[dns-operations] Subverting BIND's SRTT Algorithm Derandomizing NS Selection

Peter Losher plosher at isc.org
Tue May 6 17:50:19 UTC 2014


On 6 May 2014, at 9:09, Paul Ferguson wrote:

> Can anyone from ISC (bind maintainer) comment on this vulnerability,
> especially regarding what versions are affected and if a fix is available?
>
> https://www.usenix.org/conference/woot13/workshop-program/presentation/hay

We/ISC posted a Operational notice on this last August:
https://kb.isc.org/article/AA-01030

-Peter
--
[ plosher at isc.org | Senior Operations Architect | ISC | PGP E8048D08 ]



More information about the dns-operations mailing list