CVE-2019-10163: Medium severity powerdns vulnerability
A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this PowerDNS Authoritative Server vulnerability?
The vulnerability ID is CVE-2019-10163.
What is the severity of CVE-2019-10163?
The severity of CVE-2019-10163 is medium with a severity score of 4.3.
How does CVE-2019-10163 impact PowerDNS Authoritative Server?
CVE-2019-10163 allows a remote, authorized master server to cause a high CPU load or prevent further updates to any slave zone by sending a large number of NOTIFY messages.
Which versions of PowerDNS Authoritative Server are affected by CVE-2019-10163?
PowerDNS Authoritative Server versions 4.0.0 to 4.0.8 and versions 4.1.0 to 4.1.9 are affected by CVE-2019-10163.
How can I fix CVE-2019-10163 in PowerDNS Authoritative Server?
To fix CVE-2019-10163, upgrade PowerDNS Authoritative Server to version 4.1.9 if using versions 4.1.0 to 4.1.8, or upgrade to version 4.0.9 if using versions 4.0.0 to 4.0.8.