All the latest UK technology news, reviews and analysis

Internet Storm Center warns of BIND zero-day flaw

by Iain Thomson

24 Feb 2011

Be the first to comment

  • Tweet this


A warning has been issued about a vulnerability in BIND, one of the most popular (DNS) server systems on the internet.

The Internet Storm Center (ISC) is warning system administrators about the flaw which can lock up BIND by use of a special query. BIND 9.7.1 or 9.7.2 are vulnerable to the flaw and admins have been urged to upgrade to BIND 9.7.3.

"Depending on your performance requirements, a work-around may be available. ISC was not able to reproduce this defect in 9.7.2 using -n1, which causes named to use only one worker thread, thus avoiding the deadlock," it advised.

"If your server is powerful enough to serve your data with a single processor, this option may be fast to implement until you have time to perform an upgrade."

Earlier versions are not vulnerable. If you run BIND 9.6.x, 9.6-ESV-Rx, or 9.4-ESV-R4, you do not need to upgrade.

ISC said that the flaw had been identified by Neustar and no exploits have been seen in the wild so far. Security researchers Secunia rate the flaw 'moderately critical.'

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

2%

14%

53%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Functional Oracle Support Analyst

Functional Oracle Support Analyst - EBS Financials, Support...

Oracle E-Business Suite Technical Consultant

Oracle E-Business Suite Technical Consultant - EBS...

Oracle Applications DBA

Oracle Applications DBA - East London - All salaries...

Oracle Functional Consultants

Oracle Functional Consultants - Financial - Project Accounting...

To send to more than one email address, simply separate each address with a comma.