No edit summary |
m (move URLs explicitly out) |
||
Line 7: | Line 7: | ||
=== DNS flaw === | === DNS flaw === | ||
A serious flaw in the way most DNS requests are made was [ | |||
A serious flaw in the way most DNS requests are made was announced[1] last week. It is expected that the details of this issue will be known later this month when Dan Kaminsky presents at Black Hat. In the meantime, if you run a DNS server, be sure to get an update from your vendor. | |||
[1] http://www.kb.cert.org/vuls/id/800113 | |||
On a side note about this issue, newer Linux kernels have a feature where the source port of UDP requests is randomized. That means that as long as the requesting application has random transaction IDs, it doesn't need additional logic to ensure random UDP source ports. | On a side note about this issue, newer Linux kernels have a feature where the source port of UDP requests is randomized. That means that as long as the requesting application has random transaction IDs, it doesn't need additional logic to ensure random UDP source ports. | ||
=== Package Manager Flaw? === | === Package Manager Flaw? === | ||
A report came out last week titled: | |||
A report came out[1] last week titled: Attacks on Package Managers. The actual details of this are quite a bit less interesting than the reporter makes it sound. It's basically the same problem as using an out dated mirror. | |||
[1] http://www.cs.arizona.edu/people/justin/packagemanagersecurity/attacks-on-package-managers.html |
Revision as of 20:20, 13 July 2008
Security Week
In this section, we highlight the security stories from the week in Fedora.
Contributing Writer: JoshBressers
DNS flaw
A serious flaw in the way most DNS requests are made was announced[1] last week. It is expected that the details of this issue will be known later this month when Dan Kaminsky presents at Black Hat. In the meantime, if you run a DNS server, be sure to get an update from your vendor.
[1] http://www.kb.cert.org/vuls/id/800113
On a side note about this issue, newer Linux kernels have a feature where the source port of UDP requests is randomized. That means that as long as the requesting application has random transaction IDs, it doesn't need additional logic to ensure random UDP source ports.
Package Manager Flaw?
A report came out[1] last week titled: Attacks on Package Managers. The actual details of this are quite a bit less interesting than the reporter makes it sound. It's basically the same problem as using an out dated mirror.
[1] http://www.cs.arizona.edu/people/justin/packagemanagersecurity/attacks-on-package-managers.html