A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.
2019-07-30T23:15:12.263
2024-11-21T04:18:33.233
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | powerdns | authoritative | < 4.0.8 | Yes |
| Application | powerdns | authoritative | < 4.1.9 | Yes |
| Application | powerdns | authoritative | 4.1.0 | Yes |
| Operating System | opensuse | backports | sle-15 | Yes |
| Operating System | opensuse | backports | sle-15 | Yes |
| Operating System | opensuse | leap | 15.0 | Yes |
| Operating System | opensuse | leap | 15.1 | Yes |