{"id":"CVE-2019-10162","details":"A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while looking up the NS/A/AAAA records it is about to use for an outgoing notify.","modified":"2026-08-07T11:31:04.053243044Z","published":"2019-07-30T23:15:12.183Z","related":["openSUSE-SU-2019:1904-1","openSUSE-SU-2019:1921-1","openSUSE-SU-2024:11156-1"],"database_specific":{"unresolved_ranges":[{"vendor_product":"opensuse:leap","cpes":["cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*","cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"15.0"},{"last_affected":"15.0"},{"introduced":"15.1"},{"last_affected":"15.1"}],"source":"CPE_STRING"}]},"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00036.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00054.html"},{"type":"ADVISORY","url":"https://blog.powerdns.com/2019/06/21/powerdns-authoritative-server-4-0-8-and-4-1-10-released/"},{"type":"ADVISORY","url":"https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2019-04.html"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10162"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/powerdns/pdns","events":[{"introduced":"ba64cecd417688dc39c75e92f1a23b91f7f46d64"},{"fixed":"fdd1fca63fc4949984b501ed1bca8fa01a23fc61"},{"last_affected":"ba64cecd417688dc39c75e92f1a23b91f7f46d64"},{"introduced":"80da1b4773cbdad76755b01c70739059d6f607af"},{"fixed":"4dcb0559597b774839fbf148abe27300ef49578d"}],"database_specific":{"cpe":["cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*","cpe:2.3:a:powerdns:authoritative:4.0.0:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.0.8"},{"introduced":"4.0.0-NA"},{"last_affected":"4.0.0-NA"},{"introduced":"4.1.0"},{"fixed":"4.1.10"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["rec-4.1.9","rec-4.1.8","rec-4.1.7","rec-4.1.6","rec-4.1.5","rec-4.1.4","rec-4.1.3","rec-4.1.2","rec-4.1.1","rec-4.1.0","rec-4.0.7","rec-4.0.6","rec-4.0.5","rec-4.0.5-rc2","rec-4.0.5-rc1","rec-4.0.4","rec-4.0.3","dnsdist-1.1.0-beta1","rec-4.0.2","rec-4.0.1","auth-4.0.1","rec-4.0.0","auth-4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10162.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}