CVE-2019-10163: Opensuse Backports
Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.
A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.
Affected products
- Opensuse Backports: version sle-15 only
- Opensuse Leap: version 15.0 only; version 15.1 only
- Powerdns Authoritative: from 4.0.0, before 4.0.8 (fixed in 4.0.8); from 4.1.0, before 4.1.9 (fixed in 4.1.9); version 4.1.0 only
Published 2019-07-30. Last modified 2026-06-17.