Security vulnerability in Bind9.2.1?

Mark_Andrews at isc.org Mark_Andrews at isc.org
Thu Jul 4 03:40:49 UTC 2002


> Hi All,
> 
> I was notified of the security vulnerability in Bind, link below:
> 
> http://www.cert.org/advisories/CA-2002-19.html
> 
> According to this announcement, Bind9.2.1 is vulnerable.
> 
> Is this in fact so?

	Yes, if you specify "configure --enable-libbind".
 
> If so, is there a new version available for Win2000/WinNT?

	No.  The binary release doesn't use libbind which is
	the vulnerable part.

	Mark

> 
> Thanks,
> -- 
> Bjorn Johansson
> 
--
Mark Andrews, Internet Software Consortium
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: Mark.Andrews at isc.org


More information about the bind-users mailing list