Re: named 8.3.2-T1B vulnerable?

From: Jeff Ito (jeffi@rcn.com)
Date: 06/30/02


From: "Jeff Ito" <jeffi@rcn.com>
To: <security@freebsd.org>
Date: Sun, 30 Jun 2002 14:09:42 -0400


> I've a question about replacing with PORT_REPLACES_BASE_BIND8.
>
> If today I install BIND 8.3.3 from the port with that option it will
> overwrite the system one but next time I'll do a buildworld /
> installworld I'll get again 8.3.2-T1B or whatever RELENG_4(_6) will
> have that time.. right ?

Yes,
see /etc/make.conf to prevent this

#NO_BIND= true # do not build BIND

> More, I'll get an entry in the installed packages database for BIND
> 8.3.3 that is "dangerous", since if I'll ever pkg_delete it I'll lost
> the real/overwritten BIND...
>
> Is possible to "make install" it without making an entry in pkgdb ?
>

pkg_add has -R, I'm not certain about doing the same with make install,
but you can always delete the entry from /var/db/pkg/
 
 --
>
> bye!
>
> Ale
>

HTH,
Jeff

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: logrotate failure
    ... 'named' because bind wasn't installed. ... I guess most folks weren't bit because they do install bind. ... You might want to check to see if you still have a bind logrotate file ... I repeat, no upgrade, fresh install. ...
    (Fedora)
  • Re: named 8.3.2-T1B vulnerable?
    ... > If today I install BIND 8.3.3 from the port with that option it will ... > overwrite the system one but next time I'll do a buildworld / ... bind 8.3.3 import on -current. ... name of the port from foo-version to foo-system-version when installing ...
    (FreeBSD-Security)
  • FreeBSD Security Advisory: FreeBSD-SA-01:18.bind
    ... BIND is an implementation of the Domain Name Service protocols. ... assist the ability of attackers to exploit the primary vulnerability ... the bind8 port in the ports collection ... If you have chosen to install BIND from the ports collection and are ...
    (FreeBSD-Security)
  • Re: bind9 prevents external access
    ... I have now installed resolvconf and after rebooting resolvconf ... nameserver: 127.0.0.1 ... >> the allow-recursion part was only to filter for whom your bind will ... A fresh install should resolve names normally. ...
    (Debian-User)
  • Question about Bind
    ... I did not realise installing FreeBSD would automatically install Bind 9.3. ... # Enable network daemons for user convenience. ...
    (freebsd-questions)