Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: US-CERT Vulnerability Note VU#800113



On Mon, Jul 28, 2008 at 5:43 PM, Chris <email@hidden> wrote:
> On Jul 28, 2008, at 3:42 PM, Bill Larson wrote:
>
>> On Jul 28, 2008, at 12:29 PM, jeff donovan wrote:
>>
>>> I don't think Apple has released a patch because ISC is till working out
>>> some tweaks with performance on high volume recursive servers.
>>
>> From Paul Vixie, speaking for ISC:
>>
>>        UNTIL THE RELEASE OF THE -P2 CODE, IT IS IMPERATIVE THAT YOU RUN A
>> -P1
>>        VERSION OF BIND ON YOUR CACHING RESOLVERS.  THE VULNERABILITY IS OF
>> MORE
>>        CONCERN THAN A SLOW SERVER.
>>
>> Yes, there are performance issues with the current patch version of BIND
>> to eliminate the DNS vulnerability, but that doesn't mean hide your head in
>> the sand.  The problems reported on the BIND-USERS mailing list are mainly
>> identifying problems with some Linux systems (not all of them) and Solaris.
>
> And I don't hear anyone who rolled their own 9.4.2-P1 complaining that it
> performs unacceptably.
>
> They should issue the patch and let us decide whether or not the risk of
> poor performance is greater or lesser than the risk of cache poisoning.
>
> For me, it's better to give the right address for paypal.com with a possible
> performance hit than it is to give the wrong answer quickly.
> _______________________________________________
> Do not post admin requests to the list. They will be ignored.
> Macos-x-server mailing list      (email@hidden)
> Help/Unsubscribe/Update your Subscription:
> http://lists.apple.com/mailman/options/macos-x-server/email@hidden
>
> This email sent to email@hidden
>

Also, I would imagine that most os x servers do a pretty light amount
of dns work, as that is a secondary feature (ie, you don't buy an
xserve to be your DNS box). I could see institutions being large
enough to dedicate one or two boxes for dns by themselves, but if that
were the case I wouldn't spend the money on an xserve, when a box
running redhat would be sufficient (and patched faster).

Speaking of which, I am surprised there isn't a premade, bind specific
CentOS vmware image out there, for instant drop in bind replacement.

-- 
Chris Barker
Purveyor of Fine Suggestions
ACSA
 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/macos-x-server/email@hidden

This email sent to email@hidden

References: 
 >Re: US-CERT Vulnerability Note VU#800113 (From: "John C. Welch" <email@hidden>)
 >Re: US-CERT Vulnerability Note VU#800113 (From: Jaime Magiera <email@hidden>)
 >Re: US-CERT Vulnerability Note VU#800113 (From: Angus Fox <email@hidden>)
 >Re: US-CERT Vulnerability Note VU#800113 (From: Jose Hales-Garcia <email@hidden>)
 >Re: US-CERT Vulnerability Note VU#800113 (From: "Chris Barker" <email@hidden>)
 >Re: US-CERT Vulnerability Note VU#800113 (From: Robert Cerny <email@hidden>)
 >Re: US-CERT Vulnerability Note VU#800113 (From: jeff donovan <email@hidden>)
 >Re: US-CERT Vulnerability Note VU#800113 (From: Bill Larson <email@hidden>)
 >Re: US-CERT Vulnerability Note VU#800113 (From: Chris <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.