Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 28 Jun 2002 18:31:06 -0700 (PDT)
From:      Doug Barton <DougB@FreeBSD.org>
To:        Robert Watson <rwatson@FreeBSD.org>
Cc:        cvs-committers@FreeBSD.org, <cvs-all@FreeBSD.org>
Subject:   Re: cvs commit: ports/net/bind8 Makefile distinfo         ports/net/bind8/files patch-aa
Message-ID:  <20020628182743.I16738-100000@zoot.corp.yahoo.com>
In-Reply-To: <Pine.NEB.3.96L.1020628205629.30000A-100000@fledge.watson.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Fri, 28 Jun 2002, Robert Watson wrote:

>
> On Fri, 28 Jun 2002, Doug Barton wrote:
>
> > dougb       2002/06/28 17:05:17 PDT
> >
> >   Modified files:
> >     net/bind8            Makefile distinfo
> >     net/bind8/files      patch-aa
> >   Log:
> >   Upgrade to 8.3.3, the latest from ISC. This release fixes the
> >   libbind bug, and adds logging for people who attempt to exploit
> >   it to named. Also improves logging for named-xfer, and adds
> >   features to ndc to attempt to preserve command line arguments
> >   that named was started with.
> >
> >   All users of BIND 8 are HIGHLY encouraged to upgrade to this version.
>
> It's worth noting that for most consumers of bind, this won't provide any
> added protection against the resolver vulnerability at all, so it
> shouldn't be over-sold :-).

Actually it's still debatable just how possible it is to exploit the
resolver bug at all, but that's another topic. In addition to the logging
improvements for people trying to exploit the bug, users of bind 8 are
still encouraged to upgrade to this version just in case they missed all
the other announcements of the importance of upgrading to the latest
version of bind 8 in the first place.


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe cvs-all" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020628182743.I16738-100000>