« Apple DNS Patch Lands | Main | "Nobody Got Shot" Isn't an Argument Against WPA. »
August 2, 2008
About That Apple DNS Patch ...
It seems that Apple’s fix for that DNS vulnerability doesn’t apply to its client OSs:
“Researchers from security firm nCircle and the SANS Institute both report that fully patched versions of Tiger (10.4.11) and Leopard (10.5.4) remain vulnerable even after running a bevy of patches Apple released Thursday. Other vendors, including Microsoft, Sun Micro, released similar patches weeks ago.
“Both researchers found that OS X clients fail to adequately randomize DNS source ports, allowing attackers to poison the caches of DNS servers that run on the operating system.
“‘So Apple might have fixed some of the more important parts for servers, but is far from done yet as all the clients linked against a DNS client library still need to get the workaround for the protocol weakness,’ SANS handler Swa Frantzen wrote.
(Link)
Posted by mhall at 1:33 AM | Add Comment


Leave a comment