Bug 245804 (CVE-2007-3409) - CVE-2007-3409 Perl Net::DNS denial of service
Summary: CVE-2007-3409 Perl Net::DNS denial of service
Status: CLOSED ERRATA
Alias: CVE-2007-3409
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,source=redhat,reporte...
Keywords:
Depends On: 245807 245808 245809 245811 245812 245813 245814 833955
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-06-26 19:32 UTC by Josh Bressers
Modified: 2012-06-20 14:29 UTC (History)
1 user (show)

(edit)
Clone Of:
(edit)
Last Closed: 2008-01-16 10:00:49 UTC


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2007:0674 normal SHIPPED_LIVE Moderate: perl-Net-DNS security update 2007-07-12 09:14:05 UTC

Description Josh Bressers 2007-06-26 19:32:09 UTC
An denial of service bug has been found in the way perl-Net-DNS expands
compressed DNS results.  It is possible to cause the application using
perl-Net-DNS to consume resources and crash.

http://rt.cpan.org/Public/Bug/Display.html?id=27285

Comment 5 Tomas Hoger 2008-01-16 09:43:28 UTC
Upstream fixed in version 0.60:

  http://search.cpan.org/src/OLAF/Net-DNS-0.60/Changes

Comment 6 Red Hat Product Security 2008-01-16 10:00:49 UTC
This issue was addressed in:

Red Hat Enterprise Linux:
  http://rhn.redhat.com/errata/RHSA-2007-0674.html

Fedora:
  updated to fixed upstream version




Note You need to log in before you can comment on or make changes to this bug.