Saturday, July 27, 2013

Swiss Guard - BIND 9 denial of service in the wild

Watch out if you run BIND 9 for domain name services . It appears that if you put together a specially malformed rdata part of a request you can take the DNS server down, and that means a denial of service weapon. It appears to be being used in the wild already.  The news comes via the Internet Storm Center and takes us to an ISC Advisory for CVE-2013-4854. BIND 9 versions are all affected, except for BIND 9.6 and 9.6-ESV, but including BIND 9.7 and later. BIND 10 is unaffected. You should see updates from your repositories soon if you use a distro supplied BIND. If you roll your own, head to the ISC downloads page and get to work.



And if you don't have to worry about it, here's a name related song for you to enjoy.

Cuts off a bit sharpish but you can find the full version on Live Lounge 3.

No comments: