Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 14 Feb 2001 09:43:55 -0800
From:      Kris Kennaway <kris@obsecurity.org>
To:        Tom <tom@uniserve.com>
Cc:        Terry Rossi <tpr@pics.com>, Michael DeMutis <maillist@2gen.net>, freebsd-stable@FreeBSD.ORG
Subject:   Re: Named crashing
Message-ID:  <20010214094355.C72669@mollari.cthul.hu>
In-Reply-To: <Pine.BSF.4.05.10102140834130.14937-100000@shell.uniserve.ca>; from tom@uniserve.com on Wed, Feb 14, 2001 at 08:36:24AM -0800
References:  <EE976316F1109441957E739E180A5BF202D113@pics2000.hq.pics.com> <Pine.BSF.4.05.10102140834130.14937-100000@shell.uniserve.ca>

next in thread | previous in thread | raw e-mail | index | archive | help

--jousvV0MzM2p6OtC
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

On Wed, Feb 14, 2001 at 08:36:24AM -0800, Tom wrote:

>   Some named version have a nice remote crash bug, and there are people
> who are going and crashing all the DNS servers they can find.

It's much worse than that - as you'd know if you read the FreeBSD
security advisories (01:18 in this case)

>   3.5-STABLE seems to have Bind 8.2.2, which is vunerable.  4.2-RELEASE

No it doesn't.

> sould also seem to have a vunerable version.  See http://www.isc.org from

Yes it does - see the above advisory.

Kris

--jousvV0MzM2p6OtC
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.4 (FreeBSD)
Comment: For info see http://www.gnupg.org

iD8DBQE6isPaWry0BWjoQKURArB+AJ9dPG6kxTDmoS/L3CSHETQlFQFH0QCg9qT3
WRLhapY2dfEnpoDQZOGLjcY=
=Zb+0
-----END PGP SIGNATURE-----

--jousvV0MzM2p6OtC--


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-stable" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010214094355.C72669>