Slashdot Mirror


Critical BIND Denial-of-Service Flaw Could Take Down DNS Servers

alphadogg writes: Attackers could exploit a new vulnerability in BIND, the most popular Domain Name System (DNS) server software, to disrupt the Internet for many users. The vulnerability affects all versions of BIND 9, from BIND 9.1.0 to BIND 9.10.2-P2, and can be exploited to crash DNS servers that are powered by the software. The vulnerability announced and patched by the Internet Systems Consortium is critical because it can be used to crash both authoritative and recursive DNS servers with a single packet.

8 of 68 comments (clear)

  1. Patched on 7/28 (CentOS) by bill_mcgonigle · · Score: 5, Informative

    I noticed this on Google News yesterday - checked a CentOS 7 box to find that yum had installed the patch overnight on 7/28 and systemd had restarted named for me. Good work, everybody. Make sure your updates are working.
    Oh, hai dollar-short Slashdot.

    --
    My God, it's Full of Source!
    OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
    1. Re:Patched on 7/28 (CentOS) by unrtst · · Score: 3, Informative

      FWIW, it seems CentOS 6 was not updated (though there is an SRPM from RHEL for it).
      CentOS 5 and 7 both have the update. Example mirror:
      http://mirror.atlanticmetro.ne...
      http://mirror.atlanticmetro.ne...
      http://mirror.atlanticmetro.ne...

      I also checked the mirror status: http://mirror-status.centos.or...
      And checked one that was JUST updated: http://mirror.millry.co/CentOS...
      No update!!!

      RHEL page on their 6.x update: https://rhn.redhat.com/errata/...

  2. Interesting, but budgie cage liner news by Demonoid-Penguin · · Score: 3, Informative

    Patched updates rolled out long before /. reported it (shock, horror).
    If Debian is any guide most distros have already done the same and anyone running unattended-updates for security patches has been updated for several days (25th).

    1. Re: Interesting, but budgie cage liner news by therealkevinkretz · · Score: 2

      ... Not opensuse

    2. Re: Interesting, but budgie cage liner news by rubycodez · · Score: 3, Informative
  3. But not patched in CentOS 6.6 by terremoto · · Score: 2

    A heads up for those running CentOS 6.6. This issue is not patched by default (because CentOS is in the midst of the transition from 6.6 to 6.7). Sysadmins using bog-standard CentOS 6.6 bind will need to enable the continuous release (CR) repository and update bind using that.

    See the CentOS 6 Security Support forum post CVE-2015-5477 patch for centos 6

    Wondering if this issue is serious enough to warrant the CentOS folk putting some patched bind rpms in the CentOS 6.6 updates repo? My guess is that a lot of people might miss the patch otherwise.

  4. How long has it been? by tlhIngan · · Score: 2

    Don't you just long for the days when sendmail and bind would be always in the news because of some flaw or other? Heck, didn't we all run alternatives because sendmail and bind were so buggy...

    How long has it been since we last had a Bind security issue...

    1. Re:How long has it been? by OrangeTide · · Score: 2

      How long has it been since we last had a Bind security issue...

      Not long enough.

      --
      “Common sense is not so common.” — Voltaire