DNS-Linked Flaw Leaves Many Systems Vulnerable
ID: a8360c6b-b1de-5615-a03e-14a16f8719cb
STIX ID: report--a8360c6b-b1de-5615-a03e-14a16f8719cb
Feed Name: Security Ledger
Researchers at Google disclosed a stack-based buffer overflow in the glibc DNS client resolver (CVE-2015-7547) that can be triggered by specially crafted, overly long DNS responses and may allow remote code execution on systems using glibc >= 2.9. Google developed a proof-of-concept exploit (not publicly released), recommended mitigations (drop large UDP DNS packets, use local resolvers, limit TCP response sizes, use DNSMasq), and warned the flaw's wide reach makes it potentially very impactful.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
