Slashdot Mirror


New DoS Vulnerability In All Versions of BIND 9

Icemaann writes "ISC is reporting that a new, remotely exploitable vulnerability has been found in all versions of BIND 9. A specially crafted dynamic update packet will make BIND die with an assertion error. There is an exploit in the wild and there are no access control workarounds. Red Hat claims that the exploit does not affect BIND servers that do not allow dynamic updates, but the ISC post refutes that. This is a high-priority vulnerability and DNS operators will want to upgrade BIND to the latest patch level."

2 of 197 comments (clear)

  1. Are you high? by Anonymous Coward · · Score: -1, Offtopic

    Just askin'...

  2. Please - Adhominem attacks & off-topic...? by Anonymous Coward · · Score: -1, Offtopic

    Stay on topic please - this can be useful for my purposes, especially @ least SOMEWHAT technically interesting replies (especially from detractors), as I find critique FAR MORE POSITIVELY USEFUL than praise ever could be, but it has to be valid, this is certain, as it only makes me stronger...

    Well, that is, IF my naysayers can disprove what I said, that is...

    (I just never see too much of that & especially on THIS point, even on this website)

    APK

    P.S.=> Give us a break - please: This blatant "ad-hominem" attack of myself, it's not on topic & I'd like to hear technical reasons, logical ones, that make my points incorrect is all, on HOSTS files especially. As Martin Lawrence said it best? I'll quote him on that -> "I don't do drugs"... apk