[CentOS] BIND vulnerability

Thu Jul 30 00:41:54 UTC 2009
Stephen Harris <lists at spuddy.org>

In-Reply-To=<4A70B20C.5020808 at karan.org>
Reply-To: 

(Apologies if this isn't in the thread properly; I'm trying to fake it from
the website headers :-))

Karanbir Singh wrote:
> http://lists.centos.org/pipermail/centos-devel/2009-July/004794.html
> 
> I've updated 2 machines, and had no problems here. But some wider 
> testing would be good and we can get them into the main repos so more 
> people benefit.

I just updated one machine; the process ended up with named not running.

I did 
  rpm -Uvh bind-utils-9.2.4-30.el4_8.4.i386.rpm bind-9.2.4-30.el4_8.4.i386.rpm bind-libs-9.2.4-30.el4_8.4.i386.rpm

and got

  Jul 29 20:29:15 linode named:  succeeded
  Jul 29 20:29:16 linode named[2873]: shutting down: flushing changes
  Jul 29 20:29:16 linode named[2873]: stopping command channel on 127.0.0.1#953
  Jul 29 20:29:16 linode named[2873]: no longer listening on 127.0.0.1#53
  Jul 29 20:29:16 linode named[2873]: no longer listening on 66.160.141.105#53
  Jul 29 20:29:17 linode named[2873]: exiting
  Jul 29 20:29:18 linode named:  failed

After a restart it appeared to work...

  Jul 29 20:29:41 linode named[31609]: starting BIND 9.2.4 -u named
  Jul 29 20:29:41 linode named[31609]: using 4 CPUs
  Jul 29 20:29:41 linode named[31609]: loading configuration from '/etc/named.conf'

etc...

The daemon seems to be responding properly to requests after this manual
start.

-- 

rgds
Stephen