[Fwd: [Bug 1174] New: bind 9.3.0 remote vulnerability]

Dan Osterrath <[email protected]> Thu, 27 Jan 2005 07:18:54 +0100
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
If anyone is interested...

-------- Original-Nachricht --------
Betreff: 	[Bug 1174] New: bind 9.3.0 remote vulnerability
Datum: 	Wed, 26 Jan 2005 23:16:50 -0700 (MST)
Von: 	[email protected]
Antwort an: 	BLFS Book Maintenance List <[email protected]>
An: 	[email protected]


http://blfs-bugs.linuxfromscratch.org/show_bug.cgi?id=1174

           Summary: bind 9.3.0 remote vulnerability
           Product: Beyond LinuxFromScratch
           Version: SVN
               URL: http://www.kb.cert.org/vuls/id/938617


In bind 9.3.0 theres a vulnerability that causes an remote attacker to exit the
daemon. ISC has released version 9.3.1. A patch against 9.3.0 is also available.
As a workaround turn of dnssec validation with:
 "dnssec-enable no;"

Note: This bug has only low severity as by default dnssec validation is off by
default.


-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page