Vulnerabilitate DoD bind – Update Plesk 9.5 si 10 windows

BIND a anuntat o vulnerabilitate care poate duce la producerea unui denial of service. Aceasta vulnerabilitate afecteaza toate serverele care ruleaza bind 9.7.1 si 9.7.2. Plesk 9.5 pentru Windows si Plesk 10 pentru Windows contin aceasta versiune de bind si este indicat un upgrade cat mai rapid la versiunea 9.7.3.

Descriere vulnerabilitate:

https://www.isc.org/software/bind/advisories/cve-2009-0696

“Receipt of a specially-crafted dynamic update message to a zone for which the server is the master may cause BIND 9 servers to exit. Testing indicates that the attack packet has to be formulated against a zone for which that machine is a master. Launching the attack against slave zones does not trigger the assert.

This vulnerability affects all servers that are masters for one or more zones – it is not limited to those that are configured to allow dynamic updates. Access controls will not provide an effective workaround.”

Cum se efectueaza upgrade de Bind pe windows: http://kb.parallels.com/5542

No Comments Yet

Leave a Reply

Your email address will not be published. Required fields are marked *