MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
dns
Recherche

The "KeyTrap" DNS vulnerability

mardi 20 février 2024, 20:01 , par LWN.net
DNS resolvers (those that handle DNSSEC, at least) are almost uniformly
vulnerable to an exploit
that has been named 'KeyTrap'. In short, the right type of packet can
send a DNS system into something close to an infinite loop, taking it out
of service indefinitely.

With just a single DNS packet, hackers could paralyze all common
DNS implementations and public DNS providers. Exploiting this
attack would have serious consequences for any application that
uses the internet, including the unavailability of technologies
such as web browsers, email and instant messaging. This devastating
effect prompted major DNS vendors to call KeyTrap 'The worst attack
on DNS ever discovered'

Some more information and pointers to updates can be found on the
CVE-2023-50387 page; some distributors have been faster to get updates
out than others.

(Thanks to Dave Täht).
https://lwn.net/Articles/962924/

Voir aussi

News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Date Actuelle
dim. 5 mai - 21:14 CEST