Is Bind still broken?

Danny Mayer mayer at gis.net
Wed Nov 20 03:56:46 UTC 2002


At 09:00 PM 11/19/02, John Oliver wrote:
>On 20 Nov 2002 01:25:11 -0000, dns wrote:
> > ... when was the 'last' time you saw a security warning about djbdns, and
> > bind.  in my book, a "Remote ROOT conpromise" 'feature' in ANY package,
> > translates to 'broken'.  memory being what it is, i've forgotten what
> > versions of bind "aren't" vulnerable.

ISC makes a complete list available so you don't need to rely on your
memory:
http://www.isc.org/products/BIND/bind-security.html

Danny

>So, go use djbdns.  Why cry about it here?
>
>--
>John Oliver, CCNA                            http://www.john-oliver.net/
>Linux/UNIX/network consulting         http://www.john-oliver.net/resume/
>***               sendmail, Apache, ftp, DNS, spam filtering         ***
>****                Colocation, T1s, web/email/ftp hosting          ****



More information about the bind-users mailing list