Perl Net::DNS DNS Response Remote Denial of Service Vulnerability
BID:26902
Info
Perl Net::DNS DNS Response Remote Denial of Service Vulnerability
| Bugtraq ID: | 26902 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-6341 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2007 12:00AM |
| Updated: | Mar 27 2008 12:39AM |
| Credit: | Beyond Security is credited with the discovery of this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Net::DNS Net::DNS 0.60 Net::DNS Net::DNS 0.59 Net::DNS Net::DNS 0.48 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
Perl Net::DNS DNS Response Remote Denial of Service Vulnerability
The Perl Net::DNS module is prone to a remote denial-of-service vulnerability because the module fails to properly handle malformed DNS responses.
Successfully exploiting this issue allows attackers to crash applications that use the affected module.
Net::DNS 0.60 is vulnerable; other versions may also be affected.
The Perl Net::DNS module is prone to a remote denial-of-service vulnerability because the module fails to properly handle malformed DNS responses.
Successfully exploiting this issue allows attackers to crash applications that use the affected module.
Net::DNS 0.60 is vulnerable; other versions may also be affected.
Exploit / POC
Perl Net::DNS DNS Response Remote Denial of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Perl Net::DNS DNS Response Remote Denial of Service Vulnerability
Solution:
Please see the referenced advisories for details on obtaining and applying the appropriate updates.
Solution:
Please see the referenced advisories for details on obtaining and applying the appropriate updates.
References
Perl Net::DNS DNS Response Remote Denial of Service Vulnerability
References:
References:
- #30316: Security issue with Net::DNS::Resolver (CPAN)
- Net::DNS Malformed Packet DoS (beSTORM)
- Net:DNS Homepage (Net:DNS)