While this has nothing to do specifically with the topic of DNSSEC that we cover here on Deploy360, there is important news in the broader world of "DNS security". The vendors of three of the major DNS recursive resolvers today released security advisories about a particularly nasty bug where the resolver can be tricked into trying to follow essentially an infinite loop and wind up exhausting all resources and potentially shutting down. The advisories from BIND, PowerDNS and Unbound are found at these links:
- BIND: CVE-2014-8500: A Defect in Delegation Handling Can Be Exploited to Crash BIND
- PowerDNS: Security Advisory 2014-02: PowerDNS Recursor 3.6.1 and earlier can be made to provide bad service
- Unbound: Unbound security advisory