Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[secu] BIND, gentoo et la faille DNS...
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index French
View previous topic :: View next topic  
Author Message
El_Goretto
Moderator
Moderator


Joined: 29 May 2004
Posts: 3174
Location: Paris

PostPosted: Fri Jul 11, 2008 9:48 am    Post subject: [secu] BIND, gentoo et la faille DNS... Reply with quote

Bon, on ne va pas rappeler les faits, c'est partout sur le net.

L'idée était plutôt de savoir où on en est, nous, les gentooistes, vu qu'il n'y a eu aucune annonce GLSA sur le sujet, et que ça continue de sonner dans le vide.
En allant sur le site qui va bien, on tombe sur la matrice de vulnérabilité de BIND. C'est la colonne 29 qui emporte la mise. On sert des miquettes, et on lance un coup de eix après une synchro portage toute fraîche:
Code:
# eix -I bind
[U] net-dns/bind
     Available versions:  9.2.6 ~9.2.6-r3 9.2.6-r4 ~9.2.6-r5 9.2.8 ~9.2.8-r3 9.3.2 ~9.3.2-r3 9.3.2-r4 ~9.3.2-r5 9.3.4 9.3.4-r2 9.3.4-r3 9.4.1-r1 9.4.1_p1 9.4.2_p1 ~9.5.0_p1 {berkdb bind-mysql dlz doc idn ipv6 ldap mysql odbc postgres resolvconf selinux ssl threads urandom}
     Installed versions:  9.4.1_p1(15:02:09 23.05.2008)(ssl threads -berkdb -dlz -doc -idn -ipv6 -ldap -mysql -odbc -postgres -resolvconf -selinux -urandom)
     Homepage:            http://www.isc.org/products/BIND/bind9.html
     Description:         BIND - Berkeley Internet Name Domain - Name Server


Ouf.

Bon, la 9.4.2_p1 hein, ben au boulot. Et la 9.5.0_p1 pour ceux qui peuvent :)
_________________
-TrueNAS & jails: µ-serv Gen8 E3-1260L, 16Go ECC + µ-serv N40L, 10Go ECC
-Réseau: APU2C4 (OpenWRT) + GS726Tv3 + 2x GS108Tv2 + Archer C5v1 (OpenWRT)
Back to top
View user's profile Send private message
Koboneil
n00b
n00b


Joined: 18 Jun 2007
Posts: 18
Location: Mulhouse (68), France

PostPosted: Fri Jul 11, 2008 10:46 am    Post subject: Re: [secu] BIND, gentoo et la faille DNS... Reply with quote

Sur http://planet.gentoo.org :

Matthias Geerdsen wrote:

In the light of the yesterday’s large coordinated release of DNS related updates to various products, I would like to point you to the updated bind packages in the portage tree.

* net-dns/bind-9.4.2_p1 is currently being marked stable on all supported architectures
* net-dns/bind-9.5.0_p1 has been committed with unstable keywords

Nameservers should be updated quite soon, since this issue should be considered serious.

A GLSA will be published after all security architectures have marked the affected package stable. The progress can be followed in bug #231201.

For more information have a look at the following links and the references therein:

* US-CERT Vulnerability Note VU#800113
* CVE-2008-1447
* ISC info

Also note that if you are restricting the used outgoing ports of your nameserver by a firewall for example, this policy should be revisited.

_________________
Koboneil.
Back to top
View user's profile Send private message
guilc
Bodhisattva
Bodhisattva


Joined: 15 Nov 2003
Posts: 3326
Location: Paris - France

PostPosted: Fri Jul 11, 2008 10:56 am    Post subject: Re: [secu] BIND, gentoo et la faille DNS... Reply with quote

El_Goretto wrote:
vu qu'il n'y a eu aucune annonce GLSA sur le sujet

Ca, c'est normal, dans la procédure de correction des failles sécu

La GLSA sera émise au moment où toutes les arch auront stabilisé la 9.4.2_p1 et tildarché la 9.5.0_p1
Evidemment, si une arch-team traine, ça retarde. Mais ça n'empeche pas les mises à jour sur les arch déja marquées
_________________
Merci de respecter les règles du forum.

Mon site perso : https://www.xwing.info
Mon PORTDIR_OVERLAY : https://gentoo.xwing.info ou layman -a xwing
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index French All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum