NetBSD
NetBSD is believed to be vulnerable to these problems; in response,
NetBSD-current has been upgraded to 8.2.2-P7 and 8.2.2-P7 will be
present in the forthcoming NetBSD 1.5 release.
RedHat
Please see "RHSA-2000:107-01: Updated bind packages fixing DoS
attack", available at:
- http://www.redhat.com/support/errata/RHSA-2000-107.html
Slackware
Updated Slackware distributions for bind may be found at:
- ftp://ftp.slackware.com/pub/slackware/slackware-current/slakware/n1/bind.tgz
SuSE Inc
SuSE Linux has published a Security Announcement regarding these
vulnerabilities. For further information, please visit:
- http://www.suse.com/de/support/security/2000_045_bind8_txt.txt
The CERT Coordination Center thanks Mark Andrews, David Conrad, and
Paul Vixie of the ISC for developing
a solution and assisting in the preparation of this advisory. We would
also recognize the contribution of Olaf Kirch in helping us understand
the exact nature of the "zxfr bug" vulnerability.
Author: This document was written by Jeffrey S. Havrilla and Jeffrey P. Lanza.
Feedback on this advisory is appreciated.
This document is available from:
http://www.cert.org/advisories/CA-2000-20.html
CERT/CC Contact Information
Email: cert@cert.org
Phone: +1 412-268-7090 (24-hour hotline)
Fax: +1 412-268-6989
Postal address:
-
CERT Coordination Center
Software Engineering Institute
Carnegie Mellon University
Pittsburgh PA 15213-3890
U.S.A.
CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4)
Monday through Friday; they are on call for emergencies during other
hours, on U.S. holidays, and on weekends.
Using encryption
We strongly urge you to encrypt sensitive information sent by
email. Our public PGP key is available from
If you prefer to use DES, please call the CERT hotline for more
information.
Getting security information
CERT publications and other security information are available from
our web site
* "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office.
NO WARRANTY
Any material furnished by Carnegie Mellon University and the
Software Engineering Institute is furnished on an "as is"
basis. Carnegie Mellon University makes no warranties of any kind,
either expressed or implied as to any matter including, but not
limited to, warranty of fitness for a particular purpose or
merchantability, exclusivity or results obtained from use of the
material. Carnegie Mellon University does not make any warranty of any
kind with respect to freedom from patent, trademark, or copyright
infringement.