A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "pdns-backend-geoip": "4.1.6-3build1", "pdns-backend-pgsql": "4.1.6-3build1", "pdns-backend-pipe": "4.1.6-3build1", "pdns-backend-sqlite3-dbgsym": "4.1.6-3build1", "pdns-backend-opendbx-dbgsym": "4.1.6-3build1", "pdns-server": "4.1.6-3build1", "pdns-backend-odbc": "4.1.6-3build1", "pdns-backend-lua-dbgsym": "4.1.6-3build1", "pdns-server-dbgsym": "4.1.6-3build1", "pdns-backend-mysql-dbgsym": "4.1.6-3build1", "pdns-backend-opendbx": "4.1.6-3build1", "pdns-backend-sqlite3": "4.1.6-3build1", "pdns-backend-pipe-dbgsym": "4.1.6-3build1", "pdns-backend-pgsql-dbgsym": "4.1.6-3build1", "pdns-backend-remote": "4.1.6-3build1", "pdns-backend-tinydns-dbgsym": "4.1.6-3build1", "pdns-backend-ldap": "4.1.6-3build1", "pdns-backend-odbc-dbgsym": "4.1.6-3build1", "pdns-backend-bind-dbgsym": "4.1.6-3build1", "pdns-tools-dbgsym": "4.1.6-3build1", "pdns-backend-lua": "4.1.6-3build1", "pdns-backend-tinydns": "4.1.6-3build1", "pdns-backend-geoip-dbgsym": "4.1.6-3build1", "pdns-backend-mydns-dbgsym": "4.1.6-3build1", "pdns-backend-remote-dbgsym": "4.1.6-3build1", "pdns-backend-ldap-dbgsym": "4.1.6-3build1", "pdns-backend-mysql": "4.1.6-3build1", "pdns-backend-mydns": "4.1.6-3build1", "pdns-tools": "4.1.6-3build1", "pdns-backend-bind": "4.1.6-3build1" } ] }