Release date:
Updated on:
Affected Systems:
OpenDNSSEC
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56679
OpenDNSSEC is an open-source solution that implements DNSSEC to protect zone data before it is released to an authenticated Domain Name Server.
OpenDNSSEC uses the 'curl' API in an insecure way. There is a security bypass vulnerability in its implementation. It successfully exploits a server that allows attackers to perform man-in-the-middle attacks or simulate user trust.
<* Source: Alessandro Ghedini
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
OpenDNSSEC
----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.opendnssec.org/files/source/