From owner-freebsd-security@FreeBSD.ORG Fri Jan 28 18:13:02 2005 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3D22A16A4CE for ; Fri, 28 Jan 2005 18:13:02 +0000 (GMT) Received: from rwcrmhc13.comcast.net (rwcrmhc13.comcast.net [204.127.198.39]) by mx1.FreeBSD.org (Postfix) with ESMTP id 2166843D41 for ; Fri, 28 Jan 2005 18:13:02 +0000 (GMT) (envelope-from DougB@freebsd.org) Received: from lap (c-24-130-110-32.we.client2.attbi.com[24.130.110.32]) by comcast.net (rwcrmhc13) with SMTP id <20050128181301015009oplle>; Fri, 28 Jan 2005 18:13:01 +0000 Date: Fri, 28 Jan 2005 10:13:00 -0800 (PST) From: Doug Barton To: Mipam In-Reply-To: Message-ID: <20050128101001.N2359@ync.qbhto.arg> References: Organization: http://www.FreeBSD.org/ X-message-flag: Outlook -- Not just for spreading viruses anymore! MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed cc: freebsd-security@freebsd.org Subject: Re: fbsd not vulnerable to recent bind issues? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 28 Jan 2005 18:13:02 -0000 On Fri, 28 Jan 2005, Mipam wrote: > Hi, > > Recently some security issues with bind have come up. > NetBSD patched it's version of 9.3.0: > > http://mail-index.netbsd.org/source-changes/2005/01/27/0009.html > > Is the version in RELENG_5 not affected? > (ftp://ftp.isc.org/isc/bind/9.3.0/9.3.0-patch1) Our version does have the vulerability, however the nature of the vulnerability is such that it's incredibly unlikely that our users would be affected. That said, I am currently working with the 9.3.1 beta sources to be ready to upgrade promptly, and if 9.3.1-REL doesn't come out "soon," I'll import the patch. What I can do today is patch the port, stay tuned for that. Doug -- This .signature sanitized for your protection