]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
add CVE-2017-3136 note
authorMark Andrews <marka@isc.org>
Wed, 15 Feb 2017 01:44:12 +0000 (12:44 +1100)
committerMark Andrews <marka@isc.org>
Wed, 15 Feb 2017 01:45:30 +0000 (12:45 +1100)
(cherry picked from commit d77eadc26113486f32fea25320ae4c6f1f2e7fb2)

doc/arm/notes.xml

index 3a7ece283812b44aca93573f99a3b053108ae4c5..c5c06abafd89a1f90b3240266051d77e1581ff77 100644 (file)
 
   <section xml:id="relnotes_security"><info><title>Security Fixes</title></info>
     <itemizedlist>
+      <listitem>
+       <para>
+         <command>dns64</command> with <command>break-dnssec yes;</command>
+         can result in an assertion failure. This flaw is disclosed in
+         CVE-2017-3136.[RT #44653]
+       </para>
+      </listitem>
       <listitem>
        <para>
          If a server is configured with a response policy zone (RPZ)