SuSE: bind (SUSE-SA:2008:033)


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) SuSE: bind (SUSE-SA:2008:033)
# 1  
Old 07-11-2008
SuSE: bind (SUSE-SA:2008:033)

LinuxSecurity.com: The new version of bind uses a random transaction-ID (TRXID) and a random UDP source-port for DNS queries to address DNS cache poisoning attacks possible because of the "birthday paradox" and an attack discovered by Dan Kaminsky. Unfortunately we do not have details about Kaminsky's attack and have to trust the statement that a random UDP source-port is sufficient to stop it.

More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question