]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
Add release note for [GL #4152]
authorMark Andrews <marka@isc.org>
Tue, 20 Jun 2023 05:38:40 +0000 (15:38 +1000)
committerMichal Nowak <mnowak@isc.org>
Thu, 7 Sep 2023 17:47:59 +0000 (19:47 +0200)
doc/notes/notes-current.rst

index 6b355503610ab63957897e6d3804ed9b19f72c9f..9cd2daac3ecfb02416305258f6daef3213518b94 100644 (file)
@@ -15,7 +15,13 @@ Notes for BIND 9.19.17
 Security Fixes
 ~~~~~~~~~~~~~~
 
-- None.
+- Previously, sending a specially crafted message over the control
+  channel could cause the packet-parsing code to run out of available
+  stack memory, causing :iscman:`named` to terminate unexpectedly.
+  This has been fixed. (CVE-2023-3341)
+
+  ISC would like to thank Eric Sesterhenn from X41 D-Sec GmbH for
+  bringing this vulnerability to our attention. :gl:`#4152`
 
 New Features
 ~~~~~~~~~~~~