Newsgroups: comp.protocols.dns.bind
From: Rob_Aust...@isc.org
Date: Wed, 7 Jan 2009 19:32:11 +0000 (UTC)
Local: Wed, Jan 7 2009 2:32 pm
Subject: BIND Security Advisory (CVE-2009-0025; Severity: Low)
Internet Systems Consortium Security Advisory.
BIND: EVP_VerifyFinal() and DSA_do_verify() return checks. 7 January 2009 Versions affected: BIND 9.0 (all versions) Severity: Low. Description: Return values from OpenSSL library functions EVP_VerifyFinal() Impact: It is theoretically possible to spoof answers returned from Workaround: BIND 9.3, 9.4, 9.5 and 9.6: BIND 9.3, 9.4, 9.5: Fix: Upgrade to 9.3.6-P1, 9.4.3-P1, 9.5.1-P1, 9.6.0-P1. There are no fixes planned for BIND 9.1 or BIND 9.2, as those Questions should be addressed to bind9-b...@isc.org. CVE: CVE-2009-0025 Also see CVE-2008-5077 for the corresponding OpenSSL issue Acknowledgement: Credit: Google Security Team (for the original OpenSSL issue), Revision History: 2009-01-05 Initial pre-release text 2009-01-07 Public release with corrected CVE You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||