LWN.net Logo

pdns: simpler spoofing attacks

Package(s):pdns CVE #(s):CVE-2008-3337
Created:August 8, 2008 Updated:December 22, 2008
Description:

From the Red Hat bugzilla:

PowerDNS does not respond to certain queries it considers malformed. This in itself is not a problem, and was even thought of as a security measure.

Brian and Florian have discovered that not answering a query for an invalid DNS record within a valid domain allows for a larger spoofing window of the valid domain. Because of the Kaminsky-discovery, this has become bad.

For a sophisticated attacker, this provides no benefit. However, such a long window allows unsophisticated hackers to achieve better results.

Alerts:
Gentoo 200812-19 2008-12-19
SuSE SUSE-SR:2008:017 2008-08-29
SuSE SUSE-SA:2008:041 2008-08-14
Fedora FEDORA-2008-7048 2008-08-07
Debian DSA-1628-1 2008-08-10
Fedora FEDORA-2008-7083 2008-08-07

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds