FreeBSD Security Advisory FreeBSD-SA-14:30.unbound

Darren Pilgrim list_freebsd at bluerosetech.com
Wed Dec 17 18:12:28 UTC 2014


On 12/17/2014 12:36 AM, FreeBSD Security Advisories wrote:
> IV.  Workaround
>
> No workaround is available, but hosts not running unbound(8) are not
> vulnerable.

The first part of that statement is false.  The dns/unbound port was 
fixed for CVE-2014-8602 on 9 December.  Thus a valid work around is to 
disable local_unbound and use ports/dns/unbound.


More information about the freebsd-security mailing list