CVE-2019-10162: Opensuse Leap
High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.
A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while looking up the NS/A/AAAA records it is about to use for an outgoing notify.
Affected products
- Opensuse Leap: version 15.0 only; version 15.1 only
- Powerdns Authoritative: from 4.0.0, before 4.0.8 (fixed in 4.0.8); from 4.1.0, before 4.1.10 (fixed in 4.1.10); version 4.0.0 only
Published 2019-07-30. Last modified 2026-06-17.