Resource exhaustion - CVE-2019-10163

 

Resource exhaustion - CVE-2019-10163

Published: July 31, 2019 / Updated: August 4, 2020


Vulnerability identifier: #VU33441
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10163
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to perform service disruption.

A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.


Affected software

pdns (Alpine package)
SUSE Package Hub for SUSE Linux Enterprise
Opensuse
SUSE Linux

How to mitigate CVE-2019-10163

Install update from vendor's website.

pdns (Alpine package) - addressed in versions 4.0.8-r0, 4.1.10-r0

External References

Related Security Bulletins