View previous topic :: View next topic |
Author |
Message |
El_Goretto Moderator
Joined: 29 May 2004 Posts: 3174 Location: Paris
|
Posted: Fri Jul 11, 2008 9:48 am Post subject: [secu] BIND, gentoo et la faille DNS... |
|
|
Bon, on ne va pas rappeler les faits, c'est partout sur le net.
L'idée était plutôt de savoir où on en est, nous, les gentooistes, vu qu'il n'y a eu aucune annonce GLSA sur le sujet, et que ça continue de sonner dans le vide.
En allant sur le site qui va bien, on tombe sur la matrice de vulnérabilité de BIND. C'est la colonne 29 qui emporte la mise. On sert des miquettes, et on lance un coup de eix après une synchro portage toute fraîche:
Code: | # eix -I bind
[U] net-dns/bind
Available versions: 9.2.6 ~9.2.6-r3 9.2.6-r4 ~9.2.6-r5 9.2.8 ~9.2.8-r3 9.3.2 ~9.3.2-r3 9.3.2-r4 ~9.3.2-r5 9.3.4 9.3.4-r2 9.3.4-r3 9.4.1-r1 9.4.1_p1 9.4.2_p1 ~9.5.0_p1 {berkdb bind-mysql dlz doc idn ipv6 ldap mysql odbc postgres resolvconf selinux ssl threads urandom}
Installed versions: 9.4.1_p1(15:02:09 23.05.2008)(ssl threads -berkdb -dlz -doc -idn -ipv6 -ldap -mysql -odbc -postgres -resolvconf -selinux -urandom)
Homepage: http://www.isc.org/products/BIND/bind9.html
Description: BIND - Berkeley Internet Name Domain - Name Server
|
Ouf.
Bon, la 9.4.2_p1 hein, ben au boulot. Et la 9.5.0_p1 pour ceux qui peuvent _________________ -TrueNAS & jails: µ-serv Gen8 E3-1260L, 16Go ECC + µ-serv N40L, 10Go ECC
-Réseau: APU2C4 (OpenWRT) + GS726Tv3 + 2x GS108Tv2 + Archer C5v1 (OpenWRT) |
|
Back to top |
|
|
Koboneil n00b
Joined: 18 Jun 2007 Posts: 18 Location: Mulhouse (68), France
|
Posted: Fri Jul 11, 2008 10:46 am Post subject: Re: [secu] BIND, gentoo et la faille DNS... |
|
|
Sur http://planet.gentoo.org :
Matthias Geerdsen wrote: |
In the light of the yesterday’s large coordinated release of DNS related updates to various products, I would like to point you to the updated bind packages in the portage tree.
* net-dns/bind-9.4.2_p1 is currently being marked stable on all supported architectures
* net-dns/bind-9.5.0_p1 has been committed with unstable keywords
Nameservers should be updated quite soon, since this issue should be considered serious.
A GLSA will be published after all security architectures have marked the affected package stable. The progress can be followed in bug #231201.
For more information have a look at the following links and the references therein:
* US-CERT Vulnerability Note VU#800113
* CVE-2008-1447
* ISC info
Also note that if you are restricting the used outgoing ports of your nameserver by a firewall for example, this policy should be revisited.
|
_________________ Koboneil. |
|
Back to top |
|
|
guilc Bodhisattva
Joined: 15 Nov 2003 Posts: 3326 Location: Paris - France
|
Posted: Fri Jul 11, 2008 10:56 am Post subject: Re: [secu] BIND, gentoo et la faille DNS... |
|
|
El_Goretto wrote: | vu qu'il n'y a eu aucune annonce GLSA sur le sujet |
Ca, c'est normal, dans la procédure de correction des failles sécu
La GLSA sera émise au moment où toutes les arch auront stabilisé la 9.4.2_p1 et tildarché la 9.5.0_p1
Evidemment, si une arch-team traine, ça retarde. Mais ça n'empeche pas les mises à jour sur les arch déja marquées _________________ Merci de respecter les règles du forum.
Mon site perso : https://www.xwing.info
Mon PORTDIR_OVERLAY : https://gentoo.xwing.info ou layman -a xwing |
|
Back to top |
|
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|