Subscribe to Windows IT Pro
October 18, 2001 11:52 AM

Keep an Eye on BIND Bugs

Windows IT Pro
InstantDoc ID #22931
Rating: (0)

Earlier this year, the CERT Coordination Center (CERT/CC), a US government—funded Internet-security think tank, announced the existence of four security holes in BIND versions earlier than 8.2.3. The vulnerabilities let intruders easily access BIND servers, perform Denial of Service (DoS) attacks, hijack Web sites, and redirect email traffic. (To read CERT/CC's report about these holes, see "CERT Advisory CA-2001-02 Multiple Vulnerabilities in BIND" at http://www.cert.org/advisories/CA-2001-02.html. The Internet Software Consortium—ISC—which develops and maintains the BIND source codes, provides a list of known BIND security bugs at http://www.isc.org/products/BIND/bind-security.html.)

The CERT/CC urged companies that use BIND to immediately upgrade to BIND 8.2.3 or later or BIND 9.1.0 or later, which aren't vulnerable to the identified security holes. (Microsoft's DNS Server isn't a BIND implementation and therefore isn't vulnerable to these particular bugs.)

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.