FreeBSD : p5-Net-DNS -- multiple Vulnerabilities (d2b8a963-3d59-11dc-b3d3-0016179b2dd5)

This script is Copyright (C) 2007-2013 Tenable Network Security, Inc.


Synopsis :

The remote FreeBSD host is missing a security-related update.

Description :

A Secunia Advisory reports :

An error exists in the handling of DNS queries where IDs are
incremented with a fixed value and are additionally used for child
processes in a forking server. This can be exploited to poison the DNS
cache of an application using the module if a valid ID is guessed.

An error in the PP implementation within the 'dn_expand()' function
can be exploited to cause a stack overflow due to an endless loop via
a specially crafted DNS packet.

See also :

http://www.nessus.org/u?41e4b12b

Solution :

Update the affected package.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)

Family: FreeBSD Local Security Checks

Nessus Plugin ID: 25807 (freebsd_pkg_d2b8a9633d5911dcb3d30016179b2dd5.nasl)

Bugtraq ID:

CVE ID: CVE-2007-3377
CVE-2007-3409

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now