Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Daily Reviews Summary 05/22/12
· The Perfect Desktop - Ubuntu Studio 12.04
· Microsoft's So.cl: A Brief Tour
· 4 RHEL Updates
· 8 CentOS Updates
· Daily Reviews Summary 05/21/12
· Windows 8 Release Preview reportedly ready, build 8400
· DSA 2477-1: sympa security update
· Create And Restore Partition Images With Partimage
· Install Varnish CentOS 6

Upcoming News
· Samsung Green DDR3 1600MHz 8GB 30nm Memory Kit Review @ eTeknix.com
· [security-announce] SUSE-SU-2012:0637-1: important: Security update for openssl
· Phanteks PH-TC14CS_RD CPU Cooler Review @ DragonSteelMods
· Thermaltake Frio Advanced Heatsink Review
· Crucial BallistiX Elite 16GB 1600MHz Quad Channel Kit Review
· Tom Clancy's Ghost Recon Future Soldier (XBOX 360) Game Review @ HardwareHeaven.com
· Hacks Decimate Diablo III Debut @ HotHardware.com
· Patriot Viper Xtreme Division 2 PC3-19200 8GB Memory Kit Review
· Sapphire HD7770 Vapor X Overclock Edition Review
· Zalman CNPS8900 Extreme CPU Cooler Review @ Legit Reviews

Linux Compatibility
· Canon Canoscan N650U
· TB-5300 Slimline Design Tablet
· HANDYCAM DCR-HC17E
· Linksys Wireless-G WPC54G PC-Card
· XPS L502X
· Slim Portable DVD Writer GP10
· AverTV Volar Green HD
· Dell Latitude E6420
· Canon CanoScan FB 636U
· Logitech QuickCam Pro 4000

New Forum Topics
· USB Not detected on any PC
by: AntNik45
on: 2012-05-09 18:37
0 replies, 0 views

· RESIDENT EVIL 2 for PC
by: elyp00
on: 2012-05-04 07:55
0 replies, 0 views

· Need to know if those graphic cards works well on Ubuntu
by: Dechiqtor
on: 2012-04-19 23:04
0 replies, 0 views

· Obtaining IE8
by: packman
on: 2012-04-14 19:46
0 replies, 0 views

· A few problems running Warcraft II Battle.net Edition on Vista
by: Lord Claremorris
on: 2012-04-08 16:15
0 replies, 0 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » July 2008 » DSA 1604-1: BIND 8 deprecation notice

DSA 1604-1: BIND 8 deprecation notice

Posted by Bob on: 07/08/2008 06:25 PM [ Print | 0 comment(s) ]

The Debian Security Team published a new security update for Debian GNU/Linux. Here the announcement:




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
Debian Security Advisory DSA-1604-1 security@debian.org
http://www.debian.org/security/ Florian Weimer
July 08, 2008 http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package : bind
Vulnerability : DNS cache poisoning
Problem type : remote
Debian-specific: no
CVE Id(s) : CVE-2008-1447
CERT advisory : VU#800113


Dan Kaminsky discovered that properties inherent to the DNS protocol
lead to practical DNS cache poisoning attacks. Among other things,
successful attacks can lead to misdirected web traffic and email
rerouting.

The BIND 8 legacy code base could not be updated to include the
recommended countermeasure (source port randomization, see DSA-1603-1
for details). There are two ways to deal with this situation:

1. Upgrade to BIND 9 (or another implementation with source port
randomization). The documentation included with BIND 9 contains a
migration guide.

2. Configure the BIND 8 resolver to forward queries to a BIND 9
resolver. Provided that the network between both resolvers is trusted,
this protects the BIND 8 resolver from cache poisoning attacks (to the
same degree that the BIND 9 resolver is protected).

This problem does not apply to BIND 8 when used exclusively as an
authoritative DNS server. It is theoretically possible to safely use
BIND 8 in this way, but updating to BIND 9 is strongly recommended.
BIND 8 (that is, the bind package) will be removed from the etch
distribution in a future point release.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show lt;pkggt;' and http://packages.debian.org/lt;pkggt;
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iQEVAwUBSHOIFL97/wQC1SS+AQLZYAgAhiucKuHSkgZRjm1E9vUS4t9VmVhKdYB2
jDhG00WloZPxeBjHT0Ar1b4S/QGbDQ2Dy2hlMONsl5ZZWAbkzzANDsVIDC2xez5w
NBqJjfEKYuk7Q3E+elyJ/z79F0HbMtO+SdagRoSbIV3nWfSoRI6jp+32Be69JazW
Te3gLKOAm6TpdYPpn7wmw2pXeOKzeUaOh/npXAYH4YEKmqnxzJZy+0862kaKSQ8G
9qGIQ9zKCkPLs4bKt+JhpwWumfgaabGT6KlGAtC3ORBef54Ux/EdpNFEGBWvWrxU
HOcPZGBJKxUAO4doJdRPNcFV4ez4u2v0WFK3bRM+JNgegnoplvnxuA==
=vK+3
-----END PGP SIGNATURE-----


Bookmark and Share

« Apple Posts Details for iPhone 3G Launch · DSA 1605-1: DNS vulnerability impact on the libc stub resolver »

Linux Compatible » News » July 2008 » DSA 1604-1: BIND 8 deprecation notice
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2011 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition