New User, Welcome!     Login

Internet Systems Consortium

[ GLSA 200708-13 ] BIND: Weak random number generation

attack.

Background
==========

ISC BIND is the Internet Systems Consortium implementation of the
Domain Name System (DNS) protocol.

Affected packages
=================


[ GLSA 201006-11 ] BIND: Multiple vulnerabilities

Several cache poisoning vulnerabilities have been found in BIND.

Background
==========

ISC BIND is the Internet Systems Consortium implementation of the
Domain Name System (DNS) protocol.

Affected packages
=================


[ GLSA 200807-08 ] BIND: Cache poisoning

cache poisoning on recursive resolvers.

Background
==========

ISC BIND is the Internet Systems Consortium implementation of the
Domain Name System (DNS) protocol.

Affected packages
=================


[ GLSA 200903-14 ] BIND: Incorrect signature verification

spoofed records authenticated using DNSSEC.

Background
==========

ISC BIND is the Internet Systems Consortium implementation of the
Domain Name System (DNS) protocol.

Affected packages
=================


Security Advisory: CVE-2011-2464 - ISC BIND 9 Remote packet Denial of Service against Authoritative and Recursive Servers

Legal Disclaimer:: 

Internet Systems Consortium (ISC) is providing this notice on an "AS IS"
basis. No warranty or guarantee of any kind is expressed in this notice and
none should be implied. ISC expressly excludes and disclaims any warranties
regarding this notice or materials referred to in this notice, including,
without limitation, any implied warranty of merchantability, fitness for a
particular purpose, absence of hidden defects, or of non-infringement. Your

[ MDVSA-2009:037 ] bind

           Multi Network Firewall 2.0
 _______________________________________________________________________

 Problem Description:

 Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not
 properly check the return value from the OpenSSL EVP_VerifyFinal
 function, which allows remote attackers to bypass validation of
 the certificate chain via a malformed SSL/TLS signature, a similar
 vulnerability to CVE-2008-5077 and CVE-2009-0025.
 

Security Advisory: CVE-2011-2465 ISC BIND 9 Remote Crash with Certain RPZ Configurations

https://www.isc.org/security-vulnerability-disclosure-policy


Legal Disclaimer:: 

Internet Systems Consortium (ISC) is providing this notice on an "AS IS"
basis. No warranty or guarantee of any kind is expressed in this notice and
none should be implied. ISC expressly excludes and disclaims any warranties
regarding this notice or materials referred to in this notice, including,
without limitation, any implied warranty of merchantability, fitness for a
particular purpose, absence of hidden defects, or of non-infringement. Your

[ GLSA 200908-02 ] BIND: Denial of Service

daemon.

Background
==========

ISC BIND is the Internet Systems Consortium implementation of the
Domain Name System (DNS) protocol.

Affected packages
=================


Comments re ISC's announcement on bind9 security

trust and reassure the bind9 users that ISC digs security...

(another mistake in the ISC announcement is right at the top of the
page, where it reads "In June of 2007, a problem regarding Transaction
ID generation in BIND 9.4.1 (and prior) was reported to Internet
Systems Consortium (ISC) engineers." but according to Trusteer, they
reported it on May 29th:
http://www.trusteer.com/docs/bind9dns.html#chapter_4)





Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!