[Info-vax] New VSI Roadmap (yipee!)

Craig A. Berry craigberry at nospam.mac.com
Sun Mar 1 19:05:54 EST 2015


On 3/1/15 2:25 PM, Stephen Hoffman wrote:
> On 2015-03-01 19:44:01 +0000, Kerry Main said:
>
>> From what I can see on the ISC web site, BIND 9.9.7 and 9.10 was only
>> just released in Feb 2015.
>
> Welcome to Internet Time.  This is one of the problems most everybody's
> having, as the patches and the bugs and the attacks and the updates are
> arriving at ever faster rates.
>
>> Btw, the current release of TCPIP is ECO 5.
>
> ECO 5 was placed on hold, reportedly due to a telnet crash.  ECO5 —
> hopefully to be known as ECO6 — will be reissued soon, but ECO4 is
> (again) current.  See the " TCPIP v5.7 eco5" thread.

The once and future ECO 5 does have 3 BIND fixes in it, two of them CVEs
(CVE-2012-4244 AND CVE-2009-0025). In other words, it fixes one
six-year-old vulnerability and one three-year-old vulnerability. As far
as Internet Time goes, that's eons of exposure. And it still reports
itself as version 9.3.1.




More information about the Info-vax mailing list