• Blog
  • California Consumer Privacy Act (CCPA)
  • Cart
  • Checkout
  • Contact
  • DMCA
  • Home
  • My account
  • Privacy Policy
  • Shop
Thursday, October 23, 2025
  • Login
Buyer's Insight
  • Home
  • Top Stories
  • Local News
    • Politics
    • Business & Economy
    • Entertainment
    • Sports
  • Health
  • Lifestyle
  • Science & Environment
  • Technology
  • Review Radar
    • Weight Loss Products Reviews
    • Forex Trading
    • Shop
  • Contact
No Result
View All Result
  • Home
  • Top Stories
  • Local News
    • Politics
    • Business & Economy
    • Entertainment
    • Sports
  • Health
  • Lifestyle
  • Science & Environment
  • Technology
  • Review Radar
    • Weight Loss Products Reviews
    • Forex Trading
    • Shop
  • Contact
No Result
View All Result
Buyer's Insight
No Result
View All Result

Cache poisoning vulnerabilities found in 2 DNS resolver apps

James Walker by James Walker
October 23, 2025
in Technology
Reading Time: 1 min read
0
0
SHARES
0
VIEWS

“Under specific circumstances, due to a weakness in the pseudo-random number generator (PRNG) used, it is possible for an attacker to predict the source port and request ID that BIND will use,” BIND developers wrote in Wednesday’s disclosure. “BIND may be required to cache responses from attackers, if the impersonation is successful.”

CVE-2025-40778 also raises the possibility of relaunching cache poisoning attacks.

“In certain circumstances, BIND is too lenient when accepting response records, allowing an attacker to inject false data into the cache,” the developers explained. “Forged records can be injected into the cache during a query, which can potentially affect the resolution of future queries.”

Even in such cases, the consequences would be much more limited than the scenario envisioned by Kaminsky. One reason for this is that authoritative servers themselves are not vulnerable. Additionally, as noted here and here by Red Hat, various other countermeasures against cache poisoning remain intact. They include DNSSEC, a protection that requires DNS records to be digitally signed. Additional measures take the form of rate limiting and server firewalling, which are considered best practices.

“As the exploitation is non-trivial, requires network-level impersonation and precise timing, and only affects cache integrity without server compromise, the vulnerability is considered important rather than critical,” Red Hat wrote in its CVE-2025-40780 disclosure.

The vulnerabilities can nevertheless potentially cause damage in certain organizations. Patches for all three should be installed as soon as possible.

Post Views: 5
Tags: appsCacheDNSpoisoningresolvervulnerabilities
Previous Post

Romeo Beckham shares photo with ex Kim Turnbull on Instagram

Next Post

Reddit accuses Perplexity of stealing user posts, widening data rights battle with AI industry

Related Posts

Technology

Quantum Threat to Bitcoin Rises as Google Reveals Latest Advance

October 23, 2025
Technology

This new Battlefield 6 skin is causing a meltdown

October 23, 2025
Technology

Next year’s A20 chip could drive iPhone prices even higher

October 23, 2025
Technology

The Samsung Galaxy XR is the first Android XR headset, now on sale for $1,800

October 23, 2025
Technology

NFL owners meeting sees deals with ESPN, Amazon and EA approved

October 23, 2025
Technology

Apple confirms it has removed controversial dating apps Tea and TeaOnHer from the App Store

October 23, 2025
Next Post

Reddit accuses Perplexity of stealing user posts, widening data rights battle with AI industry

News Net Daily

  • Home
  • California Consumer Privacy Act (CCPA)
  • Contact
  • DMCA
  • Privacy Policy

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Top Stories
  • Local News
    • Politics
    • Business & Economy
    • Entertainment
    • Sports
  • Health
  • Lifestyle
  • Science & Environment
  • Technology
  • Review Radar
    • Weight Loss Products Reviews
    • Forex Trading
    • Shop
  • Contact