]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
CHANGES, release note
authorEvan Hunt <each@isc.org>
Fri, 6 Jul 2018 03:48:26 +0000 (20:48 -0700)
committerEvan Hunt <each@isc.org>
Fri, 13 Jul 2018 20:33:29 +0000 (13:33 -0700)
(cherry picked from commit 9c492aba65c178f30baafeb5502013f95a9d5b9a)
(cherry picked from commit ecb90158b6e457496922666f56c3f8f7cb3143d4)

CHANGES
doc/arm/notes.xml

diff --git a/CHANGES b/CHANGES
index 750b6001a7bef010fae39a8573f980825ee85fc6..c333cf70664e703fa02ed6941f9503b4fd286c93 100644 (file)
--- a/CHANGES
+++ b/CHANGES
@@ -1,3 +1,7 @@
+4997.  [security]      named could crash during recursive processing
+                       of DNAME records when "deny-answer-aliases" was
+                       in use. (CVE-2018-5740) [GL #387]
+
        --- 9.11.4 released ---
 
        --- 9.11.4rc2 released ---
index 220a20e696d99a1f5c44e9dc9913c36bba457e65..7b7475b58f0b69a619f95d48fbb6f4abfe5de2fb 100644 (file)
 
   <section xml:id="relnotes_security"><info><title>Security Fixes</title></info>
     <itemizedlist>
+      <listitem>
+       <para>
+         <command>named</command> could crash during recursive processing
+         of DNAME records when <command>deny-answer-aliases</command> was
+         in use. This flaw is disclosed in CVE-2018-5740. [GL #387]
+       </para>
+      </listitem>
       <listitem>
        <para>
          When recursion is enabled but the <command>allow-recursion</command>