BIND security problems

From: Kevin Oberman <oberman_at_es.net>
Date: Mon, 18 May 1998 13:46:03 -0700

Digital UNIX (any released version) includes a truly ancient version
of BIND. All versions of BIND except 4.9.7 and 8.1.2 have known
security holes and should not be used.

I strongly urge anyone running named on DU to get either 4.9.7 or
8.1.2. The ISC web page explains why you should really go with 8.1.2,
but 4.9.7 should be easier to do since it typically requires no
changes to named support files while 8.1.2 replaces named.boot with
named.conf.

BIND is developed by a former Digital employee who uses an Alpha in
the process, so it builds very easily on a standard DU system.

BIND is available from http://www.isc.org/bind.html.

R. Kevin Oberman, Network Engineer
Energy Sciences Network (ESnet)
Ernest O. Lawrence Berkeley National Laboratory (Berkeley Lab)
E-mail: oberman_at_es.net Phone: +1 510 486-8634
Received on Mon May 18 1998 - 22:47:07 NZST

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:37 NZDT