{"id":"DSA-1605-1","summary":"glibc - DNS cache poisoning","details":"\nDan Kaminsky discovered that properties inherent to the DNS protocol\nlead to practical DNS spoofing and cache poisoning attacks. Among\nother things, successful attacks can lead to misdirected web traffic\nand email rerouting.\n\n\nAt this time, it is not possible to implement the recommended\ncountermeasures in the GNU libc stub resolver. The following\nworkarounds are available:\n\n\n1. Install a local BIND 9 resolver on the host, possibly in\nforward-only mode. BIND 9 will then use source port randomization\nwhen sending queries over the network. (Other caching resolvers can\nbe used instead.)\n\n\n2. Rely on IP address spoofing protection if available. Successful\nattacks must spoof the address of one of the resolvers, which may not\nbe possible if the network is guarded properly against IP spoofing\nattacks (both from internal and external sources).\n\n\nThis DSA will be updated when patches for hardening the stub resolver\nare available.\n\n\n","modified":"2022-07-04T02:00:46.305685Z","published":"2008-07-08T00:00:00Z","withdrawn":"2024-05-15T05:36:14.081210Z","schema_version":"1.7.3"}