Vulnerability Development mailing list archives

Re: BEWARE : Possible compromission under BIND 8.2.2-P5 with Iquery probe


From: Daniel Roesen <droesen () ENTIRE-SYSTEMS COM>
Date: Tue, 13 Mar 2001 09:48:07 +0100

On Mon, Mar 12, 2001 at 10:52:51AM -0800, David R. Conrad wrote:
All versions of BIND except 4.9.8, 8.2.3, and 9.* are
vulnerable to an information leak bug that permits the dumping of a stack
frame via a mis-formed IQUERY request.

That BIND 9.* is vulnerable to this problem would be news.


Best regards,
Daniel

--
----------------------------------------------------------------------
entire systems GmbH         | droesen () entire-systems com
Internet Services           | Phone: +49 2624 9550-55
Ferbachstrasse 12           | Fax:   +49 2624 9550-20
D-56203 Hoehr-Grenzhausen   | http://www.entire-systems.com/
----------------------------------------------------------------------


Current thread: