Re: libc flaw: BIND 9 closes most holes but also opens one

From: Brett Glass (brett@lariat.org)
Date: 06/29/02


Date: Sat, 29 Jun 2002 15:52:12 -0600
To: Doug Barton <DougB@FreeBSD.ORG>
From: Brett Glass <brett@lariat.org>

At 03:44 PM 6/29/2002, Doug Barton wrote:

> Non sequitur. I was responding to your claim that libbind was fixed
>only in 8.3.3. You are categorically wrong on that point.

Not unless ISC is lying, which of course it would have no
reason to do. See

http://marc.theaimsgroup.com/?l=bind-announce&m=102527570707030&w=2

which says that libbind was fixed between 8.3.2 and 8.3.3.

> Only if you're using something that links against it. IMO you're better
>off just not having [libbind] around.

Some things link with it. I believe that Sendmail is among them.

--Brett

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: libc flaw: BIND 9 closes most holes but also opens one
    ... At 03:56 PM 6/29/2002, Doug Barton wrote: ... The URL I left in the quotation above is the ... That's not the version of libbind that's in 9.2.1. ... with "unsubscribe freebsd-security" in the body of the message ...
    (FreeBSD-Security)
  • Re: named 8.3.2-T1B vulnerable?
    ... At 06:15 PM 6/29/2002, Doug Barton wrote: ... libbind has the same resolver bug as our libc did. ...
    (FreeBSD-Security)