US-CERT: Multiple DNS Implementations Vulnerable to Cache Poisoning
US-CERT has released notification of the Cache Poisoning vulnerabilities in several DNS deployments (posted yesterday via Securosis). This is a highly critical issue, that apparently can only be overcome with a DNSSEC DJBDNS implementation.
References (Directly from the Vulnerability Announcement)
* US-CERT Vulnerability Note VU#800113
* US-CERT Vulnerability Note VU#484649
* US-CERT Vulnerability Note VU#252735
* US-CERT Vulnerability Note VU#927905
* US-CERT Vulnerability Note VU#457875
* Internet Draft: Measures for making DNS more resilient against forged answers
* RFC 3833
* RFC 2827
* RFC 3704
* RFC 3013
* Microsoft Security Bulletin MS08-037
* Internet Systems Consortium BIND Vulnerabilities





