diff options
author | dougb <dougb@FreeBSD.org> | 2007-07-25 08:12:36 +0000 |
---|---|---|
committer | dougb <dougb@FreeBSD.org> | 2007-07-25 08:12:36 +0000 |
commit | e9f5980a15892cbb50c32cfaab95f2dcb23cebcd (patch) | |
tree | 5e59e5d349bab1b1962e57d794d1ceb729fa3150 /contrib/bind9/README | |
parent | 7fe38836a11b0c3827d4e4c79c7d24ddf4534957 (diff) | |
download | FreeBSD-src-e9f5980a15892cbb50c32cfaab95f2dcb23cebcd.zip FreeBSD-src-e9f5980a15892cbb50c32cfaab95f2dcb23cebcd.tar.gz |
Vendor import of 9.4.1-P1, which has fixes for the following:
1. The default access control lists (acls) are not being
correctly set. If not set anyone can make recursive queries
and/or query the cache contents.
See also:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2925
2. The DNS query id generation is vulnerable to cryptographic
analysis which provides a 1 in 8 chance of guessing the next
query id for 50% of the query ids. This can be used to perform
cache poisoning by an attacker.
This bug only affects outgoing queries, generated by BIND 9 to
answer questions as a resolver, or when it is looking up data
for internal uses, such as when sending NOTIFYs to slave name
servers.
All users are encouraged to upgrade.
See also:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2926
Approved by: re (kensmith, implicit)
Diffstat (limited to 'contrib/bind9/README')
-rw-r--r-- | contrib/bind9/README | 5 |
1 files changed, 5 insertions, 0 deletions
diff --git a/contrib/bind9/README b/contrib/bind9/README index ac05b83..4cdd146 100644 --- a/contrib/bind9/README +++ b/contrib/bind9/README @@ -43,6 +43,11 @@ BIND 9 Nominum, Inc. +BIND 9.4.1-P1 + + BIND 9.4.1-P1 is a security release, containing a fixes for a + security bugs in BIND 9.4.1. + BIND 9.4.1 BIND 9.4.1 is a security release, containing a fix for a |