From mboxrd@z Thu Jan 1 00:00:00 1970 From: Matthias Fischer To: development@lists.ipfire.org Subject: [PATCH] bind: Update to 9.11.0-P5 Date: Sun, 16 Apr 2017 14:11:10 +0200 Message-ID: <20170416121110.1826-1-matthias.fischer@ipfire.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============4413015951736931737==" List-Id: --===============4413015951736931737== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable For details see: https://ftp.isc.org/isc/bind9/9.11.0-P5/RELEASE-NOTES-bind-9.11.0-P5.html "BIND 9.11.0-P5 addresses the security issues described in CVE-2017-3136, CVE-2017-3137, and CVE-2017-3138, and updates the built-in trusted keys for t= he root zone. Security Fixes rndc "" could trigger an assertion failure in named. This flaw is disclosed in (CVE-2017-3138). [RT #44924] Some chaining (i.e., type CNAME or DNAME) responses to upstream queries could trigger assertion failures. This flaw is disclosed in CVE-2017-3137. [RT #447= 34] dns64 with break-dnssec yes; can result in an assertion failure. This flaw is disclosed in CVE-2017-3136. [RT #44653] If a server is configured with a response policy zone (RPZ) that rewrites an answer with local data, and is also configured for DNS64 address mapping, a N= ULL pointer can be read triggering a server crash. This flaw is disclosed in CVE-= 2017-3135. [RT #44434] A coding error in the nxdomain-redirect feature could lead to an assertion fa= ilure if the redirection namespace was served from a local authoritative data source s= uch as a local zone or a DLZ instead of via recursive lookup. This flaw is disclosed in CVE-2016-9778. [RT #43837] named could mishandle authority sections with missing RRSIGs, triggering an a= ssertion failure. This flaw is disclosed in CVE-2016-9444. [RT #43632] named mishandled some responses where covering RRSIG records were returned wi= thout the requested data, resulting in an assertion failure. This flaw is disclosed in CVE-2016-9147. [RT #43548] named incorrectly tried to cache TKEY records which could trigger an assertio= n failure when there was a class mismatch. This flaw is disclosed in CVE-2016-9131. [RT= #43522] It was possible to trigger assertions when processing responses containing an= swers of type DNAME. This flaw is disclosed in CVE-2016-8864. [RT #43465] Bug Fixes A synthesized CNAME record appearing in a response before the associated DNAM= E could be cached, when it should not have been. This was a regression introduced while = addressing CVE-2016-8864. [RT #44318] Best, Matthias Signed-off-by: Matthias Fischer --- lfs/bind | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lfs/bind b/lfs/bind index e178219c2..ea6fb835b 100644 --- a/lfs/bind +++ b/lfs/bind @@ -25,7 +25,7 @@ =20 include Config =20 -VER =3D 9.11.0-P3 +VER =3D 9.11.0-P5 =20 THISAPP =3D bind-$(VER) DL_FILE =3D $(THISAPP).tar.gz @@ -43,7 +43,7 @@ objects =3D $(DL_FILE) =20 $(DL_FILE) =3D $(DL_FROM)/$(DL_FILE) =20 -$(DL_FILE)_MD5 =3D 311787a0a69345a1f1cf7869b0266bf0 +$(DL_FILE)_MD5 =3D 3e1e525fc640308316cdf98cd29cfa11 =20 install : $(TARGET) =20 --=20 2.11.0 --===============4413015951736931737==--