Article 14TG5 Kaminsky: A Skeleton Key of Unknown Strength

Kaminsky: A Skeleton Key of Unknown Strength

by
ris
from LWN.net on (#14TG5)
Dan Kaminsky looksat the Glibc DNS bug (CVE-2015-7547). "We've investigated the DNS lookup path, which requires the glibc exploit to survive traversing one of the millions of DNS caches dotted across the Internet. We've found that it is neither trivial to squeeze the glibc flaw through common name servers, nor is it trivial to prove such a feat is impossible. The vast majority of potentially affected systems require this attack path to function, and we just don't know yet if it can. Our belief is that we're likely to end up with attacks that work sometimes, and we're probably going to end up hardening DNS caches against them with intent rather than accident. We're likely not going to apply network level DNS length limits because that breaks things in catastrophic and hard to predict ways."
External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments