Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    Jun 2005
    Posts
    12

    Default Multiple DoS Vulnerabilities in the BIND 9 Software

    Hello,

    If you run any of following BIND software, update it asap:
    BIND 9.3.0
    BIND 9.3.1
    BIND 9.3.2
    BIND 9.3.3b1
    BIND 9.3.3rc1
    BIND 9.4.0a1
    BIND 9.4.0a2
    BIND 9.4.0a3
    BIND 9.4.0a4
    BIND 9.4.0a5
    BIND 9.4.0a6
    BIND 9.4.0b1

    http://www.niscc.gov.uk/niscc/docs/r...90.pdf?lang=en
    http://www.sitic.se/sr_item?item_id=176487 (SWEDISH)

    The fixed version can you find here: http://www.isc.org/sw/bind/ (BIND 9.3.2-P1)

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Unfortunately, that information isn't much use without a properly compiled list for the comon OS's since most flavours of Linux backport fixes nowadays and the information in that report is purely for the ISC bind version, so is only relevant for people who install it from source. Do you know of a proper CVE number or bugtraq ID that would give better information?
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  3. #3
    Member
    Join Date
    Jun 2005
    Posts
    12

    Default

    What i found was this one:
    http://www.niscc.gov.uk/niscc/docs/r...90.pdf?lang=en

    http://www.isc.org/index.pl?/sw/bind/ > Check under Alerts, and you will see "(5 Sept 2006) NISCC 172003", click on that and you will come to that site.

    But i just saw it was affected versions, so it could maybe be on all OS`s?
    I have no idea, i just wanted to give a msg to all so they know it atleast and if it was any dangerous

  4. #4
    Member
    Join Date
    Nov 2005
    Posts
    64

    Default

    Are there any updates on this please? I see cPanel has issued an all-out precautionary message regarding this although it seems to apply only to FreeBSD in the warning message.

  5. #5
    Member Stephanie_R's Avatar
    Join Date
    Mar 2004
    Posts
    36

    Default

    Code:
    root@nameserver [/etc]# rpm -qa bind
    bind-9.2.4-7_EL3
    This is an RHE3 nameserver with cpanel, I'm assuming CentOs is also using a similar backported version.
    According to Redhat's errata this has been adressed in bind-9.2.4-7_EL3 For RHE3 and 4

    If anyone else has any input I'm sure we'd all like to know.

  6. #6
    Member
    Join Date
    Feb 2005
    Posts
    111

    Default

    Anyone know if Fedora Core 2 is affected by these? (bind-9.2.3-13)?

  7. #7
    Member Stephanie_R's Avatar
    Join Date
    Mar 2004
    Posts
    36

    Default

    Forgot to add,


    There is a CVE for this here:
    http://cve.mitre.org/cgi-bin/cvename...=CVE-2006-4096

Similar Threads & Tags
Similar threads

  1. CPanel Multiple Cross-Site Scripting Vulnerabilities BugTraq ID: 20683
    By dlennon in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 10-26-2006, 11:07 AM
  2. cPanel Multiple Cross-Site Scripting Vulnerabilities
    By leorevenda in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-22-2006, 11:17 AM
  3. PHP: Multiple vulnerabilities - Severity: high
    By XPerties in forum cPanel and WHM Discussions
    Replies: 26
    Last Post: 06-07-2006, 01:25 PM
  4. Multiple vulnerabilities have been identified in MySQL
    By equens in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-17-2006, 04:14 PM
  5. WHM AutoPilot Multiple Vulnerabilities
    By fikse in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 12-30-2004, 03:39 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube