SB2019112226 - Resource exhaustion in PowerDNS 



SB2019112226 - Resource exhaustion in PowerDNS

Published: November 22, 2019 Updated: July 28, 2020

Security Bulletin ID SB2019112226
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource exhaustion (CVE-ID: CVE-2019-10203)

The vulnerability allows a remote authenticated user to perform service disruption.

PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a serial between 2^31 and 2^32-1 while trying to notify a slave leads to DoS.


Remediation

Install update from vendor's website.