Skip to main content

Alert A-02012C - Vulnerabilita' in BIND


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

******************************************************************

   Alert ID: A-02012C

   Data di creazione:  Fri Nov 15 15:03:41 CET 2002

   Titolo: vulnerabilita' in Bind v4 e v8

   Gravita': alta

******************************************************************

L'Internet Software Consortium [1] ha segnalato la presenza di alcune 
vulnerabilita' in BIND V4 e V8 che consentirebbo anche l'esecuzione di 
codice arbitrario con i privilegi del processo 'named'.

Vi allego il testo dell'advisory:

ISC is aware of several bugs which can result in serious vulnerabilities 
in BIND as distributed by ISC.  More information about these 
vulnerabilities can be found here:

http://www.isc.org/products/BIND/bind-security.html

Upgrading to BIND version 9.2.1 is strongly recommended.  However, 
patches for BIND 8.3.3, 8.2.6 and 4.9.10 are now publicly available from 
ISC and new BIND 4 & 8 releases will be published in the next day or two .

You can find the patches here:

http://www.isc.org/products/BIND/patches/

Questa informazione e' stata ripresa anche in un advisory CERT [2].

cordiali saluti

massimo ianigro


Riferimenti:
[1]  http://www.isc.org
[2]  http://www.cert.org/advisories/CA-2002-31.html

Appendice

   GARR-CERT Home Page:  http://www.cert.garr.it


- --

 

Alert di GARR-CERT Usata per la segnalazione di allarmi di sicurezza e comunicazioni di interesse generale diretti agli enti GARR. L'iscrizione è aperta e consigliata a tutti, il posting è riservato ai membri di GARR-CERT