SecureLink recommends Infoblox upgrade

US-CERT has issued Vulnerability Note VU#725188 (CVE-2009-0696) related to a vulnerability that may allow a remote, unauthenticated attacker to create a denial-of-service condition in BIND 9. The denial-of-service condition can occur when processing a specially-crafted dynamic DNS update packet . The vulnerability affects all servers that are masters for one or more zones and is not limited to those that are configured to allow dynamic updates. Infoblox has already patched several versions of NIOS. These have been posted on the Infoblox support site, including the following versions:

  • 4.2r5-5
  • 4.3r2-9
  • 4.3r4-4
  • 4.3r5-1
 

If you have any questions, please contact SecureLink Technical Support (support@securelink.be).