200 Vendors Impacted By DNS Poisoning Flaw

Share post:

Researchers from security firm Nozomi Networks have uncovered a critical vulnerability in third-party code libraries used by hundreds of vendors.

The vulnerability is a DNS poisoning flaw. DNS poisoning allows attackers to replace the legitimate DNS lookup for a site with malicious IP addresses that can disguise as the real sites as they try to install malware.

In this case, the flaw allows attackers with access to the connection between an affected device and the internet to poison DNS requests used to translate domains to IP addresses.

The flaw is located in uClibc and uClibc fork uClibc-ng. The two libraries provide alternatives to the standard C library for embedded Linux, Nozom.

According to the researchers, 200 vendors incorporate at least one of the libraries into wares including Linksys WRT54G- Wireless-G Broadband Router, NetGear WG602 wireless router, and most Axis network cameras, embedded Gentoo, Buildroot, LEAF Bering uClibc, and Tuxscreen Linux Phone.

The sources for this piece include a story in ArsTechnica.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for week ending Friday April 19, 2024

On this episode Jen Ellis, co-chair of the Ransomware Task Force, talks about ways of fighting one of the biggest cyber threats to IT d

Cyber Security Today, April 19, 2024 – Police bust phishing rental platform, a nine-year old virus found on Ukrainian computers, and more

This episode reports on a threat actor targeting governments in the Middle East with a novel way of hiding malware is going international

Controversial expansion of US surveillance powers nears Senate vote

The US Senate is poised to vote on a significant expansion of Section 702 of the Foreign Intelligence...

Russian-linked hackers target U.S. and European water systems

A Russian military-affiliated hacking group, Sandworm, is suspected of coordinating recent cyberattacks on water utilities in the U.S.,...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways