Summary: | [DNS Amplification Attacks] Включить поддержку DNS RRL (доступно, начиная с 9.9.4 и 9.10.x) | ||
---|---|---|---|
Product: | Sisyphus | Reporter: | Sergey Y. Afonin <asy> |
Component: | bind | Assignee: | placeholder <placeholder> |
Status: | CLOSED FIXED | QA Contact: | qa-sisyphus |
Severity: | normal | ||
Priority: | P3 | CC: | evg, george, glebfm, ldv, mike, placeholder, sem, slev |
Version: | unstable | ||
Hardware: | all | ||
OS: | Linux |
Description
Sergey Y. Afonin
2014-10-14 11:35:10 MSK
*** Bug 29573 has been marked as a duplicate of this bug. *** Оказывается, её и в 9.9.4 добавили: BIND 9.9.4 BIND 9.9.4 is a maintenance release, and patches the security flaws described in CVE-2013-3919 and CVE-2013-4854. It also introduces DNS Response Rate Limiting (DNS RRL) as a compile-time option. To use this feature, configure with the "--enable-rrl" option. То есть, надо просто включить при сборке, а до 9.10 можно и не обновлять. bind-9.9.6-alt1 -> sisyphus: * Tue Nov 18 2014 Fr. Br. George <george@altlinux> 9.9.6-alt1 - Update to ftp://ftp.isc.org/isc/bind9/9.9.6/bind-9.9.6.tar.gz - Fix old style autoheader AC_DEFINE - Enable ratelimits (Closes: #30398) - Provide initial rndc_keygen (Closes: #28034) * Mon Oct 06 2014 Fr. Br. George <george@altlinux> 9.9.5-alt3 - Build with GSSAPI * Tue Jun 17 2014 Fr. Br. George <george@altlinux> 9.9.5-alt2 - Updated to ftp://ftp.isc.org/isc/bind9/9.9.5-P1/bind-9.9.5-P1.tar.gz |