Ubuntu Security Notice USN-594-1
26th March, 2008
libnet-dns-perl vulnerability
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 6.10
- Ubuntu 6.06 LTS
Software description
- libnet-dns-perl
Details
It was discovered that Net::DNS did not correctly validate the size
of DNS replies. A remote attacker could send a specially crafted DNS
response and cause applications using Net::DNS to abort, leading to a
denial of service.
Update instructions
The problem can be corrected by updating your system to the following package version:
- Ubuntu 6.10:
- libnet-dns-perl 0.57-1ubuntu1.1
- Ubuntu 6.06 LTS:
- libnet-dns-perl 0.53-2ubuntu1.1
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
In general, a standard system upgrade is sufficient to effect the
necessary changes.