Mac OS X v10.5.5 and Security Update 2008-006 released
Finally, Apple had released Mac OS X v10.5.5 with Security Update 2008-006 and immediately the mDNSResponder get fixed accordingly. It has been a while for Apple to come up with the correct fix to solve DNS poisoning attack. Being advised by Dan Kaminsky, mDNSResponder now implementing source port and transaction ID randomization to improve resilience against cache poisoning attacks. Besides that, this Security Update updates other critical vulnerabilities such as OpenSSH, Kernel, Finder, Disk Utils and many more. For more information, please refer to http://support.apple.com/kb/HT3137.





