ICANN/GNSO GNSO Email List Archives

[ga]


<<< Chronological Index >>>    <<< Thread Index >>>

[ga] Another DNS Flaw Found, Patched

  • To: Ga <ga@xxxxxxxxxxxxxx>, ICANN SSAC <ssac-liaison@xxxxxxxxxxxxxxxxxxxxxxx>, "twomey@xxxxxxxxx" <twomey@xxxxxxxxx>
  • Subject: [ga] Another DNS Flaw Found, Patched
  • From: "Jeffrey A. Williams" <jwkckid1@xxxxxxxxxxxxx>
  • Date: Sat, 10 Jan 2009 01:15:33 -0800

All,

  I wonder how many name server operators have implimented
the patch so far.  It seems ICANN has yet to do so...

See:
Remember the big DNS flaw that Dan Kaminsky
'discovered' last year? Well, it looks like
http://www.internetnews.com/security/article.php/3795311/Another+DNS+flaw.htm

another flaw in DNS has just been patched. This time it's an item that
affects DNSSEC, which was supposed to be the savior for
http://it.slashdot.org/article.pl?sid=08/07/08/195225&tid=172 the
Kaminsky
flaw. The good news, though, is that this time, the issue is relatively
minor
and DNS has already been patched. 'The flaw is specific to certain
usages of DNSSEC,' Joao Damas, senior programming manager of the ISC
told InternetNews. 'It is strongly advised that all BIND DNSSEC
deployments
update in case they are using the particular pattern affected (DSA keys
in
some cases) and to prevent coming across the problem in the future
unexpectedly.'

Regards,

Spokesman for INEGroup LLA. - (Over 284k members/stakeholders strong!)
"Obedience of the law is the greatest freedom" -
   Abraham Lincoln
"YES WE CAN!"  Barack ( Berry ) Obama

"Credit should go with the performance of duty and not with what is
very often the accident of glory" - Theodore Roosevelt

"If the probability be called P; the injury, L; and the burden, B;
liability depends upon whether B is less than L multiplied by
P: i.e., whether B is less than PL."
United States v. Carroll Towing  (159 F.2d 169 [2d Cir. 1947]
===============================================================
Updated 1/26/04
CSO/DIR. Internet Network Eng. SR. Eng. Network data security IDNS.
div. of Information Network Eng.  INEG. INC.
ABA member in good standing member ID 01257402 E-Mail
jwkckid1@xxxxxxxxxxxxx
My Phone: 214-244-4827




<<< Chronological Index >>>    <<< Thread Index >>>