]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
add CVE-2017-3136 note
authorMark Andrews <marka@isc.org>
Wed, 15 Feb 2017 01:44:12 +0000 (12:44 +1100)
committerMark Andrews <marka@isc.org>
Wed, 15 Feb 2017 01:44:12 +0000 (12:44 +1100)
doc/arm/notes.xml

index ebde91ccb658d41a9755e5809fbe511620d48e1c..4a637cf05303d6e5d81f0cd7420a216fda8b634e 100644 (file)
 
   <section xml:id="relnotes_security"><info><title>Security Fixes</title></info>
     <itemizedlist>
+      <listitem>
+       <para>
+         <command>dns64</command> with <command>break-dnssec yes;</command>
+         can result in an assertion failure. This flaw is disclosed in
+         CVE-2017-3136.[RT #44653]
+       </para>
+      </listitem>
       <listitem>
        <para>
          If a server is configured with a response policy zone (RPZ)