Alert A-02012C - Vulnerabilita' in BIND
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ****************************************************************** Alert ID: A-02012C Data di creazione: Fri Nov 15 15:03:41 CET 2002 Titolo: vulnerabilita' in Bind v4 e v8 Gravita': alta ****************************************************************** L'Internet Software Consortium [1] ha segnalato la presenza di alcune vulnerabilita' in BIND V4 e V8 che consentirebbo anche l'esecuzione di codice arbitrario con i privilegi del processo 'named'. Vi allego il testo dell'advisory: ISC is aware of several bugs which can result in serious vulnerabilities in BIND as distributed by ISC. More information about these vulnerabilities can be found here: http://www.isc.org/products/BIND/bind-security.html Upgrading to BIND version 9.2.1 is strongly recommended. However, patches for BIND 8.3.3, 8.2.6 and 4.9.10 are now publicly available from ISC and new BIND 4 & 8 releases will be published in the next day or two . You can find the patches here: http://www.isc.org/products/BIND/patches/ Questa informazione e' stata ripresa anche in un advisory CERT [2]. cordiali saluti massimo ianigro Riferimenti: [1] http://www.isc.org [2] http://www.cert.org/advisories/CA-2002-31.html Appendice GARR-CERT Home Page: http://www.cert.garr.it - --