Re: BIND update?



Hi Chris,

Chris Palmer schrieb:
So I'm not too worried about the lack of urgency from the FreeBSD security
team on this particular issue. It's not news that DNS is insecure and that
BIND has a bug. Nobody should have been depending on the security of DNS or
on a bulletproof BIND.

True words!
However, since the SecTeam of FreeBSD always did a great job, in this specific case, which had quite a huge coverage in the "press", at least a Heads Up to freebsd-security@ saying something like "Stay tuned for a patch folks, we're investigating" would have been appropriate.
When everybody tries to get mad, and that's what happened, a statement like that could have calmed things done in the first place.
But maybe I missed that heads up, 'cause I jumped into this discussion quite late...

Well, anyway, SecTeam, keep up the good work :)

Cheers,
./Marian

_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: BIND update?
    ... or criticism with a positive approach. ... the fact that DNS ... the BIND installation in the base is not intended to ... security advisories to write, FreeBSD ...
    (FreeBSD-Security)
  • Re: Local DNS Caching not caching on external interface
    ... I am very new to Bind and FreeBSD. ... I have just configured a Local DNS server using the built-in Bind ... query the caching name server from my local network. ...
    (freebsd-questions)
  • Re: Domain Name if None Registered?
    ... but that address is assigned to your consumer broadband router ... The computer is named "freebsd", ... Any programmer who owns a Unix system has to do some admin work, but I have no experience with DNS and BIND. ...
    (comp.unix.bsd.freebsd.misc)
  • [NEWS] BIND 9 DNS Cache Poisoning
    ... BIND 9 DNS Cache Poisoning ... source UDP port and DNS transaction ID can be effectively predicted. ... address of the target name server), and the destination UDP port (53 the ...
    (Securiteam)
  • [UNIX] Multiple Remote Vulnerabilities in BIND4 and BIND8
    ... ISS X-Force has discovered several serious vulnerabilities in the Berkeley ... Internet Name Domain Server (BIND). ... majority of DNS servers on the Internet. ... deployed recursive DNS servers on the Internet. ...
    (Securiteam)