Donate
‹ Back
Domain Name System Security Extensions (DNSSEC) 9 December 2014

DNS Security Advisories Out Today For BIND, PowerDNS and Unbound – Time To Upgrade!

Dan York
By Dan YorkDirector of Web Strategy

DNSWhile this has nothing to do specifically with the topic of DNSSEC that we cover here on Deploy360, there is important news in the broader world of “DNS security”.  The vendors of three of the major DNS recursive resolvers today released security advisories about a particularly nasty bug where the resolver can be tricked into trying to follow essentially an infinite loop and wind up exhausting all resources and potentially shutting down.  The advisories from BIND, PowerDNS and Unbound are found at these links:

The advisories from both PowerDNS and Unbound indicate that this bug would be difficult for an attacker to exploit unless they were within the user base of the recursive resolver.  The BIND advisory is more open-ended and indicates the bug could be executed remotely.

In all cases the easiest solution is to upgrade to the newest versions:

While there are apparently no known exploits of the bug in the wild yet, that will now only be a matter of time.  It would be best to upgrade your recursive resolvers as soon as possible.

P.S. While you are in there updating your DNS resolver, if you are using BIND or Unbound, why not enable DNSSEC validation?  It’s a simple change in the configuration file, as shown in this SURFnet white paper.

‹ Back

Disclaimer: Viewpoints expressed in this post are those of the author and may or may not reflect official Internet Society positions.

Related articles

DNS Security Advisories Out Today For BIND, PowerDNS and Unbound - Time To Upgrade!
Deploy3609 December 2014

DNS Security Advisories Out Today For BIND, PowerDNS and Unbound – Time To Upgrade!

While this has nothing to do specifically with the topic of DNSSEC that we cover here on Deploy360, there is...

DNS Security & Privacy discussed at e-AGE18
DNS Security & Privacy discussed at e-AGE18
Deploy36024 December 2018

DNS Security & Privacy discussed at e-AGE18

The Internet Society continued its engagement with Middle East networking community by participating in the e-AGE18 Conference, where we took...

DNSSEC Reference Card Provides Quick Answers
Deploy3601 February 2012

DNSSEC Reference Card Provides Quick Answers

Have you wished you had a quick reference card to remember the DNSSEC options to use with "dig"? Or to...

Join the conversation with Internet Society members around the world