Along with Heartbleed and others, the bug is the latest of several serious flaws found in the backbone of the internet. Kaminsky pointed out that ironically, the latest hole was coded into Gnu DNS libraries just months after he corrected other serious DNS flaws in 2008. He's advising anybody running Linux servers to "patch this bug with extreme prejudice." (Android devices aren't affected, by the way.)

Nobody is sure yet if the code can be executed remotely. However, Redhat, which discovered the vulnerability along with Google, said that "a back of the envelope analysis shows that it should be possible to write correctly formed DNS responses with attacker controlled payloads that will penetrate a DNS cache hierarchy and therefore allow attackers to exploit machines behind such caches." However, the bug makes servers vulnerable to man-in-the-middle attacks right now, if hackers gain access to certain servers. That makes it what Kaminsky calls a "solid critical vulnerability by any normal standard." Now, the only question is whether things will get much worse.