FreeBSD Security Advisory - FreeBSD-SA-16:08.bind

Discussion in 'News Aggregator' started by Packet Storm, 28 Jan 2016.

  1. Packet Storm

    Packet Storm Guest

    FreeBSD Security Advisory - There is an off-by-one error in a buffer size check when performing certain string formatting operations. Slaves using text-format db files could be vulnerable if receiving a malformed record in a zone transfer from their master. Masters using text-format db files could be vulnerable if they accept a malformed record in a DDNS update message. Recursive resolvers are potentially vulnerable when debug logging is enabled and if they are fed a deliberately malformed record by a malicious server. A server which has cached a specially constructed record could encounter this condition while performing 'rndc dumpdb'.

    Continue reading...
     

Share This Page

Loading...