Tools

News

Notícias

Classificados

Cursos

Broker

 
IPv4:
IPv6:
UpOrDown
Ping
MTR
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc & Sum

BIND Warns of DNS Cache Poisoning Flaws

Image © Arstechnica
Two critical DNS vulnerabilities in BIND, tracked as CVE-2025-40778 and CVE-2025-40780, could enable cache poisoning. Unbound has related disclosures with CVE-2025-11411. Patches are available now.

Security researchers warn that two bugs in BIND could let attackers poison caches and redirect users to malicious destinations. The flaws, identified as CVE-2025-40778 (a logic error) and CVE-2025-40780 (a weakness in generating pseudo-random numbers), carry a high severity rating of 8.6. Separately, developers of the Unbound DNS resolver flagged similar vulnerabilities disclosed by the same researchers, with CVE-2025-11411 and a separate severity score of 5.6.

If exploited, these issues could cause resolvers across thousands of organizations to substitute legitimate domain lookups with forged results, pointing users to attacker-controlled IPs. Patches for BIND and Unbound were released on Wednesday to mitigate the risk.

The Kaminsky-era cache poisoning concept remains a touchstone for DNS security. The bugs arise from how DNS answers are matched and validated, threatening the integrity of cached mappings and enabling widespread redirection under certain conditions.

Details from the disclosure note that CVE-2025-40780 undermines entropy defenses that previously helped protect DNS responses, while CVE-2025-40778 allows forged data to be cached during a query. DNSSEC, rate limiting, and network-level protections remain important countermeasures, and patching is strongly advised.

Administrators should apply the patches promptly, as exploitation requires spoofed traffic and precise timing. While authoritative servers themselves are not directly compromised, the risk to cache integrity warrants urgent remediation and best-practice defenses to minimize impact.

 

Arstechnica

Notícias relacionadas

Armazenamento em medidores: nova fronteira de segurança
IA acelera ataques; defesas precisam evoluir
Rivais expõem operadores do Lumma Stealer 2025
Futurecom 2025: Tendências Digitais
IoT, streaming e fraudes em pauta no Congresso
Telecom em Santa Rita gera 3 mil empregos

O ISP.Tools sobrevive graças aos anúncios.

Considere desativar seu bloqueador de anúncios.
Prometemos não ser intrusivos.

Consentimento de cookies

Usamos cookies para melhorar sua experiência em nosso site.

Ao usar nosso site, você concorda com os cookies. Saiba mais sobre o site