Skip to content
  1. May 06, 2021
  2. May 05, 2021
  3. May 04, 2021
  4. May 03, 2021
  5. May 01, 2021
  6. Apr 30, 2021
  7. Apr 29, 2021
    • Noah Meyerhans's avatar
      bind: bump to 9.17.12 · ccb1e892
      Noah Meyerhans authored
      
      
      Fixes the following security issues:
      
      * CVE-2021-25215 - named crashed when a DNAME record placed in the ANSWER
                         section during DNAME chasing turned out to be the final
                         answer to a client query.
      * CVE-2021-25214 - Insufficient IXFR checks could result in named serving a
                         zone without an SOA record at the apex, leading to a
                         RUNTIME_CHECK assertion failure when the zone was
                         subsequently refreshed. This has been fixed by adding an
                         owner name check for all SOA records which are included
                         in a zone transfer.
      
      Signed-off-by: default avatarNoah Meyerhans <frodo@morgul.net>
      ccb1e892