Ubuntu 6.06 LTS / 6.10 : libnet-dns-perl vulnerability (USN-594-1)

Medium Nessus Plugin ID 31702


The remote Ubuntu host is missing a security-related patch.


It was discovered that Net::DNS did not correctly validate the size of DNS replies. A remote attacker could send a specially crafted DNS response and cause applications using Net::DNS to abort, leading to a denial of service.

Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.


Update the affected libnet-dns-perl package.

Plugin Details

Severity: Medium

ID: 31702

File Name: ubuntu_USN-594-1.nasl

Version: $Revision: 1.11 $

Type: local

Agent: unix

Published: 2008/03/28

Modified: 2016/05/27

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:canonical:ubuntu_linux:libnet-dns-perl, cpe:/o:canonical:ubuntu_linux:6.06:-:lts, cpe:/o:canonical:ubuntu_linux:6.10

Required KB Items: Host/cpu, Host/Ubuntu, Host/Ubuntu/release, Host/Debian/dpkg-l

Patch Publication Date: 2008/03/26

Reference Information

CVE: CVE-2007-6341

OSVDB: 43106

USN: 594-1

CWE: 119