SHA256
1
0
forked from pool/bind
Go to file
Jorik Cronenberg 7a18d2cf86 Accepting request 1005206 from home:jcronenberg:branches:network
- Update to bind release 9.18.7
  Security Fixes:
  * Previously, there was no limit to the number of database lookups
    performed while processing large delegations, which could be
    abused to severely impact the performance of named running as a
    recursive resolver. This has been fixed. (CVE-2022-2795)
  * When an HTTP connection was reused to request statistics from the
    stats channel, the content length of successive responses could
    grow in size past the end of the allocated buffer.
    This has been fixed. (CVE-2022-2881)
  * Memory leaks in code handling Diffie-Hellman (DH) keys were fixed
    that could be externally triggered, when using TKEY records in DH
    mode with OpenSSL 3.0.0 and later versions. (CVE-2022-2906)
  * named running as a resolver with the stale-answer-client-timeout
    option set to 0 could crash with an assertion failure, when there
    was a stale CNAME in the cache for the incoming query.
    This has been fixed. (CVE-2022-3080)
  * Memory leaks were fixed that could be externally triggered in the
    DNSSEC verification code for the EdDSA algorithm. (CVE-2022-38178)
  Feature Changes:
  * Response Rate Limiting (RRL) code now treats all QNAMEs that are
    subject to wildcard processing within a given zone as the same
    name, to prevent circumventing the limits enforced by RRL.
  * Zones using dnssec-policy now require dynamic DNS or
    inline-signing to be configured explicitly.
  * When reconfiguring dnssec-policy from using NSEC with an NSEC-only
    DNSKEY algorithm (e.g. RSASHA1) to a policy that uses NSEC3,
    BIND 9 no longer fails to sign the zone; instead, it keeps using
    NSEC until the offending DNSKEY records have been removed from the
    zone, then switches to using NSEC3.
  * A backward-compatible approach was implemented for encoding
    internationalized domain names (IDN) in dig and converting the
    domain to IDNA2008 form; if that fails, BIND tries an IDNA2003
    conversion.
  Bug Fixes:
  * A serve-stale bug was fixed, where BIND would try to return stale
    data from cache for lookups that received duplicate queries or
    queries that would be dropped. This bug resulted in premature
    SERVFAIL responses, and has now been resolved.
  This obsoletes the following patch:
  * bind-fix-mysql-bindings.patch
  [bsc#1203614, bsc#1203615, bsc#1203616, bsc#1203618, bsc#1203620]

OBS-URL: https://build.opensuse.org/request/show/1005206
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=357
2022-09-21 13:17:51 +00:00
.gitattributes OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/bind?expand=0&rev=1 2006-12-18 23:15:14 +00:00
.gitignore OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/bind?expand=0&rev=1 2006-12-18 23:15:14 +00:00
bind-9.18.7.tar.xz Accepting request 1005206 from home:jcronenberg:branches:network 2022-09-21 13:17:51 +00:00
bind-9.18.7.tar.xz.sha512.asc Accepting request 1005206 from home:jcronenberg:branches:network 2022-09-21 13:17:51 +00:00
bind-ldapdump-use-valid-host.patch Accepting request 614182 from home:nkukreja:branches:network 2018-06-05 09:30:33 +00:00
bind.changes Accepting request 1005206 from home:jcronenberg:branches:network 2022-09-21 13:17:51 +00:00
bind.conf Accepting request 992780 from home:jcronenberg:branches:network 2022-08-04 14:25:35 +00:00
bind.keyring Accepting request 449784 from home:simotek:branches:network 2017-01-12 12:21:22 +00:00
bind.spec Accepting request 1005206 from home:jcronenberg:branches:network 2022-09-21 13:17:51 +00:00
dlz-schema.txt Updating link to change in openSUSE:Factory/bind revision 45.0 2010-04-13 19:20:44 +00:00
dnszone-schema.txt Accepting request 614550 from home:nkukreja:branches:network 2018-06-07 06:48:37 +00:00
named.conf Accepting request 787151 from home:kukuk:container 2020-03-23 07:34:53 +00:00
named.root Accepting request 909186 from home:polslinux:branches:network 2021-07-29 13:39:41 +00:00
vendor-files.tar.bz2 Accepting request 992780 from home:jcronenberg:branches:network 2022-08-04 14:25:35 +00:00