Articles / Debian: New dkim-milter pac…

Debian: New dkim-milter packages fix denial of service

It was discovered that dkim-milter, an implementation of the DomainKeys Identified Mail protocol, may crash during DKIM verification if it encounters a specially-crafted or revoked public key record in DNS. Updated packages are available from
Debian Security Advisory DSA-1728-1                                   Florian Weimer
February 27, 2009           
Package        : dkim-milter
Vulnerability  : improper assertion
Problem type   : remote
Debian-specific: no

It was discovered that dkim-milter, an implementation of the DomainKeys
Identified Mail protocol, may crash during DKIM verification if it
encounters a specially-crafted or revoked public key record in DNS.

The old stable distribution (etch) does not contain dkim-milter packages.

For the stable distribution (lenny), this problem has been fixed in
version 2.6.0.dfsg-1+lenny1.

For the unstable distribution (sid), this problem has been fixed in
version 2.6.0.dfsg-2.

We recommend that you upgrade your dkim-milter packages.

Upgrade instructions
wget url
       will fetch the file for you
dpkg -i file.deb
       will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
       will update the internal database
apt-get upgrade
       will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 5.0 alias lenny
Source archives:
 These files will probably be moved into the stable distribution on
 its next update.

For apt-get: deb stable/updates main
For dpkg-ftp: dists/stable/updates/main
Mailing list:
Package info: `apt-cache show ' and
Version: GnuPG v1.4.9 (GNU/Linux)


