Likes Likes:  0
Resultaten 1 tot 5 van de 5
Geen
  1. #1
    John
    BIND 9.2.2 Vulnerabilities?
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    BIND 9.2.2 Vulnerabilities?


    The ISC website lists the following as of today:

    http://www.isc.org/products/BIND/bind-security.html

    "ISC has discovered or has been notified of several bugs which can result
    in vulnerabilities of varying levels of severity in BIND as distributed by
    ISC. Upgrading to BIND version 9.2.2 is strongly recommended. If you
    cannot upgrade, BIND 8.3.4, 8.2.7, and 4.9.11 are available."

    9.2.2 apparently was just released yesterday though I've seen no
    discussion about any specific vulnerabilities.

    The matrix at the bottom of the list shows two vulnerabilities, one with
    openssl, the other with libbind.

    Can anyone elaborate on what's happened here? I susbscribe to the BIND
    mailing list and haven't heard anything about this issue.

    Thx



  2. #2
    David Kennedy CISSP
    BIND 9.2.2 Vulnerabilities?
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: BIND 9.2.2 Vulnerabilities?

    At 01:04 PM 3/4/03 -0600, John wrote:


    Heavily edited from the bind-announce message:


    >>>>


    <excerpt>To: bind-announce@isc.org

    From: Mark_Andrews@isc.org

    Subject: BIND 9.2.2 is now available.

    Date: Tue, 04 Mar 2003 12:51:37 +1100

    List-Id: <<bind-announce.isc.org>



    BIND 9.2.2 is now available. This is a maintenance release of BIND
    9.2.

    It contains no new features.


    BIND 9.2.2 can be downloaded from


    ftp://ftp.isc.org/isc/bind9/9.2.2/bind-9.2.2.tar.gz


    The PGP signature of the distribution is at


    ftp://ftp.isc.org/isc/bind9/9.2.2/bind-9.2.2.tar.gz.asc


    The signature was generated with the ISC public key, which is

    available at <<http://www.isc.org/ISC/isckey.txt>.


    A list of changes made since 9.2.0 follows. For earlier changes,

    see the file CHANGES in the distribution.



    1356. [security] Support patches OpenSSL libraries.

    http://www.cert.org/advisories/CA-2002-23.html

    1349. [security] Minimum OpenSSL version now 0.9.6e (was 0.9.5a).

    http://www.cert.org/advisories/CA-2002-23.html

    1318. [bug] libbind: Remote buffer overrun.


    </excerpt><<<<<<<<


    (many non-security fixes/bug edited out by DMK)




    --

    Regards,


    David Kennedy CISSP /"\

    Director of Research Services, \ / ASCII Ribbon Campaign

    TruSecure Corp. http://www.trusecure.com X Against HTML Mail

    Protect what you connect; / \

    Look both ways before crossing the Net.



  3. #3
    Gerhard den Hollander
    BIND 9.2.2 Vulnerabilities?
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: BIND 9.2.2 Vulnerabilities?

    * David Kennedy CISSP <david.kennedy@acm.org> (Tue, Mar 04, 2003 at 04:26:05PM -0500)
    > At 01:04 PM 3/4/03 -0600, John wrote:
    >
    > Heavily edited from the bind-announce message:


    So, does this mean that we can continue running 9.2.1 , or should we all
    rush out and upgrade to 9.2.2 as there is a security leak waiting to be
    exploited ?

    Kind regards,
    --
    Gerhard den Hollander Phone :+31-10.280.1515
    Global IT Support manager Direct:+31-10.280.1539
    Jason Geosystems BV Fax :+31-10.280.1511
    (When calling please note: we are in GMT+1)
    gdenhollander@jasongeo.com POBox 1573
    visit us at http://www.jasongeo.com 3000 BN Rotterdam
    JASON.......#1 in Reservoir Characterization The Netherlands

    This e-mail and any attachment is/are intended solely for the named
    addressee(s) and may contain information that is confidential and privileged.
    If you are not the intended recipient, we request that you do not
    disseminate, forward, distribute or copy this e-mail message.
    If you have received this e-mail message in error, please notify us
    immediately by telephone and destroy the original message.

  4. #4
    John
    BIND 9.2.2 Vulnerabilities?
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: BIND 9.2.2 Vulnerabilities?


    That was really what I was trying to get at. If there are vulnerabilities
    I don't think that they are being discussed in a manner that brings this
    to the attention of those of us who are running 9.2.1. It seems that the
    announcement was rather low-key and I stumbled across this information on
    the website almost by mistake.

    On Wed, 5 Mar 2003, Gerhard den Hollander wrote:
    >
    > So, does this mean that we can continue running 9.2.1 , or should we all
    > rush out and upgrade to 9.2.2 as there is a security leak waiting to be
    > exploited ?



  5. #5
    Scott Wunsch
    BIND 9.2.2 Vulnerabilities?
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: BIND 9.2.2 Vulnerabilities?

    On Wed, 05-Mar-2003 at 15:46:41 -0600, John wrote:

    > That was really what I was trying to get at. If there are vulnerabilities
    > I don't think that they are being discussed in a manner that brings this
    > to the attention of those of us who are running 9.2.1. It seems that the
    > announcement was rather low-key and I stumbled across this information on
    > the website almost by mistake.


    I'm rather puzzled by it too :-). Some days before before the 9.2.2
    release, my 9.2.1 nameserver was getting repeatedly killed (with an
    assertion failure) by a stream of DNS queries over TCP from one of our
    users. Every time I restarted it, it would die again within a few seconds.
    We "solved" the problem by blocking traffic from the customer who was
    generating all the TCP queries.

    I reported this to ISC, and was informed that this was fixed in 9.2.2rc1
    (but my request for more details was ignored).

    So, if nothing else, I consider 9.2.2 to be a fix for a denial of service
    problem.

    --
    Take care,
    Scott \\'unsch

    .... Write all complaints in this box (in triplicate): [] Thank You!

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics