[Full-Disclosure] Fw: Bind 8 bug experience

From: Patrick Oonk (patrick.oonk@pine.nl)
Date: 11/15/02


From: patrick.oonk@pine.nl (Patrick Oonk)
Date: Fri, 15 Nov 2002 09:53:14 +0100

The ISC site is pretty messed up too:

BIND 8.3.3 is the latest version of ISC BIND 8. We strongly recommend
that you upgrade to BIND 9.2.1 or, if that is not immediately possible,
to BIND 8.3.2 due to certain security vulnerabilities in previous
^^^^^^^^^^^^^
versions. 8.3.3 contains a security fix in libbind. If you have BIND 8.x
you need to upgrade.

duh?

-- 
 Patrick Oonk    -   Pine Digital Security    -   patrick.oonk@pine.nl
 T:+31-70-3111010 - F:+31-70-3111011 - Read news at http://security.nl 
 PGPid A4E74BBF  fp A7CF 7611 E8C4 7B79 CA36  0BFD 2CB4 7283 A4E7 4BBF
 Excuse of the day: sounds like a Windows problem, try calling
 Microsoft support


Relevant Pages

  • Re: Somethings happening with named
    ... potential impact of an upgrade, and since this hasn't recurred I've left it ... and decided to keep an eye on things until it happens again. ... If someone could briefly explain the versioning used by bind, ... FreeBSD: The Power To Serve - http://www.FreeBSD.org ...
    (FreeBSD-Security)
  • Re: Errata for RedHat: how reliable?
    ... > I downloaded and applied all the errata listed at RH's site. ... > across the BIND site which told me that I *absolutely must* upgrade any ... Go for it with bind 9.2.1, if I were you, from source, with libsafe, ...
    (comp.os.linux.security)
  • Re: Errata for RedHat: how reliable?
    ... > I downloaded and applied all the errata listed at RH's site. ... > across the BIND site which told me that I *absolutely must* upgrade any ... Go for it with bind 9.2.1, if I were you, from source, with libsafe, ...
    (comp.os.linux.security)
  • RE: BIND 8.2.3 upgrade available
    ... TIA ... Subject: BIND 8.2.3 upgrade available ... I have also just upgraded the net/bind8 port, ...
    (FreeBSD-Security)
  • Re: [COVERT-2001-01] Multiple Vulnerabilities in BIND - FreeBSDImplications ?
    ... > Do I need to upgrade or am I ok? ... BIND vulnerabilities and which versions are affected for each one: ... BIND integrated, and 3.x-STABLE should be updated by tomorrow. ... The prebuilt packages directory at freebsd.org still had just 8.2.2-p7, ...
    (FreeBSD-Security)