[svlug] Bind Vulnerabilities

Derek J. Balling dredd at megacity.org
Fri Mar 23 13:32:02 PST 2001


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

>begin  Karsten M. Self quotation:
>8.2.3 (current version, released _26 Jan 2001_) is indeed NOT
>vulnerable to the TSIG vulnerability cited.  The final release fixed
>that and the "infoleak" bug:
>http://www.isc.org/products/BIND/bind-security.html
>
>My system upgraded to that version on 29 Jan 2001 -- the easy way --
>thanks to this line in /etc/apt/sources.list :
>
>deb http://security.debian.org/ stable/updates main contrib non-free

I'd still recommend heading for the 9.x tree myself....

D


-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>

iQA/AwUBOrvAnQJuFNqj63mKEQK/VACgnmh6u/qEipFO7NSBIXmkAyLqZT8AoKHv
x0y1L2N6EvK85CJu2gJhi1AC
=D/Pd
-----END PGP SIGNATURE-----
-- 
+---------------------+-----------------------------------------+
| dredd at megacity.org  | "Conan! What is best in life?"          |
|  Derek J. Balling   | "To crush your enemies, see them        |
|                     |    driven before you, and to hear the   |
|                     |    lamentation of their women!"         |
+---------------------+-----------------------------------------+




More information about the svlug mailing list