Security Advisories (5)
CVE-2007-6341 (2008-02-08)

Allows remote attackers to cause a denial of service (program "croak") via a crafted DNS response.

CVE-2007-3409 (2007-06-26)

Net::DNS before 0.60, a Perl module, allows remote attackers to cause a denial of service (stack consumption) via a malformed compressed DNS packet with self-referencing pointers, which triggers an infinite loop.

CVE-2007-3377 (2007-06-25)

Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.

CVE-2026-64193 (2026-07-20)

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's eval. There is some escaping done for $ and @, but not for backticks. This can be exploited for command execution if $pkt->edns->option('EXTENDED-ERROR') is called in array context, for example with a payload of {0:`"<command>"`} in EXTRA-TEXT.

CVE-2026-64194 (2026-07-20)

Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to construct a name which saturates the call stack (at least with larger TCP responses), leading to a potential Denial of Service. The guard `$link < $offset` prevents forward and circular chains, but still allows arbitrarily long backward chains. The per-offset cache (`$cache`) is populated at the start of each call and short-circuits only re-traverses of the same offset - the initial descent through a fresh chain still recurses at full depth. A crafted packet can chain two-byte compression pointers so that each one points two bytes earlier than the previous, producing a chain length of `offset / 2`. For the 14-bit pointer field (max offset 16383) this gives up to ~8191 recursive frames. For a TCP DNS message the limit is the 16-bit length field (~32767 frames). Perl's default C stack handles only a few thousand frames; beyond that the process receives SIGSEGV or similar, which is a denial-of-service for any application parsing untrusted DNS data. The vulnerability is triggered by `Net::DNS::Packet->new(\$wire)` i.e. any point where the library decodes a DNS message from the network.

NAME

Net::DNS::Header - DNS packet header class

SYNOPSIS

use Net::DNS::Header;

DESCRIPTION

A Net::DNS::Header object represents the header portion of a DNS packet.

METHODS

new

$header = new Net::DNS::Header;
$header = new Net::DNS::Header(\$data);

Without an argument, new creates a header object appropriate for making a DNS query.

If new is passed a reference to a scalar containing DNS packet data, it creates a header object from that data.

print

$header->print;

Dumps the header data to the standard output.

id

print "query id = ", $header->id, "\n";

Returns the query identification number.

qr

print "query response flag = ", $header->qr, "\n";

Returns the query response flag.

opcode

print "query opcode = ", $header->opcode, "\n";

Returns the query opcode (the purpose of the query).

aa

print "answer is ", $header->aa ? "" : "non-", "authoritative\n";

Returns true if this is an authoritative answer.

tc

print "packet is ", $header->tc ? "" : "not ", "truncated\n";

Returns true if this packet is truncated.

rd

print "recursion was ", $header->rd ? "" : "not ", "desired\n";

Returns true if recursion was desired.

ra

print "recursion is ", $header->ra ? "" : "not ", "available\n";

Returns true if recursion is available.

rcode

print "query response code = ", $header->rcode, "\n";

The query response code, i.e., the status of the query.

qdcount

print "# of question records: ", $header->qdcount, "\n";

Returns the number of records in the question section of the packet.

ancount

print "# of answer records: ", $header->ancount, "\n";

Returns the number of records in the answer section of the packet.

nscount

print "# of authority records: ", $header->nscount, "\n";

Returns the number of records in the authority section of the packet.

arcount

print "# of additional records: ", $header->arcount, "\n";

Returns the number of records in the additional section of the packet.

data

$hdata = $header->data;

Returns the header data in binary format, appropriate for use in a DNS query packet.

COPYRIGHT

Copyright (c) 1997 Michael Fuhr. All rights reserved. This program is free software; you can redistribute it and/or modify it under the same terms as Perl itself.

SEE ALSO

perl(1), Net::DNS, Net::DNS::Resolver, Net::DNS::Packet, Net::DNS::Question, Net::DNS::RR, RFC 1035 Section 4.1.1