The Daily Static
  The Daily Static
UF Archives
Register
UF Membership
Ad Free Site
Postcards
Community

Geekfinder
UFie Gear
Advertise on UF

Forum Rules
& FAQ


Username

Password


Create a New Account

 
 

Back to UserFriendly Strip Comments Index

Can someone check out Sans.org for me? by romandas2006-09-07 02:30:05
  I think you mean isc.sans.org (Storm Center) by ideur2006-09-07 02:36:07
    Do you have information on the DoS? (n/t) by romandas2006-09-07 03:34:40
      OK; here it comes: by ideur 2006-11-19 12:55:59
Internet Systems Consortium BIND Denial of Service Vulnerabilities
<div class="diarydates"> Published: 2006-09-06,
Last Updated: 2006-09-06 17:39:28 UTC by Joel Esler (Version: qotdsubmit at this domain>2(click to highlight changes)) </div> <div class="diarydates"> Digg this| del.icio.us </div>

<div class="diarytext"> Internet Systems Consortium has stated there are a couple vulnerabilities in BIND (DNS server), that can be exploited to cause a DoS.

<span style="font-weight: bold;">SIG Query Processing (CVE-2006-4095):</span>
1) An assertion error within the processing of SIG queries can be exploited to crash either a recursive server when more than one SIG(covered) Resource Record set (RRset) is returned or an authoritative server serving a RFC 2535 DNSSEC zone where there are multiple SIG(covered) RRsets.

<span style="font-weight: bold;">Excessive Recursive Queries INSIST failure (CVE-2006-4096):</span>
2) An error within the handling of multiple recursive queries can be exploited to trigger an INSIST failure by causing the response to the query to arrive after all clients looking for the response have left the recursion queue.

So ensure you are patched to the current version: BIND 9.3.3rc2, BIND 9.3.2-P1, BIND 9.2.7rc1, or BIND 9.2.6-P1.

Updates are available here.

As of this time we have not received any information on an exploit for either vulnerability.

</div> </div> <div class="diarystory">

********************************

This is a direct copy of the source code from their page ...

[ Reply ]

 

[Todays Cartoon Discussion] [News Index]

Come get yer ARS (Account Registration System) Source Code here!
All images, characters, content and text are copyrighted and trademarks of J.D. Frazer except where other ownership applies. Don't do bad things, we have lawyers.
UserFriendly.Org and its operators are not liable for comments or content posted by its visitors, and will cheerfully assist the lawful authorities in hunting down script-kiddies, spammers and other net scum. And if you're really bad, we'll call your mom. (We're not kidding, we've done it before.)