CVE-2019-10162: Opensuse Leap

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while looking up the NS/A/AAAA records it is about to use for an outgoing notify.

Affected products

  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Powerdns Authoritative: from 4.0.0, before 4.0.8 (fixed in 4.0.8); from 4.1.0, before 4.1.10 (fixed in 4.1.10); version 4.0.0 only

Published 2019-07-30. Last modified 2026-06-17.