Re: What about BIND 9.3.4 in FreeBSD in base system ?

看板FB_security作者時間19年前 (2007/02/02 05:00), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串7/17 (看更多)
Doug Barton wrote: > Chris Marlatt wrote: [ ... ] > Yes, but whether a full upgrade is needed for "support" or not depends > on your definition. Given that FreeBSD is not vulnerable to these issues > in its default configuration, one could easily argue that an upgrade for > RELENG_5 isn't necessary. I've been bitten by CVE-2006-4096, and have applied the workaround to limit the # of outstanding queries. I've got two nameservers tracking 5-STABLE which were vulnerable to CVE-2006-4095, and I have no doubt that there are other people besides me who will be affected by CVE-2007-0493. I'm starting to feel thankful that my important domains include off-site secondaries which are running djbdns. Does the FreeBSD security team have a position with regard to whether the above DoS vulnerabilities ought to be fixed in the 5-STABLE branch? -- -Chuck _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #15mbJh00 (FB_security)
討論串 (同標題文章)
文章代碼(AID): #15mbJh00 (FB_security)