Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· OCZ Vertex 450 Series Solid State Drives announced
· NVIDIA GeForce GTX 780 Reviews Roundup
· Apple's 'iWatch' to come in late 2014 with focus on biometrics, analyst says
· Windows 8.1 laptops with AMDs new chips to support wireless display
· HP $399 touchscreen laptop breaks price barrier
· What's Wrong with the Xbox One? and more
· Microsoft updates its YouTube Windows Phone app with some concessions to Google
· 3 Debian Updates
· The third screen: Will all Windows 8 apps run on Microsoft's Xbox One?
· CentOS-6.4 LiveCD and LiveDVD for i386 and x86_64 released

Upcoming News
· REVIEW: Nvidia GeForce GTX 780 @ PureOverclock
· iStarUSA BPU-340SATA Military Grade Drive Enclosure
· A Futurelooks New Flash - Futurelooks Weekly Giveawa?= y 2 of 3 – Win an ADATA XPG v1.0 1866mhz 8GB (4GB x 2) Mem?= ory Kit
· Security issue in livecd-tools causes password issue in Fedora cloud images
· Gigabyte C847N Motherboard @ Hardware Secrets
· An MTN News Flash - MEGATech Reviews – Tep Wireles?= s Pocket WiFi Mobile Hotspot Rental
· AMD Kabini Mainstream APU Notebook Platform Preview @ Legit Reviews
· OCZ Vertex 450 Solid State Drive Review
· [CentOS-announce] CEBA-2013:0858 CentOS 6 coreutils Update
· ZOTAC GeForce GTX 780 Graphics Card Video Review with Stuart Davidson @ HardwareHeaven.com

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6458 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 700 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4577 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 773 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1152 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » July 2007 » [Security Announce] [ MDKSA-2007:146 ] - Updated perl-Net-DNS packages fix multiple vulnerabilities

[Security Announce] [ MDKSA-2007:146 ] - Updated perl-Net-DNS packages fix multiple vulnerabilities

Posted by Bob on: 07/13/2007 03:25 PM [ Print | 0 comment(s) ]

The Mandriva Security Team published a new security update for Mandriva Linux. Here the announcement:




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDKSA-2007:146
http://www.mandriva.com/security/
_______________________________________________________________________

Package : perl-Net-DNS
Date : July 12, 2007
Affected: 2007.0, 2007.1, Corporate 3.0, Corporate 4.0
_______________________________________________________________________

Problem Description:

A flaw was discovered in the perl Net: :DNS module in the way it
generated the ID field in a DNS query. Because it is so predictable,
a remote attacker could exploit this to return invalid DNS data
(CVE-2007-3377).

A denial of service vulnerability was found in how Net: :DNS parsed
certain DNS requests. A malformed response to a DNS request could
cause the application using Net: :DNS to crash or stop responding
(CVE-2007-3409).

The updated packages have been patched to prevent these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3377
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3409
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2007.0:
92d215a4965bb8d944c030cf1dd73a11 2007.0/i586/perl-Net-DNS-0.58-1.1mdv2007.0.i586.rpm
06c1dd9d596004e261a9706060a4c167 2007.0/SRPMS/perl-Net-DNS-0.58-1.1mdv2007.0.src.rpm

Mandriva Linux 2007.0/X86_64:
34bc7cfb39bd239dea991559a05f66b7 2007.0/x86_64/perl-Net-DNS-0.58-1.1mdv2007.0.x86_64.rpm
06c1dd9d596004e261a9706060a4c167 2007.0/SRPMS/perl-Net-DNS-0.58-1.1mdv2007.0.src.rpm

Mandriva Linux 2007.1:
cd6db816556ae5f3c172dafb5ee98002 2007.1/i586/perl-Net-DNS-0.59-1.1mdv2007.1.i586.rpm
dc954016fe3924ab2a362285cd780636 2007.1/SRPMS/perl-Net-DNS-0.59-1.1mdv2007.1.src.rpm

Mandriva Linux 2007.1/X86_64:
d9cbd72d34d8eab851473716740290f3 2007.1/x86_64/perl-Net-DNS-0.59-1.1mdv2007.1.x86_64.rpm
dc954016fe3924ab2a362285cd780636 2007.1/SRPMS/perl-Net-DNS-0.59-1.1mdv2007.1.src.rpm

Corporate 3.0:
338edc98b82b661a4245c8dfdea463fa corporate/3.0/i586/perl-Net-DNS-0.39-2.1.C30mdk.i586.rpm
eeeb5c182365d9726f36326892065015 corporate/3.0/SRPMS/perl-Net-DNS-0.39-2.1.C30mdk.src.rpm

Corporate 3.0/X86_64:
e47654bec20760643ce0e4d7b78ab394 corporate/3.0/x86_64/perl-Net-DNS-0.39-2.1.C30mdk.x86_64.rpm
eeeb5c182365d9726f36326892065015 corporate/3.0/SRPMS/perl-Net-DNS-0.39-2.1.C30mdk.src.rpm

Corporate 4.0:
51e6714b343575136bf296a495c32de3 corporate/4.0/i586/perl-Net-DNS-0.52-1.1.20060mlcs4.i586.rpm
862ceacd8ba656dee551039d5074dd46 corporate/4.0/SRPMS/perl-Net-DNS-0.52-1.1.20060mlcs4.src.rpm

Corporate 4.0/X86_64:
99cb67c8f400c7f826ce63702e863508 corporate/4.0/x86_64/perl-Net-DNS-0.52-1.1.20060mlcs4.x86_64.rpm
862ceacd8ba656dee551039d5074dd46 corporate/4.0/SRPMS/perl-Net-DNS-0.52-1.1.20060mlcs4.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
lt;security*mandriva.comgt;
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iD8DBQFGlqB9mqjQ0CJFipgRAtR2AJ9k0gv3DiQhhRnitqXz+ZDG2OimbwCfacXe
aq9g2vyl8V79tBNKBAMG5VY=
=OBVo
-----END PGP SIGNATURE-----


Bookmark and Share

« uTorrent 1.7 Build 3353 · RHSA-2007:0662-01 Moderate: httpd security update »

Linux Compatible » News » July 2007 » [Security Announce] [ MDKSA-2007:146 ] - Updated perl-Net-DNS packages fix multiple vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition