Bug 245466 (CVE-2007-3377) - CVE-2007-3377 perl-Net-DNS security issue
Summary: CVE-2007-3377 perl-Net-DNS security issue
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2007-3377
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Robin Norwood
QA Contact:
URL: http://search.cpan.org/~olaf/Net-DNS-...
Whiteboard:
Depends On: 245612 245613 245614 245615 245616 245617 245618 245619 245620 833954
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-06-23 16:52 UTC by Robin Norwood
Modified: 2019-09-29 12:20 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2008-01-16 10:01:12 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2007:0674 0 normal SHIPPED_LIVE Moderate: perl-Net-DNS security update 2007-07-12 09:14:05 UTC
Red Hat Product Errata RHSA-2007:0675 0 normal SHIPPED_LIVE Moderate: perl-Net-DNS security update 2008-01-07 22:28:22 UTC

Description Robin Norwood 2007-06-23 16:52:19 UTC
Dick Franks reported that a new version of Net::DNS is available  This version
fixes a potential security problem, described:

http://rt.cpan.org/Public/Bug/Display.html?id=23961

Updates for fedora and RHEL are recommended.

see also bug #245458, which tracks the Fedora version.

RHEL5 uses Net-DNS-0.59-1, just like Fedora FC5-F7, so the fix is the same. 
However, older versions of RHEL use much older versions of Net::DNS - I have not
yet verified that the issue exists with these versions, or done a review of the
other changes to check for other possible issues.

Comment 1 Josh Bressers 2007-06-25 18:20:47 UTC
I'm moving this to the security response queue for proper tracking.

Comment 8 Tomas Hoger 2008-01-16 09:43:47 UTC
Fixed in upstream verson 0.60:

  http://search.cpan.org/src/OLAF/Net-DNS-0.60/Changes

Comment 9 Red Hat Product Security 2008-01-16 10:01:12 UTC
This issue was addressed in:

Red Hat Enterprise Linux:
  http://rhn.redhat.com/errata/RHSA-2007-0675.html
  http://rhn.redhat.com/errata/RHSA-2007-0674.html

Fedora:
  updated to fixed upstream version




Note You need to log in before you can comment on or make changes to this bug.