Michael Scheidell wrote:
> Don't know if anyone has mentioned this, if so, I missed it.
> Potential DOS in spamassassin if perl-Net-DNS < .60. (previously
> recommended version was .58)
> Freebsd ports has .60, for the last two weeks.
>


Thanks for the FYI.

MrC

> -----Original Message-----
> From: rPath Update Announcements [mailto:announce-noreply@rpath.com]
> Sent: Tuesday, July 17, 2007 8:12 AM
> To: security-announce@lists.rpath.com; update-announce@lists.rpath.com
> Cc: full-disclosure@lists.grok.org.uk; bugtraq@securityfocus.com;
> lwn@lwn.net
> Subject: rPSA-2007-0142-1 perl-Net-DNS
>
>
> rPath Security Advisory: 2007-0142-1
> Published: 2007-07-17
> Products: rPath Linux 1
> Rating: Minor
> Exposure Level Classification:
> Indirect User Deterministic Denial of Service
> Updated Versions:
> perl-Net-DNS=/conary.rpath.com@rpl:devel//1/0.60-1-0.1
>
> References:
> http://cve.mitre.org/cgi-bin/cvename...=CVE-2007-3377
> http://cve.mitre.org/cgi-bin/cvename...=CVE-2007-3409
> https://issues.rpath.com/browse/RPL-1537
>
> Description:
> Previous versions of the perl-Net-DNS package contained multiple
> vulnerabilities: one can lead to DNS cache poisoning, and the other
> can result in a Denial of Service triggered by an infinite loop.
>
> Copyright 2007 rPath, Inc.
> This file is distributed under the terms of the MIT License.
> A copy is available at http://www.rpath.com/permanent/mit-license.html
> __________________________________________________ _______________________
> This email has been scanned and certified safe by SpammerTrap(tm).
> For Information please see http://www.spammertrap.com
> __________________________________________________ _______________________
>
> -------------------------------------------------------------------------
> This SF.net email is sponsored by DB2 Express
> Download DB2 Express C - the FREE version of DB2 express and take
> control of your XML. No limits. Just data. Click to get it now.
> http://sourceforge.net/powerbar/db2/
> _______________________________________________
> AMaViS-user mailing list
> AMaViS-user@lists.sourceforge.net
> https://lists.sourceforge.net/lists/...fo/amavis-user
> AMaViS-FAQ:http://www.amavis.org/amavis-faq.php3
> AMaViS-HowTos:http://www.amavis.org/howto/