Skip to main content

Top DNS service may be suffering from some serious security flaws

posted onJanuary 21, 2021
by l33tdawg
Flickr
Credit: Flickr

An Israeli cybersecurity firm has discovered some serious security flaws affecting a piece of popular Domain Name System (DNS) software. Jerusalem-based JSOF has disclosed seven vulnerabilities affecting dnsmasq, an open-source DNS forwarding program, that the firm has collectively called DNSpooq.

“The Dnspooq vulnerabilities include DNS cache poisoning vulnerabilities as well as a potential remote code execution and others,” the JSOF report read. “The list of devices using dnsmasq is long and varied. According to our internet-based research, prominent users of dnsmasq seem to include Cisco routers, Android phones, Aruba devices, Technicolor, and Red-Hat, as well as Siemens, Ubiquiti networks, Comcast, and others.”

According to JSOF, the security flaws can be used to implement DNS cache poisoning, remote code execution, and denial-of-service attacks against a huge number of affected devices.

Source

Tags

Security

You May Also Like

Recent News

Monday, May 20th

Thursday, May 16th

Wednesday, May 15th

Tuesday, May 14th

Monday, May 13th

Friday, May 10th

Thursday, May 9th

Wednesday, May 8th