News broke yesterday that Systemd, the Linux world’s favorite init monolith, can be potentially crashed or hijacked by malicious DNS servers. Tim Helming, Director of Product Managementat DomainTools commented below.
Tim Helming, Director of Product Management at DomainTools:
“While any buffer overflow that allows remote code execution is serious, there are a couple of mitigating factors which should (we hope) keep the damage level relatively low for this vulnerability/exploit. Besides the obvious (a patch is available for anyone running the affected versions of systemd), the exploit depends on a malicious (or compromised) DNS server. So the attacker would have to go to some trouble to exploit this vulnerability, by pointing potential victims to a malicious server. The easiest way to do this would be to set up the server as the authoritative name server for domain(s) controlled by the attacker. Otherwise, the attacker has to find another way to insert their server into the data flow, or to compromise other peoples’ DNS servers to enable the malicious response payloads. So, patching is important, but it would take some doing to make this exploit a widespread phenomenon.”
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.