Re: Net::DNS .060 allows remote attackers to cause DOS

2008-03-27 Thread mouss
Michael Scheidell wrote: From: http://search.cpan.org/src/OLAF/Net-DNS-0.63/Changes Fix rt.cpan.org #30316 Security issue with Net::DNS Resolver. Net/DNS/RR/A.pm in Net::DNS 0.60 build 654 allows remote attackers to cause a denial of service (program "croak") via a crafted DNS response (ht

Re: Net::DNS .060 allows remote attackers to cause DOS

2008-03-27 Thread Michael Scheidell
Justin Mason wrote: This issue has no security impact. The flaw will cause Net::DNS to "croak", which in turn should be handled by the calling application. In the case of RHEL, the only known application that uses this functionality is Spamassassin. Spamassassin handles this failure

Re: Net::DNS .060 allows remote attackers to cause DOS

2008-03-27 Thread Justin Mason
Michael Scheidell writes: > From: > http://search.cpan.org/src/OLAF/Net-DNS-0.63/Changes > > Fix rt.cpan.org #30316 Security issue with Net::DNS Resolver. > > Net/DNS/RR/A.pm in Net::DNS 0.60 build 654 allows remote attackers to > cause a denial of service (program "croak") via a crafted DNS

Net::DNS .060 allows remote attackers to cause DOS

2008-03-27 Thread Michael Scheidell
From: http://search.cpan.org/src/OLAF/Net-DNS-0.63/Changes Fix rt.cpan.org #30316 Security issue with Net::DNS Resolver. Net/DNS/RR/A.pm in Net::DNS 0.60 build 654 allows remote attackers to cause a denial of service (program "croak") via a crafted DNS response (http://nvd.nist.gov/nvd.cfm?