PT-2007-1040 · Net+1 · Net::Dns+1

Published

2007-06-25

·

Updated

2025-01-17

·

CVE-2007-3409

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Net::DNS versions prior to 0.60
Description: The issue allows remote attackers to cause a denial of service, specifically stack consumption, via a malformed compressed DNS packet with self-referencing pointers. This triggers an infinite loop, leading to disruption of protected information. The exploitation of this issue can be carried out remotely.
Recommendations: For versions prior to 0.60, update to version 0.60 or later to resolve the issue. As a temporary workaround, consider restricting access to the DNS packet processing functionality until a patch is available.

Fix

DoS

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

BDU:2015-03379
CVE-2007-3409
DSA-1515-1
RHSA-2007:0674
RHSA-2007_0674

Affected Products

Net::Dns
Red Hat