CVE Vulnerabilities

CVE-2019-10203

Incorrect Conversion between Numeric Types

Published: Nov 22, 2019 | Modified: Nov 30, 2022
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a serial between 2^31 and 2^32-1 while trying to notify a slave leads to DoS.

Weakness

When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.

Affected Software

Name Vendor Start Version End Version
Authoritative_server Powerdns 4.0.0 (including) 4.0.9 (excluding)
Authoritative_server Powerdns 4.1.0 (including) 4.1.11 (excluding)
Pdns Ubuntu bionic *
Pdns Ubuntu disco *
Pdns Ubuntu eoan *
Pdns Ubuntu esm-apps/bionic *
Pdns Ubuntu esm-apps/xenial *
Pdns Ubuntu trusty *
Pdns Ubuntu xenial *

Potential Mitigations

References