Belangrijk nieuws voor mensen die bind als *resolver* gebruiken (en met name als dat door mogelijke malicious clients is) .
Open resolvers voor de wereld zijn al een tijdlang niet zo'n geweldig idee, en nu nog minder.
Resolver en authoritive DNS moeten ook niet op dezelfde machine .
Van isc.org:
http://www.isc.org/software/bind/adv...s/cve-2011-tbd
BIND 9 Resolver crashes after logging an error in query.c
Organizations across the Internet are reporting crashes interrupting service on BIND 9 nameservers performing recursive queries. Affected servers crash after logging an error in query.c with the following message: "INSIST(! dns_rdataset_isassociated(sigrdataset))" Multiple versions are reported as being affected, including all currently supported release versions of ISC BIND 9. ISC is actively investigating the root cause and working to produce patches which avoid the crash. Further information will be made available soon.
CVE:
CVE-2011-TBD
Document Version:
1.0
Posting date:
16 Nov 2011
Program Impacted:
BIND
Versions affected:
Multiple version of BIND 9. Specific versions under investigation
Severity:
Serious
Exploitable:
Unknown

Likes:


Quote

