notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
non port: dns/bind96/files/patch-bin__nsupdate__nsupdate.c

Number of commits found: 2

Tuesday, 2 Aug 2011
06:53 dougb search for other commits by this committer
Remove patch incorporated into version 9.6-ESV-R5
Original commit
Friday, 27 May 2011
23:47 dougb search for other commits by this committer
Upgrade to 9.6-ESV-R4-P1 and 9.7.3-P1, which address the following issues:

1. Very large RRSIG RRsets included in a negative cache can trigger
an assertion failure that will crash named (BIND 9 DNS) due to an
off-by-one error in a buffer size check.

This bug affects all resolving name servers, whether DNSSEC validation
is enabled or not, on all BIND versions prior to today. There is a
possibility of malicious exploitation of this bug by remote users.

2. Named could fail to validate zones listed in a DLV that validated
insecure without using DLV and had DS records in the parent zone.

Add a patch provided by ru@ and confirmed by ISC to fix a crash at
shutdown time when a SIG(0) key is being used.
Original commit

Number of commits found: 2