{"id":103950,"date":"2022-05-04T15:37:02","date_gmt":"2022-05-04T13:37:03","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-uclibc-i-uclibc-ng-pozvolyayushhaya-podmenit-dannye-v-keshe-dns"},"modified":"2022-05-04T15:37:02","modified_gmt":"2022-05-04T13:37:03","slug":"uyazvimost-v-uclibc-i-uclibc-ng-pozvolyayushhaya-podmenit-dannye-v-keshe-dns","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-uclibc-i-uclibc-ng-pozvolyayushhaya-podmenit-dannye-v-keshe-dns","title":{"rendered":"Vulnerability in uClibc and uClibc-ng, allowing data to be altered in the DNS cache.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A vulnerability has been identified in the standard C libraries uClibc and uClibc-ng, used in many embedded and portable devices, that allows for the injection of fake data into the DNS cache. This can be exploited to substitute the cached IP address of any domain and redirect requests for that domain to an attacker\u2019s server.     <\/p>\n<p>The issue affects various Linux firmware for routers, access points, and Internet of Things devices, as well as Linux distributions for embedded systems, such as OpenWRT and Embedded Gentoo. It has been noted that the vulnerability manifests in devices from many manufacturers (for example, uClibc is used in firmware for Linksys, Netgear, and Axis), but as the vulnerability in uClibc and uClibc-ng remains unpatched, detailed information about specific devices and manufacturers affected by the issue is not yet disclosed.    <\/p>\n<p>The vulnerability is caused by the use of predictable transaction identifiers in the code for sending DNS queries. The DNS request ID is chosen by simply incrementing a counter without any additional port number randomization, which allows for DNS cache poisoning through preemptive sending of UDP packets containing fake responses (the response will be accepted if it arrives before the real answer and includes the correct ID). <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/dts-los-angeles\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3809\">server<\/a> In contrast to the method proposed by Kaminsky in 2008, the transaction identifier does not even need to be guessed, as it is inherently predictable (initially set to 1, it increments with each request rather than being randomly selected).     <center><img decoding=\"async\" alt=\"Vulnerability in uClibc and uClibc-ng, allowing data to be altered in the DNS cache.\" src=\"\/wp-content\/uploads\/2022\/05\/29cd1ae29db2776f3121eda961bd8c4d.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<p>The specification for protection against identifier guessing recommends additionally employing randomization of source network port numbers from which DNS requests are sent, which compensates for the insufficiently large identifier size. When enabling port randomization for generating fake responses, it is necessary to guess not only the 16-bit identifier but also the network port number. In uClibc and uClibc-ng, such randomization was not explicitly included (as a random source UDP port was not specified when calling bind), and its application depended on the operating system's settings.     <\/p>\n<p>When randomization of ports is disabled, determining the incrementing request identifier is considered a trivial task. However, even when randomization is applied, the attacker only needs to guess the network port from the range of 32768\u201360999, for which they can use a massive simultaneous sending of fake responses across different network ports.    <center><img decoding=\"async\" alt=\"Vulnerability in uClibc and uClibc-ng, allowing data to be altered in the DNS cache.\" src=\"\/wp-content\/uploads\/2022\/05\/ba16f63c3eab657ee687a893744ae972.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>The issue has been confirmed in all current releases of uClibc and uClibc-ng, including the latest versions uClibc 0.9.33.2 and uClibc-ng 1.0.40. In September 2021, information about the vulnerability was sent to CERT\/CC for coordinated preparation of fixes. In January 2022, details about the problem were shared with over 200 manufacturers collaborating with CERT\/CC. In March, an attempt was made to reach out separately to the uClibc-ng project maintainer, but he replied that he was unable to fix the vulnerability independently and recommended publicly disclosing the issue, hoping to receive assistance in developing a fix from the community. NETGEAR announced the release of an update addressing the vulnerability.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=57131\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u044b\u0445 \u0421\u0438-\u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 uClibc \u0438 uClibc-ng, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0445 \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0438 \u043f\u043e\u0440\u0442\u0430\u0442\u0438\u0432\u043d\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE \u043d\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u0432 \u043a\u044d\u0448 DNS, \u0447\u0442\u043e \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u043b\u044f \u043f\u043e\u0434\u043c\u0435\u043d\u044b \u0432 \u043a\u044d\u0448\u0435 IP-\u0430\u0434\u0440\u0435\u0441\u0430 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u043e\u0433\u043e \u0434\u043e\u043c\u0435\u043d\u0430 \u0438 \u043f\u0435\u0440\u0435\u043d\u0430\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0439 \u043a \u0434\u043e\u043c\u0435\u043d\u0443 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0430. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 Linux-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438 \u0434\u043b\u044f \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0442\u043e\u0440\u043e\u0432, \u0442\u043e\u0447\u0435\u043a \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u0438 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442\u0430-\u0432\u0435\u0449\u0435\u0439, \u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":103951,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103950","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u044b\u0445 \u0421\u0438-\u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 uClibc \u0438 uClibc-ng, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0445 \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0438 \u043f\u043e\u0440\u0442\u0430\u0442\u0438\u0432\u043d\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE \u043d\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u0432 \u043a\u044d\u0448 DNS, \u0447\u0442\u043e \u043c\u043e\u0436\u043d\u043e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-uclibc-i-uclibc-ng-pozvolyayushhaya-podmenit-dannye-v-keshe-dns\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 uClibc \u0438 uClibc-ng, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u0434\u0430\u043d\u043d\u044b\u0435 \u0432 \u043a\u044d\u0448\u0435 DNS | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u044b\u0445 \u0421\u0438-\u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 uClibc \u0438 uClibc-ng, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0445 \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0438 \u043f\u043e\u0440\u0442\u0430\u0442\u0438\u0432\u043d\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE \u043d\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u0432 \u043a\u044d\u0448 DNS, \u0447\u0442\u043e \u043c\u043e\u0436\u043d\u043e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-uclibc-i-uclibc-ng-pozvolyayushhaya-podmenit-dannye-v-keshe-dns\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-05-04T13:37:03+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-05-04T13:37:03+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerability in uClibc and uClibc-ng allowing data spoofing in the DNS cache | ProHoster","description":"A vulnerability (CVE not assigned) has been identified in the standard C libraries uClibc and uClibc-ng, used in many embedded and portable devices, allowing the injection of spoofed data into the DNS cache.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-uclibc-i-uclibc-ng-pozvolyayushhaya-podmenit-dannye-v-keshe-dns","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 uClibc \u0438 uClibc-ng, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u043c\u0435\u043d\u0438\u0442\u044c \u0434\u0430\u043d\u043d\u044b\u0435 \u0432 \u043a\u044d\u0448\u0435 DNS | ProHoster","og:description":"\u0412 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u044b\u0445 \u0421\u0438-\u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 uClibc \u0438 uClibc-ng, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0445 \u0432\u043e \u043c\u043d\u043e\u0433\u0438\u0445 \u0432\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0438 \u043f\u043e\u0440\u0442\u0430\u0442\u0438\u0432\u043d\u044b\u0445 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE \u043d\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u0432 \u043a\u044d\u0448 DNS, \u0447\u0442\u043e \u043c\u043e\u0436\u043d\u043e.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-uclibc-i-uclibc-ng-pozvolyayushhaya-podmenit-dannye-v-keshe-dns","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-05-04T13:37:03+00:00","article:modified_time":"2022-05-04T13:37:03+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103950","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-22 16:01:28","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-05-04 13:37:57","updated":"2026-02-22 16:01:28","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/103950","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=103950"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/103950\/revisions"}],"predecessor-version":[{"id":162337,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/103950\/revisions\/162337"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/103951"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=103950"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=103950"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=103950"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}