Re: [DSA 1605-1] DNS vulnerability impact on the libc stub resolver

2008-08-11 Thread Florian Weimer
* Hideki Yamane: > On Sun, 10 Aug 2008 22:11:05 +0200 > Florian Weimer <[EMAIL PROTECTED]> wrote: >> The 2.6.24 >> kernel available since the last etch point release offers some >> protection as well. > > Umm? This is NEW information for me. Could you give me any > references? It adds a weak fo

Re: [DSA 1605-1] DNS vulnerability impact on the libc stub resolver

2008-08-11 Thread Moritz Muehlenhoff
Hideki Yamane wrote: >> The 2.6.24 >> kernel available since the last etch point release offers some >> protection as well. > > Umm? This is NEW information for me. Could you give me any references? > (certainly if you can disclosure. It is a sensitive issue.) The Linux kernel implements UDP s

Re: [DSA 1605-1] DNS vulnerability impact on the libc stub resolver

2008-08-11 Thread Rick Moen
Quoting Hideki Yamane ([EMAIL PROTECTED]): > I want to know that, too. > Should ALL systems (servers or desktops/laptops) need to be installed > and configure bind9 (or something) package, or need to wait for update? My own preference is, indeed, to have one of the following as a local recursi