CVE-2007-6341 libnet-dns-perl possible denial of service (program "croak") via a crafted DNS response.

Bug #205721 reported by Emanuele Gentili
254
Affects Status Importance Assigned to Milestone
libnet-dns-perl (Debian)
Fix Released
Unknown
libnet-dns-perl (Ubuntu)
Fix Released
Medium
Scott Kitterman
Dapper
Fix Released
Medium
Emanuele Gentili
Edgy
Fix Released
Medium
Emanuele Gentili
Feisty
Fix Released
Medium
Emanuele Gentili
Gutsy
Fix Released
Medium
Emanuele Gentili

Bug Description

Net/DNS/RR/A.pm in Net::DNS 0.60 build 654, as used in packages such as SpamAssassin and OTRS, allows remote attackers to cause a denial of service (program "croak") via a crafted DNS response.

http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6341
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=457445

Fixed in hardy by sync from Debian Unstable, bug #201454

CVE References

Changed in libnet-dns-perl:
assignee: nobody → emgent
importance: Undecided → Medium
status: New → In Progress
Changed in libnet-dns-perl:
importance: Undecided → Medium
status: New → Confirmed
assignee: nobody → emgent
status: New → In Progress
assignee: nobody → emgent
importance: Undecided → Medium
status: New → In Progress
importance: Undecided → Medium
assignee: nobody → emgent
importance: Undecided → Medium
status: New → In Progress
Revision history for this message
Emanuele Gentili (emgent) wrote :

please use this, corrected debdiff.

Revision history for this message
Scott Kitterman (kitterman) wrote :

Fixed in Hardy.

Changed in libnet-dns-perl:
assignee: emgent → kitterman
status: In Progress → Fix Released
Revision history for this message
Emanuele Gentili (emgent) wrote :
Revision history for this message
Emanuele Gentili (emgent) wrote :

corrected debdiff for edgy.

Revision history for this message
Emanuele Gentili (emgent) wrote :

dapper ready too, waiting uploads.

Thanks.

Changed in libnet-dns-perl:
assignee: nobody → emgent
status: Confirmed → In Progress
Revision history for this message
Kees Cook (kees) wrote :

Thanks! I have created a new testing script "test-libnet-dns-perl.py" in the qa-regression-testing bzr tree, which includes the CVE reproducer. These have been uploaded and will be published shortly.

Kees Cook (kees)
Changed in libnet-dns-perl:
status: In Progress → Fix Committed
status: In Progress → Fix Committed
status: In Progress → Fix Committed
status: In Progress → Fix Committed
Changed in libnet-dns-perl:
status: Unknown → Fix Released
Changed in libnet-dns-perl:
status: Fix Committed → Fix Released
status: Fix Committed → Fix Released
status: Fix Committed → Fix Released
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.