Secunia Logo
 
Debian update for python-dns
Secunia Advisory: SA31254
Release Date: 2008-07-28
Last Update: 2008-10-10
Popularity: 1,891 views

Critical:
Less critical
Impact: Spoofing
Where: From remote
Solution Status: Vendor Patch

OS:Debian GNU/Linux 4.0

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2008-1447
CVE-2008-4126
CVE-2008-4099


Description:
Debian has issued an update for python-dns. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.

A vulnerability is caused due to python-dns not sufficiently randomising the DNS transaction ID and the source port number, which can be exploited to poison the DNS cache.

Solution:
Apply updated packages.

-- Debian GNU/Linux 4.0 alias etch --

Source archives:

http://security.debian.org/pool/updat...thon-dns/python-dns_2.3.0.orig.tar.gz
Size/MD5 checksum: 21084 82d377c6a59181072b30b0da4e9835b8
http://security.debian.org/pool/updat...ns/python-dns_2.3.0-5.2+etch1.diff.gz
Size/MD5 checksum: 3444 06a021e1cf9836cec4bbe72461bab137
http://security.debian.org/pool/updat...on-dns/python-dns_2.3.0-5.2+etch1.dsc
Size/MD5 checksum: 695 c2e7178128b7033952b7795b358dea0b

Architecture independent packages:

http://security.debian.org/pool/updat...ns/python-dns_2.3.0-5.2+etch1_all.deb
Size/MD5 checksum: 22750 b544ce3edb7d2051811ec743a49206a1

Changelog:
2008-10-10: Added CVE reference.

Original Advisory:
http://lists.debian.org/debian-security-announce/2008/msg00204.html


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 54 views
2. VLC Media Player Real Demuxer Integer Overflow Vulnerability // 48 views
3. Microsoft Office Communications Server SIP INVITE Denial of Service // 30 views
4. Basic PHP CMS "id" SQL Injection Vulnerability // 29 views
5. Active Photo Gallery "username" and "password" SQL Injection // 24 views
6. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 24 views
7. Active Newsletter "email" and "password" SQL Injection Vulnerabilities // 21 views
8. Minimal Ablog Multiple Vulnerabilities // 20 views
9. RakhiSoftware Shopping Cart Multiple Vulnerabilities // 19 views
10. Microsoft XML Core Services Multiple Vulnerabilities // 19 views