BIND 9.2.2: Slipstream Release?
[Posted March 12, 2003 by corbet]
[This article was contributed by Tom Owen]
The recent discussion on Bugtraq (e.g.
here
and
here)
raised the ugly possibility that
ISC
was fixing security problems in BIND and keeping quiet about them.
In fact it does seem as though the release could have been better described in
the BIND list.
Two faults are
described at the end of the current
Bind
vulnerability listing
and the reason for the omission looks easy to guess:
One is in the resolver library rather than the daemon itself, and the other is
caused by linking with an unfixed version of
OpenSSL.
It's not wrong to keep up to date with BIND, but the earlier server is only
vulnerable if you
use DNSSEC and linked an older version of OpenSSL.
(
Log in to post comments)