|
HP-UX update for bind
|
|
Secunia Advisory:
|
SA31143
|
|
|
Release Date:
|
2008-07-17
|
|
Last Update:
|
2008-08-11
|
|
Popularity:
|
3,608 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Spoofing
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | HP-UX 11.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
| | CVE reference: | CVE-2008-1447
|
|
Description: HP has issued an update for bind. This fixes a vulnerability, which can be exploited by malicious people to poison the DNS cache.
For more information:
SA30973
The vulnerability is reported in HP-UX B.11.11, B.11.23, and B.11.31 running BIND v9.3.2 or BIND v9.2.0, and HP-UX B.11.11 running BIND v8.1.2
Solution: Apply patches. Remove "query-source port" and "query-source-v6 port" options in /etc/named.conf and check your firewall settings. See vendor advisory for more details.
-- BIND v8.1.2 --
HP-UX B.11.11:
InternetSrvcs.INETSVCS-RUN
Upgrade to BIND v9.2.0 or BIND v9.3.2 and apply the updates
-- BIND v9.3.2 --
HP-UX B.11.11:
BindUpgrade.BIND-UPGRADE
Install revision C.9.3.2.3.0 or subsequent
http://software.hp.com
HP-UX B.11.23:
BindUpgrade.BIND-UPGRADE
BindUpgrade.BIND2-UPGRADE
Install revision C.9.3.2.3.0 or subsequent
http://software.hp.com
HP-UX B.11.31:
NameService.BIND-AUX
NameService.BIND-RUN
Install revision C.9.3.2.3.0 or subsequent
http://software.hp.com
-- BIND v9.2.0 --
HP-UX B.11.11:
BINDv920.INETSVCS-BIND
Install revision B.11.11.01.011 or subsequent
ftp://ss080058:ss080058@hprc.external.hp.com
HP-UX B.11.23:
InternetSrvcs.INETSVCS-INETD
InternetSrvcs.INETSVCS-RUN
InternetSrvcs.INETSVCS2-RUN
Install patch PHNE_37865 or subsequent
http://itrc.hp.com
Changelog: 2008-07-21: Updated "Solution" section with patch information for BIND v9.2.0.
2008-08-06: Updated "Description" with information regarding BIND v8.1.2 and updated "Solution" section.
2008-08-11: Updated "Solution" section to include information regarding /etc/named.conf and firewall settings.
Original Advisory: HPSBUX02351 SSRT080058:
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01506861
Other References: SA30973:
http://secunia.com/advisories/30973/
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
15th Oct, 2008
|
New advisories:
|
16 |
|
New vulnerabilities:
|
60 |
|
Updated advisories:
|
36 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Solutions | More...
|
|