Summary: | dev-perl/Net-DNS < 0.60 cache poisoning and DoS (CVE-2007-3377, 3409) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Matt Drew (RETIRED) <aetius> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | perl |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.net-dns.org/docs/Changes.html | ||
Whiteboard: | B3 [glsa] aetius | ||
Package list: | Runtime testing required: | --- |
Description
Matt Drew (RETIRED)
![]() (In reply to comment #0) > http://secunia.com/advisories/25829/ > > 0.60 is already in the tree, we should just need to stabilize it. Any > objections to that before I call for stable? > nope (that is, no objections) Since this is security related, were you going to add the arch's? Or were you waiting for me to? done, I'm just slack. :\ Arches, please stabilize: dev-perl/net-dns-0.60 Thanks! sparc stable, and it's dev-perl/Net-DNS-0.60 x86 stable Stable for HPPA. alpha/ia64 stable ppc64 stable amd64 stable ppc stable Ready for glsa decision. DNS poisoning is not good, so voting yes. I'll also vote yes for the DNS cache poisoning, as this is a basic DNS protection mechanism that was not implemented. GLSA request filed. mips stable. it's GLSA 200708-06, thanks everybody and sorry for the delay. arm, s390; don't forget to mark stable in order to benefit from the GLSA. |