NetBSD Information for VU#734644
ISC BIND 8 vulnerable to cache poisoning via negative responses
- Vendor Information Help Date Notified: 21 Oct 2003
- Statement Date:
- Date Updated: 17 Nov 2003
NetBSD (1.6, 1.6.1 and current) is shipping with vulnerable version of BIND 8. We will upgrade to either 8.3.7 or 8.4.2 as soon as ISC releases the info to the public. Or, users might want to use BIND 9 from pkgsrc.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.