Critical Cache Poisoning Vulnerability Discovered in Dnsmasq DNS Software
By
westurner
Solid neighbourhood-bakery energy. Trustworthy and warm.
Summary
A security researcher from Tsinghua University has responsibly disclosed a critical cache poisoning vulnerability in Dnsmasq DNS software. The vulnerability allows attackers to inject malicious DNS records and poison domain names using a single special character, bypassing existing security measures. The flaw affects all versions of Dnsmasq and is classified as critical severity with off-path exploitability.
Key quotes
· 5 pulledWe would like to responsibly disclose a critical cache poisoning vulnerability affecting the Dnsmasq DNS software
The issue allows attackers to inject arbitrary malicious DNS resource records and poison domain names without requiring advanced techniques
Vulnerability Type: Logic flaw in cache poisoning defense
Severity: Critical
Exploitability: Off-path
Article URL: https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2025q3/018288.html
Comments URL: https://news.ycombinator.com/item?id=44950981
Points: 9
# Comments: 1
You might also wanna read
Prompt Injection Attacks: The Top Security Threat Hijacking AI Chatbots
Prompt injection attacks are a critical security vulnerability in AI systems where hidden instructions within user data (like emails or docu
Quantum computing's security threats demand urgent preparation from IT professionals
The article discusses the impending quantum computing revolution and its dual nature: promising transformative advances while simultaneously
zdnet.com·16h agoCISA warns security teams of wave of attacks targeting software supply chain credentials
CISA has issued a warning urging security teams to check for software development compromises, specifically regarding a wave of attacks targ
Security Researchers Expose Weak Encryption in Canon Enterprise Printers
During a network security assessment, security researchers discovered that Canon enterprise printers configured with default administrator c
securityboulevard.com·1d agoNew browser-based side-channel attack uses SSD activity analysis to spy on users
Researchers have discovered a new browser-based side-channel attack that can spy on users by analyzing SSD (Solid State Drive) activity thro
arstechnica.com·2d agoCISA Contractor Exposed AWS GovCloud Credentials on Public GitHub Repository
A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository until recently that exposed
