Jump to content

Advisories MDKSA-2007:146: Updated perl-Net-DNS packages fix multiple vulnerabilities


paul
 Share

Recommended Posts

A flaw was discovered in the perl Net::DNS module in the way it

generated the ID field in a DNS query. Because it is so predictable,

a remote attacker could exploit this to return invalid DNS data

(CVE-2007-3377).

 

A denial of service vulnerability was found in how Net::DNS parsed

certain DNS requests. A malformed response to a DNS request could

cause the application using Net::DNS to crash or stop responding

(CVE-2007-3409).

 

The updated packages have been patched to prevent these issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...