CVE-2018-1046: Buffer Overflow
Last updated 14 January 2025
Other sources
pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS Authoritative, replaying a specially crafted PCAP file can trigger a stack-based buffer overflow, leading to a crash and potentially arbitrary code execution. This buffer overflow only occurs when the -ecs-stamp option of dnsreplay is used.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-1046?
CVE-2018-1046 is a vulnerability in pdns before version 4.1.2 that allows for a buffer overflow in dnsreplay.
How does CVE-2018-1046 impact PowerDNS?
CVE-2018-1046 can lead to a stack-based buffer overflow in the dnsreplay tool provided with PowerDNS, resulting in a crash and potentially arbitrary code execution.
What software versions are affected by CVE-2018-1046?
Software versions of PowerDNS (pdns) up to but excluding version 4.1.2 are affected by CVE-2018-1046.
What is the severity rating of CVE-2018-1046?
CVE-2018-1046 has a severity rating of 7.8 (Critical).
How can CVE-2018-1046 be fixed?
To fix CVE-2018-1046, upgrade PowerDNS (pdns) to version 4.1.2 or later.