5
CVSSv2

CVE-2007-6341

Published: 20/12/2007 Updated: 03/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Net/DNS/RR/A.pm in Net::DNS 0.60 build 654, as used in packages such as SpamAssassin and OTRS, allows remote malicious users to cause a denial of service (program "croak") via a crafted DNS response.

Vulnerable Product Search on Vulmon Subscribe to Product

net dns net dns 0.60

Vendor Advisories

Debian Bug report logs - #457445 libnet-dns-perl: CVE-2007-6341 possible remote denial of service vulnerability Package: libnet-dns-perl; Maintainer for libnet-dns-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libnet-dns-perl is src:libnet-dns-perl (PTS, buildd, popcon) Reported by: Nic ...
It was discovered that Net::DNS did not correctly validate the size of DNS replies A remote attacker could send a specially crafted DNS response and cause applications using Net::DNS to abort, leading to a denial of service ...

Exploits

source: wwwsecurityfocuscom/bid/26902/info The Perl Net::DNS module is prone to a remote denial-of-service vulnerability because the module fails to properly handle malformed DNS responses Successfully exploiting this issue allows attackers to crash applications that use the affected module Net::DNS 060 is vulnerable; other versions ...