« Apple DNS Patch Lands | Main | "Nobody Got Shot" Isn't an Argument Against WPA. »

August 2, 2008

About That Apple DNS Patch ...

It seems that Apple’s fix for that DNS vulnerability doesn’t apply to its client OSs:

“Researchers from security firm nCircle and the SANS Institute both report that fully patched versions of Tiger (10.4.11) and Leopard (10.5.4) remain vulnerable even after running a bevy of patches Apple released Thursday. Other vendors, including Microsoft, Sun Micro, released similar patches weeks ago.

“Both researchers found that OS X clients fail to adequately randomize DNS source ports, allowing attackers to poison the caches of DNS servers that run on the operating system.

“‘So Apple might have fixed some of the more important parts for servers, but is far from done yet as all the clients linked against a DNS client library still need to get the workaround for the protocol weakness,’ SANS handler Swa Frantzen wrote.

(Link)

E-mail   0 Comments    Digg This    add to del.icio.us

Posted by mhall at 1:33 AM | Add Comment

Leave a comment











Type the characters you see in the picture above.

 




JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers