| Summary: | [DNS Amplification Attacks] Включить поддержку DNS RRL (доступно, начиная с 9.9.4 и 9.10.x) | ||
|---|---|---|---|
| Product: | Sisyphus | Reporter: | Sergey Y. Afonin <asy> |
| Component: | bind | Assignee: | placeholder <placeholder> |
| Status: | CLOSED FIXED | QA Contact: | qa-sisyphus |
| Severity: | normal | ||
| Priority: | P3 | CC: | evg, george, glebfm, ldv, mike, placeholder, sem, slev, vt |
| Version: | unstable | ||
| Hardware: | all | ||
| OS: | Linux | ||
|
Description
Sergey Y. Afonin
2014-10-14 11:35:10 MSK
*** Bug 29573 has been marked as a duplicate of this bug. *** Оказывается, её и в 9.9.4 добавили:
BIND 9.9.4
BIND 9.9.4 is a maintenance release, and patches the security
flaws described in CVE-2013-3919 and CVE-2013-4854. It also
introduces DNS Response Rate Limiting (DNS RRL) as a
compile-time option. To use this feature, configure with
the "--enable-rrl" option.
То есть, надо просто включить при сборке, а до 9.10 можно и не обновлять.
bind-9.9.6-alt1 -> sisyphus: * Tue Nov 18 2014 Fr. Br. George <george@altlinux> 9.9.6-alt1 - Update to ftp://ftp.isc.org/isc/bind9/9.9.6/bind-9.9.6.tar.gz - Fix old style autoheader AC_DEFINE - Enable ratelimits (Closes: #30398) - Provide initial rndc_keygen (Closes: #28034) * Mon Oct 06 2014 Fr. Br. George <george@altlinux> 9.9.5-alt3 - Build with GSSAPI * Tue Jun 17 2014 Fr. Br. George <george@altlinux> 9.9.5-alt2 - Updated to ftp://ftp.isc.org/isc/bind9/9.9.5-P1/bind-9.9.5-P1.tar.gz |