First published: Mon Jul 16 2018(Updated: )
pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS Authoritative, replaying a specially crafted PCAP file can trigger a stack-based buffer overflow, leading to a crash and potentially arbitrary code execution. This buffer overflow only occurs when the -ecs-stamp option of dnsreplay is used.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Powerdns Pdns | <4.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1046 is a vulnerability in pdns before version 4.1.2 that allows for a buffer overflow in dnsreplay.
CVE-2018-1046 can lead to a stack-based buffer overflow in the dnsreplay tool provided with PowerDNS, resulting in a crash and potentially arbitrary code execution.
Software versions of PowerDNS (pdns) up to but excluding version 4.1.2 are affected by CVE-2018-1046.
CVE-2018-1046 has a severity rating of 7.8 (Critical).
To fix CVE-2018-1046, upgrade PowerDNS (pdns) to version 4.1.2 or later.