Go to file
Ana Guerrero 6d71b07ade Accepting request 1112571 from network
- Update to release 9.18.19
  Security Fixes:
  * Previously, sending a specially crafted message over the
    control channel could cause the packet-parsing code to run out
    of available stack memory, causing named to terminate
    unexpectedly. This has been fixed. (CVE-2023-3341)
    [bsc#1215472]
  * A flaw in the networking code handling DNS-over-TLS queries
    could cause named to terminate unexpectedly due to an assertion
    failure under significant DNS-over-TLS query load. This has
    been fixed. (CVE-2023-4236)
    [bsc#1215471]
  Removed Features:
  * The dnssec-must-be-secure option has been deprecated and will
    be removed in a future release.
  Feature Changes:
  * If the server command is specified, nsupdate now honors the
    nsupdate -v option for SOA queries by sending both the UPDATE
    request and the initial query over TCP.
  Bug Fixes:
  * The value of the If-Modified-Since header in the statistics
    channel was not being correctly validated for its length,
    potentially allowing an authorized user to trigger a buffer
    overflow. Ensuring the statistics channel is configured
    correctly to grant access exclusively to authorized users is
    essential (see the statistics-channels block definition and
    usage section).
  * The Content-Length header in the statistics channel was lacking
    proper bounds checking. A negative or excessively large value
    could potentially trigger an integer overflow and result in an
    assertion failure.
  * Several memory leaks caused by not clearing the OpenSSL error
    stack were fixed.
  * The introduction of krb5-subdomain-self-rhs and
    ms-subdomain-self-rhs UPDATE policies accidentally caused named
    to return SERVFAIL responses to deletion requests for
    non-existent PTR and SRV records. This has been fixed.
  * The stale-refresh-time feature was mistakenly disabled when the
    server cache was flushed by rndc flush. This has been fixed.
  * BIND’s memory consumption has been improved by implementing
    dedicated jemalloc memory arenas for sending buffers. This
    optimization ensures that memory usage is more efficient and
    better manages the return of memory pages to the operating
    system.
  * Previously, partial writes in the TLS DNS code were not
    accounted for correctly, which could have led to DNS message
    corruption. This has been fixed.

OBS-URL: https://build.opensuse.org/request/show/1112571
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/bind?expand=0&rev=202
2023-09-22 19:47:10 +00:00
.gitattributes OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/bind?expand=0&rev=1 2006-12-18 23:15:14 +00:00
.gitignore OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/bind?expand=0&rev=1 2006-12-18 23:15:14 +00:00
bind-9.18.19.tar.xz Updating link to change in openSUSE:Factory/bind revision 202 2023-09-22 19:47:10 +00:00
bind-9.18.19.tar.xz.asc Updating link to change in openSUSE:Factory/bind revision 202 2023-09-22 19:47:10 +00:00
bind-ldapdump-use-valid-host.patch Accepting request 1008578 from home:mcepl:branches:network 2022-10-06 23:52:09 +00:00
bind.changes Updating link to change in openSUSE:Factory/bind revision 202 2023-09-22 19:47:10 +00:00
bind.conf Accepting request 992780 from home:jcronenberg:branches:network 2022-08-04 14:25:35 +00:00
bind.keyring Updating link to change in openSUSE:Factory/bind revision 192 2023-02-17 15:44:01 +00:00
bind.spec Updating link to change in openSUSE:Factory/bind revision 202 2023-09-22 19:47:10 +00:00
dlz-schema.txt Updating link to change in openSUSE:Factory/bind revision 45.0 2010-04-13 19:20:44 +00:00
dnszone-schema.txt Accepting request 614550 from home:nkukreja:branches:network 2018-06-07 06:48:37 +00:00
named.conf Accepting request 787151 from home:kukuk:container 2020-03-23 07:34:53 +00:00
named.root Accepting request 909186 from home:polslinux:branches:network 2021-07-29 13:39:41 +00:00
vendor-files.tar.bz2 Updating link to change in openSUSE:Factory/bind revision 201 2023-09-12 19:02:08 +00:00