1
0
mirror of https://git.FreeBSD.org/ports.git synced 2025-02-08 12:01:56 +00:00
Doug Barton 83aa56c48f Update to 9.4.1-P1, which has fixes for the following:
1. The default access control lists (acls) are not being
correctly set. If not set anyone can make recursive queries
and/or query the cache contents.

See also:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2925

2. The DNS query id generation is vulnerable to cryptographic
analysis which provides a 1 in 8 chance of guessing the next
query id for 50% of the query ids. This can be used to perform
cache poisoning by an attacker.

This bug only affects outgoing queries, generated by BIND 9 to
answer questions as a resolver, or when it is looking up data
for internal uses, such as when sending NOTIFYs to slave name
servers.

All users are encouraged to upgrade.

See also:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2926
2007-07-24 22:02:16 +00:00
..
2007-04-30 08:36:01 +00:00
2007-05-19 20:36:56 +00:00
2007-03-27 22:12:03 +00:00
2007-05-19 20:36:56 +00:00
2007-07-09 12:51:37 +00:00
2007-03-07 09:17:05 +00:00
2007-05-19 20:36:56 +00:00
2007-03-27 22:12:03 +00:00
2007-04-17 19:41:28 +00:00
2007-07-22 11:37:27 +00:00
2007-01-23 02:38:28 +00:00
2007-04-30 07:33:13 +00:00
2007-04-30 07:33:13 +00:00
2007-02-26 21:26:58 +00:00
2007-03-22 13:28:51 +00:00
2007-04-17 18:51:01 +00:00
2007-05-19 20:36:56 +00:00
2007-06-20 11:21:45 +00:00
2007-04-15 05:40:03 +00:00
2007-06-09 02:36:28 +00:00
2007-01-02 21:12:46 +00:00
2007-01-11 20:04:53 +00:00
2007-02-12 12:06:07 +00:00
2007-04-25 07:24:27 +00:00
2007-01-12 21:15:52 +00:00
2007-05-01 13:24:58 +00:00
2007-07-06 09:00:17 +00:00
2007-03-25 21:21:40 +00:00
2007-01-08 22:22:42 +00:00