From owner-freebsd-current Wed Nov 17 11:10:31 1999 Delivered-To: freebsd-current@freebsd.org Received: from rover.village.org (rover.village.org [204.144.255.49]) by hub.freebsd.org (Postfix) with ESMTP id C7B3414C31 for ; Wed, 17 Nov 1999 11:10:27 -0800 (PST) (envelope-from imp@harmony.village.org) Received: from harmony.village.org (harmony.village.org [10.0.0.6]) by rover.village.org (8.9.3/8.9.3) with ESMTP id MAA07871; Wed, 17 Nov 1999 12:10:26 -0700 (MST) (envelope-from imp@harmony.village.org) Received: from harmony.village.org (localhost.village.org [127.0.0.1]) by harmony.village.org (8.9.3/8.8.3) with ESMTP id MAA18303; Wed, 17 Nov 1999 12:10:42 -0700 (MST) Message-Id: <199911171910.MAA18303@harmony.village.org> To: trouble@netquick.net Cc: current@freebsd.org Subject: Re: BIND update In-reply-to: Your message of "Wed, 17 Nov 1999 14:15:05 EST." <3832FEB9.4B9B9F52@netquick.net> References: <3832FEB9.4B9B9F52@netquick.net> <199911171850.LAA18026@harmony.village.org> Date: Wed, 17 Nov 1999 12:10:42 -0700 From: Warner Losh Sender: owner-freebsd-current@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG -----BEGIN PGP SIGNED MESSAGE----- In message <3832FEB9.4B9B9F52@netquick.net> TrouBle writes: : just a quick note, where do i find the information needed about the bind : problem i face in 3.3-RELEASE if any ?? You can find it at the BIND web site. FreeBSD has Bind 8.1.2. - From the chart at http://www.isc.org/products/BIND/bind-security-19991108.html we see solinger DoS maxfd DoS w/ workaround naptr possible problem when users can modify zone files maxdname sprintf overflow that is unlikely to trigger elevated privs, but may be used to crash servers. The NXT exploit is not present in 8.1.x, so that remote exploit is not present. More complete information and fixes will be forthcoming. Warner -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv Comment: Processed by Mailcrypt 3.4, an Emacs/PGP interface iQCVAwUBODL9l1UuHi5z0oilAQGNWwQAo/BE8oSXvz7IhGBuLYz4i+7BxOXnM6cG zVESLfsv9WapRn8PXu1+suppa2RHcyu0ynGeWPjoN0SAX3IElTI2vPrwCT9UG8j0 526wcOm+VCvJjxMah+0ix50oUkMRRvdnV5Kae4Q4ZQCQiUOwyHWQTxV5tlljii+y 4x9y/UiCS5g= =X4s/ -----END PGP SIGNATURE----- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-current" in the body of the message