Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.70567
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2353-1)
Summary:The remote host is missing an update for the Debian 'ldns' package(s) announced via the DSA-2353-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'ldns' package(s) announced via the DSA-2353-1 advisory.

Vulnerability Insight:
David Wheeler discovered a buffer overflow in ldns's code to parse RR records, which could lead to the execution of arbitrary code.

For the oldstable distribution (lenny), this problem has been fixed in version 1.4.0-1+lenny2.

For the stable distribution (squeeze), this problem has been fixed in version 1.6.6-2+squeeze1.

For the unstable distribution (sid), this problem has been fixed in version 1.6.11-1.

We recommend that you upgrade your ldns packages.

Affected Software/OS:
'ldns' package(s) on Debian 5, Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-3581
46470
http://secunia.com/advisories/46470
46476
http://secunia.com/advisories/46476
49748
http://www.securityfocus.com/bid/49748
FEDORA-2011-13895
http://lists.fedoraproject.org/pipermail/package-announce/2011-October/068091.html
FEDORA-2011-13915
http://lists.fedoraproject.org/pipermail/package-announce/2011-October/068201.html
FEDORA-2011-13929
http://lists.fedoraproject.org/pipermail/package-announce/2011-October/068239.html
[oss-security] 20110924 CVE request: heap-based buffer overflow in ldns
http://seclists.org/oss-sec/2011/q3/503
[oss-security] 20110930 Re: CVE request: heap-based buffer overflow in ldns
http://seclists.org/oss-sec/2011/q3/542
http://nlnetlabs.nl/svn/ldns/tags/release-1.6.11/Changelog
http://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=403
openSUSE-SU-2011:1161
http://lists.opensuse.org/opensuse-security-announce/2011-10/msg00008.html
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.