CVE-2007-3377
EPSS 3.6%libnet-dns-perl - several vulnerabilities
Published: 6/25/2007Modified: 4/28/2026
Description
Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.
Affected packages (2)
- Debian/libnet-dns-perlfrom 0, < 0.60-1
- Debian/libnet-dns-perlfrom 0, < 0.48-1sarge1