|
|||||||||||
|
[ MDKSA-2007:146 ] - Updated perl-Net-DNS packages fix multiple vulnerabilities
From: <security(at)mandriva.com>
Date: Thu Jul 12 2007 - 20:49:11 EDT -----BEGIN PGP SIGNED MESSAGE-----
Mandriva Linux Security Advisory MDKSA-2007:146http://www.mandriva.com/security/ Package : perl-Net-DNS Date : July 12, 2007 Affected: 2007.0, 2007.1, Corporate 3.0, Corporate 4.0 Problem Description: A flaw was discovered in the perl Net::DNS module in the way it generated the ID field in a DNS query. Because it is so predictable, a remote attacker could exploit this to return invalid DNS data (CVE-2007-3377). A denial of service vulnerability was found in how Net::DNS parsed certain DNS requests. A malformed response to a DNS request could cause the application using Net::DNS to crash or stop responding (CVE-2007-3409). The updated packages have been patched to prevent these issues. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3377 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3409 Updated Packages:
Mandriva Linux 2007.0:
Mandriva Linux 2007.0/X86_64:
Mandriva Linux 2007.1:
Mandriva Linux 2007.1/X86_64:
Corporate 3.0:
Corporate 3.0/X86_64:
Corporate 4.0:
Corporate 4.0/X86_64:
To upgrade automatically use MandrivaUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. All packages are signed by Mandriva for security. You can obtain the GPG public key of the Mandriva Security Team by executing: gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98 You can view other update advisories for Mandriva Linux at: http://www.mandriva.com/security/advisories If you want to report vulnerabilities, please contact security_(at)_mandriva.com
Type Bits/KeyID Date User ID
iD8DBQFGlqB9mqjQ0CJFipgRAtR2AJ9k0gv3DiQhhRnitqXz+ZDG2OimbwCfacXe
aq9g2vyl8V79tBNKBAMG5VY=
This archive was generated by hypermail 2.1.8 : Thu Aug 09 2007 - 17:55:46 EDT |
||||||||||
|
|||||||||||