Re: bind vulnerabilities

2021-05-01 Thread alcol alcol
; kb.isc.org From: bind-users on behalf of Elias Pereira Sent: Saturday, May 1, 2021 3:03 PM To: bind-users@lists.isc.org Subject: bind vulnerabilities According to the article below, only the: "BIND 9.11.31, 9.16.15, and 9.17.12 all contain patches an

bind vulnerabilities

2021-05-01 Thread Elias Pereira
According to the article below, only the: "BIND 9.11.31, 9.16.15, and 9.17.12 all contain patches and the appropriate update should be applied" https://www.zdnet.com/google-amp/article/isc-urges-updates-of-dns-servers-to-wipe-out-new-bind-vulnerabilities/ Is this statement correct?

CVE-2017-3142 and CVE-2017-3143 -- TSIG-related BIND vulnerabilities

2017-06-29 Thread Michael McNally
Today ISC announced two significant BIND vulnerabilities (via our bind-announce list -- https://lists.isc.org/mailman/listinfo/bind-announce) They are CVE-2017-3142 and CVE-2017-3143 and both are related to errors in our TSIG support. These are unusual CVEs for BIND -- many