Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10163

Опубликовано: 30 июл. 2019
Источник: nvd
CVSS3: 3.5
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.8 (исключая)
cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*
Версия от 4.1.0 (включая) до 4.1.9 (исключая)
cpe:2.3:a:powerdns:authoritative:4.1.0:-:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:opensuse:backports:sle-15:-:*:*:*:*:*:*
cpe:2.3:o:opensuse:backports:sle-15:sp1:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

EPSS

Процентиль: 0%
0.00008
Низкий

3.5 Low

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-770
CWE-770

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 6 лет назад

A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.

CVSS3: 4.3
debian
больше 6 лет назад

A Vulnerability has been found in PowerDNS Authoritative Server before ...

CVSS3: 4.3
github
больше 3 лет назад

A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.

CVSS3: 4.3
fstec
почти 7 лет назад

Уязвимость DNS-сервера PowerDNS, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
около 6 лет назад

Security update for pdns

EPSS

Процентиль: 0%
0.00008
Низкий

3.5 Low

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-770
CWE-770