How to mitigate CVE-2019-10203
Install update from vendor's website.
PowerDNS - addressed in versions 4.0.9, 4.1.11
pdns (Alpine package) - update to 4.1.11-r0
pdns (Alpine package) - update to 4.1.11-r0