Re: Confused about CVE-2013-2266

2013-04-04 Thread Mark Andrews
It says "or upgrade to the patched release most closely related to your current version of BIND" then it lists the two versions to choose from. 9.9.2-P2 is fixed as is 9.9.3b2. Mark In message , Red Cricket writes: > > Hi, > > I am sorry for being so dense but I am confused about what to d

Confused about CVE-2013-2266

2013-04-04 Thread Red Cricket
Hi, I am sorry for being so dense but I am confused about what to do about protecting my BIND DNS servers running 9.9.1-P4 from the regex issue. The link https://kb.isc.org/article/AA-00871 says this ... Impact: ... Intentional exploitation of this condition can cause denial of service in all a