Compression loops in domain names resulted in an infinite loop in the
domain name expander written in Perl (CVE-2007-3409). The Debian
package uses an expander written in C by default, but this vulnerability
has been addressed nevertheless.
Decoding malformed A records could lead to a crash (via an uncaught
Perl exception) of certain applications using libnet-dns-perl
(CVE-2007-6341).
For the stable distribution (etch), these problems have been fixed in
version 0.59-1etch1.
For the old stable distribution (sarge), these problems have been fixed in
version 0.48-1sarge1.
We recommend that you upgrade your libnet-dns-perl package.
Upgrade instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
...
Get the latest Linux and open source security news straight to your inbox.