[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] bind hack



dfd wrote:
> 
> The RAQ1 uses bind 4.9.7(?); RAQ2 uses 8.1.2.  Don't know about the qubes.
> Both versions are vulnerable to some types of attacks.  There is more
> information on http://www.isc.org/products/BIND/bind-security-19991108.html
> about the types of attacks and what versions are vulnerable to which type.
> 
> There doesn't appear to be any updates for the RAQ1 or RAQ2 to BIND
> 8.2.2-P5 from cobalt unfortunately.

Versions earlier to 8.2 are not vulnerable to the remote root exploit.
You can get more detail no the issues surrounding the BIND security
advisory from CERT.

http://www.cert.org/advisories/CA-99-14-bind.html

Jeff