FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

p5-Net-DNS -- multiple Vulnerabilities

Affected packages
p5-Net-DNS < 0.60

Details

VuXML ID d2b8a963-3d59-11dc-b3d3-0016179b2dd5
Discovery 2007-06-27
Entry 2007-07-28

A Secunia Advisory reports:

An error exists in the handling of DNS queries where IDs are incremented with a fixed value and are additionally used for child processes in a forking server. This can be exploited to poison the DNS cache of an application using the module if a valid ID is guessed.

An error in the PP implementation within the "dn_expand()" function can be exploited to cause a stack overflow due to an endless loop via a specially crafted DNS packet.

References

CVE Name CVE-2007-3377
CVE Name CVE-2007-3409
URL http://secunia.com/advisories/25829/