packages/net/bind
Noah Meyerhans 037f1def7d bind: Update to version 9.11.3 and optionally support eddsa for dnssec
EdDSA support is optional and currently defaults to being disabled.

The following security issues are addressed with this update:

  * An error in TSIG handling could permit unauthorized zone transfers
    or zone updates. These flaws are disclosed in CVE-2017-3142 and
    CVE-2017-3143.
  * The BIND installer on Windows used an unquoted service path, which
    can enable privilege escalation. This flaw is disclosed in
    CVE-2017-3141.
  * With certain RPZ configurations, a response with TTL 0 could cause
    named to go into an infinite query loop. This flaw is disclosed in
    CVE-2017-3140.
  * Addresses could be referenced after being freed during resolver
    processing, causing an assertion failure. The chances of this
    happening were remote, but the introduction of a delay in
    resolution increased them. This bug is disclosed in CVE-2017-3145.

Signed-off-by: Noah Meyerhans <frodo@morgul.net>
2018-06-13 21:46:03 -07:00
..
files net/bind: Update db.root 2016-03-20 14:38:15 +01:00
patches bind: patch unneeded if openssl is build w/ deprecated 2017-08-08 10:53:31 -06:00
Config.in bind: Update to version 9.11.3 and optionally support eddsa for dnssec 2018-06-13 21:46:03 -07:00
Makefile bind: Update to version 9.11.3 and optionally support eddsa for dnssec 2018-06-13 21:46:03 -07:00