>> Bind Security Update Fixes OpenSSL Security Bypass and Denial of Service Issues
Title : Bind Security Update Fixes OpenSSL Security Bypass and Denial of Service Issues VUPEN ID : VUPEN/ADV-2006-4327 CVE ID : CVE-2006-2937 - CVE-2006-2940 - CVE-2006-4339
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-11-03
Technical Description
Internet Systems Consortium has released security updates for BIND to address multiple vulnerabilities identified in OpenSSL. This flaw could be exploited by attackers to cause a denial of service or bypass security restrictions. For additional information, see : VUPEN/ADV-2006-3820 - VUPEN/ADV-2006-3453
Upgrade to BIND 9.2.6-P2, BIND 9.2.3-P2, BIND 9.2.7rc3, BIND 9.3.3rc3 or BIND 9.4.0b3, and generate new RSASHA1 and RSAMD5 keys : http://www.isc.org/sw/bind/ References