LWN.net Logo

pdns-recursor: DNS cache poisoning

Package(s):pdns-recursor CVE #(s):CVE-2008-1637
Created:April 9, 2008 Updated:July 17, 2008
Description:

From the Red Hat bugzilla entry:

Amit Klein of Trusteer discovered and documented weakness in a way PowerDNS Recursor generates DNS queries and transaction IDs used in DNS queries. This weakness can be used to predict transaction IDs used in a subsequent queries after observing certain amount of consequent previous queries, leading to a high possibility of performing a successful cache poisoning attack.

Alerts:
Fedora FEDORA-2008-3010 2008-04-08
Fedora FEDORA-2008-3036 2008-04-08
Debian DSA-1544-1 2008-04-09
Gentoo 200804-22 2008-04-18
SuSE SUSE-SR:2008:012 2008-06-06
Debian DSA-1544-2 2008-07-16

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.