[Fwd: [Bug 1174] New: bind 9.3.0 remote vulnerability]
Dan Osterrath <[email protected]> Thu, 27 Jan 2005 07:18:54 +0100
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
If anyone is interested... -------- Original-Nachricht -------- Betreff: [Bug 1174] New: bind 9.3.0 remote vulnerability Datum: Wed, 26 Jan 2005 23:16:50 -0700 (MST) Von: [email protected] Antwort an: BLFS Book Maintenance List <[email protected]> An: [email protected] http://blfs-bugs.linuxfromscratch.org/show_bug.cgi?id=1174 Summary: bind 9.3.0 remote vulnerability Product: Beyond LinuxFromScratch Version: SVN URL: http://www.kb.cert.org/vuls/id/938617 In bind 9.3.0 theres a vulnerability that causes an remote attacker to exit the daemon. ISC has released version 9.3.1. A patch against 9.3.0 is also available. As a workaround turn of dnssec validation with: "dnssec-enable no;" Note: This bug has only low severity as by default dnssec validation is off by default. -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page