Re: Bind vulnerability

From: Wes Peters (wes@softweyr.com)
Date: 02/23/01


Date: Fri, 23 Feb 2001 00:23:52 -0700
From: Wes Peters <wes@softweyr.com>
To: Peter Pentchev <roam@orbitel.bg>

Peter Pentchev wrote:
>
> On Thu, Feb 22, 2001 at 09:22:03AM -0600, George.Giles@mcmail.vanderbilt.edu wrote:
> > The bind vulnerability has been fixed in 4.2-current ?
>
> There is no such thing as 4.2-current.

4.2 is a place, -CURRENT is a direction.

The latest (several) bind vulnerability(s) existed in 4.2, but have been
fixed in -CURRENT (only for system developers, quite scary and unstable)
and -STABLE (useful for real work).

> The BIND vulnerability has been fixed in 4.2-STABLE, yes.

Technically, -STABLE is a direction also. But the bind vulnerability(s)
are fixed in -STABLE. Read the handbook about using cvsup.

-- 
            "Where am I, and what am I doing in this handbasket?"
Wes Peters                                                         Softweyr LLC
wes@softweyr.com                                           http://softweyr.com/
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: Somethings happening with named
    ... > If someone could briefly explain the versioning used by bind, ... is it worth upgrading to T9B (or whatever the latest ... You can install the bind8 port over your current bind ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: SSHD revelaing too much information.
    ... Does it even announce that it is BIND. ... as the will of the attacker or the tools used. ... Large effort for a short time gain. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: Somethings happening with named
    ... > Not the first time I face the following problem: ... > While everything seems to work properly: sendmail, ... What version of bind are you running. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: Trojan injected in my Freebsd 4.1-RELEASE
    ... I'd be interested in knowing what was exploited to install it. ... Could be BIND ... or telnetd. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: FreeBSD Security Advisory: FreeBSD-SA-01:18.bind
    ... > Why not make it default in the base system? ... The best workaround is not using BIND at all. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)

Loading