View | Details | Raw Unified | Return to bug 238705 | Differences between
and this patch

Collapse All | Expand All

(-)vuln.xml (+33 lines)
Lines 58-63 Link Here
58
  * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
58
  * Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
59
-->
59
-->
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
61
  <vuln vid="1c21f6a3-9415-11e9-95ec-6805ca2fa271">
62
    <topic>powerdns -- multiple vulnerabilities</topic>
63
    <affects>
64
      <package>
65
	<name>powerdns</name>
66
	<range><lt>4.1.10</lt></range>
67
      </package>
68
    </affects>
69
    <description>
70
      <body xmlns="http://www.w3.org/1999/xhtml">
71
	<p>PowerDNS Team reports:</p>
72
	<blockquote cite="https://doc.powerdns.com/authoritative/changelog/4.1.html#change-4.1.10">
73
	  <p>CVE-2019-10162: An issue has been found in PowerDNS Authoritative Server allowing an authorized user to
74
	   cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The
75
	   issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while
76
	   looking up the NS/A/AAAA records it is about to use for an outgoing notify.</p>
77
	  <p>CVE-2019-10163: An issue has been found in PowerDNS Authoritative Server allowing a remote, authorized
78
	   master server to cause a high CPU load or even prevent any further updates to any slave zone by sending
79
	   a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.</p>
80
	</blockquote>
81
      </body>
82
    </description>
83
    <references>
84
      <url>https://doc.powerdns.com/authoritative/changelog/4.1.html#change-4.1.10</url>
85
      <cvename>CVE-2019-10162</cvename>
86
      <cvename>CVE-2019-10163</cvename>
87
    </references>
88
    <dates>
89
      <discovery>2019-06-21</discovery>
90
      <entry>2019-06-21</entry>
91
    </dates>
92
  </vuln>
93
61
  <vuln vid="5b218581-9372-11e9-8fc4-5404a68ad561">
94
  <vuln vid="5b218581-9372-11e9-8fc4-5404a68ad561">
62
    <topic>vlc -- Double free in Matroska demuxer</topic>
95
    <topic>vlc -- Double free in Matroska demuxer</topic>
63
    <affects>
96
    <affects>

Return to bug 238705