High severity7.5NVD Advisory· Published Jul 30, 2019· Updated Jun 17, 2026
CVE-2019-10162
CVE-2019-10162
Description
A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while looking up the NS/A/AAAA records it is about to use for an outgoing notify.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12- Range: <4.1.10, <4.0.8
cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*range: >=4.0.0,<4.0.8
- cpe:2.3:a:powerdns:authoritative:4.0.0:-:*:*:*:*:*:*
- osv-coords6 versionspkg:rpm/suse/pdns&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/opensuse/pdns&distro=openSUSE%20Tumbleweedpkg:rpm/suse/pdns&distro=SUSE%20Package%20Hub%2012%20SP1pkg:rpm/suse/pdns&distro=SUSE%20Package%20Hub%2015pkg:rpm/opensuse/pdns&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/pdns&distro=openSUSE%20Leap%2015.1
< 4.1.8-bp151.3.3.1+ 5 more
- (no CPE)range: < 4.1.8-bp151.3.3.1
- (no CPE)range: < 4.5.1-1.5
- (no CPE)range: < 4.1.2-bp150.2.9.1
- (no CPE)range: < 4.1.2-bp150.2.9.1
- (no CPE)range: < 4.1.2-bp150.2.9.1
- (no CPE)range: < 4.1.2-bp150.2.9.1
Patches
Vulnerability mechanics
References
5- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-08/msg00036.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-08/msg00054.htmlnvdMailing ListThird Party Advisory
- blog.powerdns.com/2019/06/21/powerdns-authoritative-server-4-0-8-and-4-1-10-released/nvdRelease NotesVendor Advisory
- doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2019-04.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.