Re: Waiting for BIND security announcement



[freebsd-security@ CC'ed to avoid answering the same there again
shorly :) - if following up, please drop either freebsd-questions or
freebsd-securiy to avoid "spamming" both lists]

On 2007.07.24 18:15:43 -0500, Jeffrey Goldberg wrote:

As I'm sure many people know there is a newly discovered BIND vulnerability
allowing cache injection (pharming). See

http://www.isc.org/index.pl?/sw/bind/bind-security.php

for details.

The version of bind on 6.2, 9.3.3, looks like it is vulnerable (along with
many other versions). It's not particularly an issue for me since my name
servers aren't publicly queryable, but I am curios about how things like
security problems in
src/contrib get handled in FreeBSD.

Yes, the FreeBSD Security Team and the FreeBSD BIND maintainer are
aware of the issue and are working on fixing it in FreeBSD as soon as
possible.

More details about the issue can be found at:
http://www.isc.org/sw/bind/bind-security.php .

Our general security handling policies can be found at:
http://security.FreeBSD.org/ .

--
Simon L. Nielsen
FreeBSD Deputy Security Officer

Attachment: pgpnq5d9cNliW.pgp
Description: PGP signature



Relevant Pages

  • RE: PAWS security vulnerability
    ... FreeBSD security list" isn't grammatically correct. ... "I told you to post the patch and info to the appropriate FreeBSD security ... "...This point and others are often discussed on the mailing lists, ...
    (freebsd-questions)
  • Changes to FreeBSD security support policy
    ... for tracking security fixes to FreeBSD 4.3-RELEASE: ... This eliminates support for the class of vulnerabilities exploitable ...
    (FreeBSD-Security)
  • RE: FreeBSD Security Survey
    ... Your also ignoring the fact that many security holes are a lot ... queries to this server to the NAS only. ... server with a new version of FreeBSD. ... Your survey responses lack any responses that indicate that leaving ...
    (freebsd-questions)
  • gateway security?
    ... some discussions of general security in a LAN environment with a FreeBSD ... headless gateway sits in a dark closet, ...
    (FreeBSD-Security)
  • [UNIX] FreeBSD Ports libkvm Security Vulnerabilities
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The FreeBSD ports asmon, ascpu, bubblemon, wmmon, and wmnet2 can be ... 2002 - Coordinated public disclosure by FreeBSD and iDEFENSE ...
    (Securiteam)