CVE-2018-1046
published 2018-07-16CVE-2018-1046: pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS Authoritative, replaying a specially…
PriorityP434high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.41%
69.7th percentile
pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS Authoritative, replaying a specially crafted PCAP file can trigger a stack-based buffer overflow, leading to a crash and potentially arbitrary code execution. This buffer overflow only occurs when the -ecs-stamp option of dnsreplay is used.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pdns | < pdns 4.1.2-1 (bookworm) | pdns 4.1.2-1 (bookworm) |
| open-xchange | pdns | >= 0 < 4.1.2-1 | 4.1.2-1 |
| open-xchange | pdns | >= 0 < 4.1.2-1 | 4.1.2-1 |
| open-xchange | pdns | >= 0 < 4.1.2-1 | 4.1.2-1 |
| open-xchange | pdns | >= 0 < 4.1.2-1 | 4.1.2-1 |
| open-xchange | pdns | >= 0 < 4.0.0~alpha2-3ubuntu0.1~esm1 | 4.0.0~alpha2-3ubuntu0.1~esm1 |
| open-xchange | pdns | >= 0 < 4.1.1-1ubuntu0.1~esm1 | 4.1.1-1ubuntu0.1~esm1 |
| open-xchange | pdns | >= 0 < 4.2.1-1ubuntu0.1~esm1 | 4.2.1-1ubuntu0.1~esm1 |
| open-xchange | pdns | >= 0 < 4.5.3-1ubuntu0.1~esm1 | 4.5.3-1ubuntu0.1~esm1 |
| powerdns | pdns | < 4.1.2 | 4.1.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PowerDNS vulnerabilities
vendor_ubuntu·2025-01-14·CVSS 7.8
CVE-2018-1046 [HIGH] PowerDNS vulnerabilities
Title: PowerDNS vulnerabilities
Summary: Several security issues were fixed in PowerDNS.
Wei Hao discovered that PowerDNS Authoritative Server incorrectly handled
memory when accessing certain files. An attacker could possibly use this
issue to achieve arbitrary code execution. (CVE-2018-1046)
It was discovered that PowerDNS Authoritative Server and PowerDNS Recursor
incorrectly handled memory when receiving certain remote input. An attacker
could possibly use this issue to cause denial of service. (CVE-2018-10851)
Kees Monshouwer discovered that PowerDNS Authoritative Server and PowerDNS
Recursor incorrectly handled request validation after having cached
malformed input. An attacker could possibly use this issue to cause denial
of service. (CVE-2018-14626)
Toshifumi Sakaguchi discove
Debian
CVE-2018-1046: pdns - pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In th...
vendor_debian·2018·CVSS 7.8
CVE-2018-1046 [HIGH] CVE-2018-1046: pdns - pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In th...
pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS Authoritative, replaying a specially crafted PCAP file can trigger a stack-based buffer overflow, leading to a crash and potentially arbitrary code execution. This buffer overflow only occurs when the -ecs-stamp option of dnsreplay is used.
Scope: local
bookworm: resolved (fixed in 4.1.2-1)
bullseye: resolved (fixed in 4.1.2-1)
forky: resolved (fixed in 4.1.2-1)
sid: resolved (fixed in 4.1.2-1)
trixie: resolved (fixed in 4.1.2-1)
OSV
pdns, pdns-recursor vulnerabilities
osv·2025-01-14·CVSS 7.8
CVE-2018-1046 [HIGH] pdns, pdns-recursor vulnerabilities
pdns, pdns-recursor vulnerabilities
Wei Hao discovered that PowerDNS Authoritative Server incorrectly handled
memory when accessing certain files. An attacker could possibly use this
issue to achieve arbitrary code execution. (CVE-2018-1046)
It was discovered that PowerDNS Authoritative Server and PowerDNS Recursor
incorrectly handled memory when receiving certain remote input. An attacker
could possibly use this issue to cause denial of service. (CVE-2018-10851)
Kees Monshouwer discovered that PowerDNS Authoritative Server and PowerDNS
Recursor incorrectly handled request validation after having cached
malformed input. An attacker could possibly use this issue to cause denial
of service. (CVE-2018-14626)
Toshifumi Sakaguchi discovered that PowerDNS Recursor incorrectly handled
request
GHSA
GHSA-622f-mfw7-jxg6: pdns before version 4
ghsa_unreviewed·2022-05-13
CVE-2018-1046 [HIGH] CWE-787 GHSA-622f-mfw7-jxg6: pdns before version 4
pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS Authoritative, replaying a specially crafted PCAP file can trigger a stack-based buffer overflow, leading to a crash and potentially arbitrary code execution. This buffer overflow only occurs when the -ecs-stamp option of dnsreplay is used.
OSV
CVE-2018-1046: pdns before version 4
osv·2018-07-16·CVSS 7.8
CVE-2018-1046 [HIGH] CVE-2018-1046: pdns before version 4
pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS Authoritative, replaying a specially crafted PCAP file can trigger a stack-based buffer overflow, leading to a crash and potentially arbitrary code execution. This buffer overflow only occurs when the -ecs-stamp option of dnsreplay is used.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-14320 podofo: Lack of proper validation of user supplied data can result in information disclosure
bugzilla·2018-09-20·CVSS 6.5
CVE-2018-14320 [MEDIUM] CVE-2018-14320 podofo: Lack of proper validation of user supplied data can result in information disclosure
CVE-2018-14320 podofo: Lack of proper validation of user supplied data can result in information disclosure
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo Library. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within PdfEncoding::ParseToUnicode(). The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition.
References:
https://www.zerodayinitiative.com/advisories/ZDI-18-1046/
Discussion:
Created podofo tracking bugs for this issue:
Affects: epel-all [bug 1631431]
Affects: fedora-all [bug 1631430]
---
This CVE Bugzilla entry is for community
Bugzilla
CVE-2018-1046 pdns: Buffer overflow in dnsreplay [fedora-all]
bugzilla·2018-05-17·CVSS 7.8
CVE-2018-1046 [HIGH] CVE-2018-1046 pdns: Buffer overflow in dnsreplay [fedora-all]
CVE-2018-1046 pdns: Buffer overflow in dnsreplay [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whil
Bugzilla
CVE-2018-1046 pdns: Buffer overflow in dnsreplay
bugzilla·2018-05-17·CVSS 7.8
CVE-2018-1046 [HIGH] CVE-2018-1046 pdns: Buffer overflow in dnsreplay
CVE-2018-1046 pdns: Buffer overflow in dnsreplay
An issue has been found in the dnsreplay tool provided with PowerDNS Authoritative, where replaying a specially crafted PCAP file can trigger a stack-based buffer overflow, leading to a crash and potentially arbitrary code execution. This buffer overflow only occurs when the –ecs-stamp option of dnsreplay is used.
Affects: dnsreplay from 4.0.0 up to and including 4.1.1
Upstream patch:
https://github.com/PowerDNS/pdns/commit/f9c57c98da1b1007a51680629b667d57d9b702b8
Reference:
https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2018-02.html
Discussion:
Created pdns tracking bugs for this issue:
Affects: fedora-all [bug 1579272]
2018-07-16
Published