Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Hi

0 views
Skip to first unread message

supriya samanta

unread,
Dec 10, 2009, 12:33:59 PM12/10/09
to bind-...@lists.isc.org
Hello All,
       
As per ISC security bulletin CVE-2009-4022 There is a problem with BIND 9 Cache Update From Additional Section
   
Problem Description: A Nameserver with DNSSEC validation enabled may incorrectly add records to its cache from the additional section of responses received during resolution of a recursive client query.This behavior only occurs when processing client queries with checking disabled
(CD).It may occur both when requesting,and not when requesting,DNSSEC records(DO).If the nameserver is authoritative-only this will not occur.
 
We have some business requirement where we need to reproduce the problem.
 
Could anyone advice a test case which I may use or direct me to some website which could be useful for this purpose.
 
Any help will be appreciated.
 
Many Thanks,
Supriya Samanta

Danny Mayer

unread,
Dec 14, 2009, 9:54:14 AM12/14/09
to supriya samanta, bind-...@lists.isc.org
supriya samanta wrote:
> Hello All,
>
> As per ISC security bulletin *CVE-2009-4022* There is a problem with

> BIND 9 Cache Update From Additional Section
>
> *Problem Description:* A Nameserver with DNSSEC validation enabled may

> incorrectly add records to its cache from the additional section of
> responses received during resolution of a recursive client query.This
> behavior only occurs when processing client queries with checking disabled
> (CD).It may occur both when requesting,and not when requesting,DNSSEC
> records(DO).If the nameserver is authoritative-only this will not occur.
>
> We have some business requirement where we need to reproduce the problem.
>
> Could anyone advice a test case which I may use or direct me to some
> website which could be useful for this purpose.
>

You should contact ISC directly about this rather than the mailing list.

Danny


--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.

0 new messages