Perl Net::DNS Remote Multiple Vulnerabilities
BID:24669
Info
Perl Net::DNS Remote Multiple Vulnerabilities
| Bugtraq ID: | 24669 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3377 CVE-2007-3409 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2007 12:00AM |
| Updated: | Mar 12 2008 02:01AM |
| Credit: | Steffen_Ullrich and Hjp are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Trustix Secure Linux 3.0.5 Trustix Secure Linux 3.0 Trustix Secure Linux 2.0 Trustix Operating System Enterprise Server 2.0 SuSE SUSE Linux Enterprise Server 10 SuSE Suse Linux Enterprise Desktop 10 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 10 SuSE Linux Desktop 10 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc SGI ProPack 3.0 SP6 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.2 X86 64 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.2 X86 64 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 rPath rPath Linux 1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Net::DNS Net::DNS 0.59 Net::DNS Net::DNS 0.58 Net::DNS Net::DNS 0.52 Net::DNS Net::DNS 0.48 Net::DNS Net::DNS 0.39 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Messaging Storage Server MSS 3.0 |
| Not Vulnerable: |
Net::DNS Net::DNS 0.60 |
Discussion
Perl Net::DNS Remote Multiple Vulnerabilities
The Perl Net::DNS module is prone to a remote denial-of-service vulnerability and a cache-poisoning issue.
Successful exploits may allow remote attackers to cause denial-of-service conditions or to manipulate cache data, potentially facilitating man-in-the-middle and site-impersonation attacks.
Versions prior to Perl Net::DNS 0.60. are reported vulnerable.
The Perl Net::DNS module is prone to a remote denial-of-service vulnerability and a cache-poisoning issue.
Successful exploits may allow remote attackers to cause denial-of-service conditions or to manipulate cache data, potentially facilitating man-in-the-middle and site-impersonation attacks.
Versions prior to Perl Net::DNS 0.60. are reported vulnerable.
Exploit / POC
Perl Net::DNS Remote Multiple Vulnerabilities
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Perl Net::DNS Remote Multiple Vulnerabilities
Solution:
The vendor has released version 0.60 to address these issues. Please see the references for more information.
Net::DNS Net::DNS 0.59
Solution:
The vendor has released version 0.60 to address these issues. Please see the references for more information.
Net::DNS Net::DNS 0.59
-
Net::DNS Net-DNS-0.60.tar.gz
http://www.net-dns.org/download/Net-DNS-0.60.tar.gz
References
Perl Net::DNS Remote Multiple Vulnerabilities
References:
References:
- #23961: id sequence is predictable and the same in all child processes. (hjp )
- #27285: Bugs in dn_expand (XS and PP) on mailformed packages (Steffen_Ullrich)
- Net:DNS Homepage (Net:DNS)
- Avaya Security Advisory ASA-2007-351 (Avaya)
- RHSA-2007:0674-3 perl-Net-DNS security update (Red Hat)
- RHSA-2007:0675-2 perl-Net-DNS security update (Red Hat)