rpm package
opensuse/perl-Net-DNS&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/perl-Net-DNS&distro=openSUSE%20Leap%2016.0
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-64194 | Hig | 7.5 | < 1.460.0-bp160.2.1 | 1.460.0-bp160.2.1 | Jul 20, 2026 | Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to construct a name which saturates the call s | |
| CVE-2026-64193 | Cri | 9.8 | < 1.460.0-bp160.2.1 | 1.460.0-bp160.2.1 | Jul 20, 2026 | Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's ev |
- affected < 1.460.0-bp160.2.1fixed 1.460.0-bp160.2.1
Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to construct a name which saturates the call s
- affected < 1.460.0-bp160.2.1fixed 1.460.0-bp160.2.1
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's ev