AplusWebMaster
Topic Starter
FYI…
BIND 9.x security patch
- http://isc.sans.org/diary.html?storyid=5641
Last Updated: 2009-01-08 02:00:56 UTC - ""The Internet Systems Consortium [ http://www.isc.org ] has released an update for all supported BIND 9.x versions today (2009-Jan-07) containing a security patch to address a potential DNS poisoning vector. *NOTE* This patch release does not appear to be an emergency situation requiring immediate updates for all… Patch deployment would appear most critical among recursive name resolvers. The flaw affects all actively developed and supported versions prior to and resolved with today's release of BIND 9.3.6-P1, 9.4.3-P1, 9.5.0-P2(-W2), 9.5.1-P1 and 9.6.0-P1… check with your vendor.
From the BIND "RELEASE NOTES" relative to each specific supported version:
"BIND 9.6.0-P1 is a SECURITY patch for BIND 9.6.0. It addresses a bug in which return values from some OpenSSL functions were left unchecked, making it theoretically possible to spoof answers from some signed zones."
ISC BIND Server software Index
https://www.isc.org/downloadables/11 …"
> https://www.isc.org/node/373
7 January 2009
- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-0025
- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2008-5077

BIND 9.x security patch
- http://isc.sans.org/diary.html?storyid=5641
Last Updated: 2009-01-08 02:00:56 UTC - ""The Internet Systems Consortium [ http://www.isc.org ] has released an update for all supported BIND 9.x versions today (2009-Jan-07) containing a security patch to address a potential DNS poisoning vector. *NOTE* This patch release does not appear to be an emergency situation requiring immediate updates for all… Patch deployment would appear most critical among recursive name resolvers. The flaw affects all actively developed and supported versions prior to and resolved with today's release of BIND 9.3.6-P1, 9.4.3-P1, 9.5.0-P2(-W2), 9.5.1-P1 and 9.6.0-P1… check with your vendor.
From the BIND "RELEASE NOTES" relative to each specific supported version:
"BIND 9.6.0-P1 is a SECURITY patch for BIND 9.6.0. It addresses a bug in which return values from some OpenSSL functions were left unchecked, making it theoretically possible to spoof answers from some signed zones."
ISC BIND Server software Index
https://www.isc.org/downloadables/11 …"
> https://www.isc.org/node/373
7 January 2009
- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-0025
- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2008-5077