pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS Authoritative, replaying a specially crafted PCAP file can trigger a stack-based buffer overflow, leading to a crash and potentially arbitrary code execution. This buffer overflow only occurs when the -ecs-stamp option of dnsreplay is used.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 16, 2018 |
| Debian | — | Upgrade pdns | Jul 30, 2024 | Jul 16, 2018 |
| Suse | — | Upgrade pdns-backend-godbcUpgrade pdns-backend-ldapUpgrade pdns-backend-luaUpgrade pdnsUpgrade pdns-backend-mydnsUpgrade pdns-backend-sqlite3Upgrade pdns-backend-postgresqlUpgrade pdns-backend-mysqlUpgrade pdns-backend-geoipUpgrade pdns-backend-remote | May 24, 2018 | May 24, 2018 |
| Ubuntu | — | Upgrade pdns-server (Ubuntu Pro)Upgrade pdns-recursor (Ubuntu Pro)Upgrade pdns-tools (Ubuntu Pro) | Jan 15, 2025 | Jul 16, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub