Bug 245458 - A new version of perl(Net::DNS) is available, which fixes potential security problems
Summary: A new version of perl(Net::DNS) is available, which fixes potential security ...
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: perl-Net-DNS   
(Show other bugs)
Version: rawhide
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Robin Norwood
QA Contact: Fedora Extras Quality Assurance
URL: http://search.cpan.org/~olaf/Net-DNS-...
Whiteboard:
Keywords:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-06-23 15:49 UTC by Robin Norwood
Modified: 2007-11-30 22:12 UTC (History)
1 user (show)

Fixed In Version: 0.60-1.fc7
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2007-06-25 23:27:20 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

Description Robin Norwood 2007-06-23 15:49:42 UTC
Dick Franks reported that a new version of Net::DNS is available  This version
fixes a potential security problem, described:

http://rt.cpan.org/Public/Bug/Display.html?id=23961

Updates for fedora and RHEL are recommended.

Comment 1 Robin Norwood 2007-06-23 16:07:25 UTC
Cc-ing Josh Bressers as part of the update is security related.

Note - I know of no exploits in the wild, however, as described in the RT above,
some issues have been noticed by users.

In particular, this link:

http://www.nntp.perl.org/group/perl.qpsmtpd/2006/03/msg4810.html

has a script which demonstrates the problem.  On my fc-7 system with
perl-Net-DNS-0.59-2.fc7, all of the child processes have the same 'ID's.  With
perl-Net-DNS-0.60-1.fc7, the IDs are randomized.

Comment 2 Fedora Update System 2007-06-25 23:27:18 UTC
perl-Net-DNS-0.60-1.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.