OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: BIND 9.2.1 crashes

jlewislewis.org
Date: Mon Oct 06 2003 - 12:01:32 CDT


On Mon, 6 Oct 2003, Keith Bergen wrote:

> Benjamin,
>
> My paranoia always assumes a buffer overflow and comprimise.
> BIND 9.2.1 appears to be vulnerable to a buffer overflow. I

The 9.2.1 he mentioned he's running on Red Hat 7.2 is the latest version
of that package from Red Hat...which includes backported security updates.
If there are holes in that bind, they're not known to the general public.

BTW...I've seen the same problem with bind-9.2.1-1.7x.2 on Red Hat 7.2
where named will apparently get stuck in some loop, sit in state R, and
cease answering queries until named is killed/restarted.
 
----------------------------------------------------------------------
 Jon Lewis *jlewislewis.org*| I route
 Senior Network Engineer | therefore you are
 Atlantic Net |
_________ http://www.lewis.org/~jlewis/pgp for PGP public key_________

---------------------------------------------------------------------------
----------------------------------------------------------------------------