digital.forest Technical Support
DNS Vulnerability Announced

Today a major vulnerability was announced in the Domain Name Service protocol. You can read the details in the US-CERT announcement here: http://www.kb.cert.org/vuls/id/800113.

We are performing an assessment of our own DNS servers, planning to patch them, and make the configuration changes as required. We will post more on that as needed. The main purpose of this post is to inform our clients who run their own DNS servers inside the digital.forest facilities about this vulnerability. Please note that this is a fundamental vulnerability in the DNS protocol, so it is not vendor specific. This means that virtually EVERY device that can operate as a DNS server is vulnerable. We strongly suggest that you consult with your equipment and software vendors to ascertain your exposure and take appropriate action.

We'll post more information as it becomes available.

posted by Chuck G. at 04:22 PM on Tuesday, July 8, 2008
Categories: DNS, Security Alerts