Re: FreeBSD Security Advisory FreeBSD-SA-06:20.bind



Peter Thoenen wrote:
Just to verify as not mentioned in the security advisory, if you are
using both the BIND and OPENSSL ports with the REPLACE_BASE directive,
these don't apply correct?

Assuming you've updated to the 9.3.2-P1 version (ports version 9.3.2.1) of
BIND 9, then yes for the BIND part of the advisory. The BIND ports with
REPLACE_BASE will overwrite all the system binaries, and actually install a
couple things that the base doesn't (not that I'd expect anyone would need
or want them, I just don't like to muck with the ports more than absolutely
necessary).

For completeness sake, I should note that what I said up there is not 100%
accurate in the case where you have BIND 8 in the base (such as in
RELENG_4), and try to replace it with BIND 9, or vice versa. In that case,
you're better off first doing a build/installworld with the NO_BIND option
set in make.conf, removing all the old binaries, libs, and includes; and
then installing the port.

hth,

Doug

--

This .signature sanitized for your protection

_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • RE: nc help needed.
    ... You can even get Netcat to listen on the NETBIOS ports that are probably ... user can run a program that will bind to the NETBIOS ports. ...
    (Security-Basics)
  • Re: Waiting for BIND security announcement
    ... BIND is more than just named. ... BIND is there in contrib coz lot of stuff depends on it and so its best left there. ... BIND is also there in ports coz the one there offers you a lot more build time options, is newer, gets updates faster, and is also easier to get up and running with out of the box. ...
    (freebsd-questions)
  • Re: How to get acces to tcp portnumbers below 1024?
    ... ability to bind to reserved ports. ... As far as being special for a reason, that reason went away the first time ... He can bind to the ports in question either by ... man 7 IP for which capability needs to be set. ...
    (alt.os.linux.suse)
  • Re: nss_ldap and openldap importing
    ... majority of machines would benefit from it. ... of having BIND in the base). ... I don't see why building it from ports is difficult.. ... for Genesis Software - http://www.gsoft.com.au ...
    (freebsd-current)
  • Re: Questions regarding BIND
    ... > I'm using FreeBSD 4.9 and I have cvsup'd the ports and src tree. ... the default perfix and leave the system version of bind alone. ... This server will not be setup to be public ... If your nameserver can see the internet ...
    (freebsd-questions)