Dit bericht is nog niet vertaald

[USN-594-1] libnet-dns-perl vulnerability

Ubuntu Security Notice USN-594-1             March 26, 2008
libnet-dns-perl vulnerability
CVE-2007-6341
Kwetsbare Ubuntu versies:

Ubuntu 6.06 LTS
Ubuntu 6.10

Kwetsbare pakketten:

Ubuntu 6.06 LTS
libnet-dns-perl 0.53-2ubuntu1.1
Ubuntu 6.10
libnet-dns-perl 0.57-1ubuntu1.1

In general, a standard system upgrade is sufficient to effect the necessary changes.

It was discovered that Net::DNS did not correctly validate the size of DNS replies. A remote attacker could send a specially crafted DNS response and cause applications using Net::DNS to abort, leading to a denial of service.