]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
4270. [security] Update allowed OpenSSL versions as named is
authorMark Andrews <marka@isc.org>
Thu, 3 Dec 2015 23:28:22 +0000 (10:28 +1100)
committerMark Andrews <marka@isc.org>
Thu, 3 Dec 2015 23:39:54 +0000 (10:39 +1100)
                        potentially vulnerable to CVE-2015-3193.

(cherry picked from commit 10d7ab44cc72170c527dde8cc9e049e046342769)

CHANGES
configure
configure.in

diff --git a/CHANGES b/CHANGES
index 731d298dccc29506b6b7b78b1fc559b0fc582486..2b71dc8962732e1b9e175fa3ad25f0df1fda9b73 100644 (file)
--- a/CHANGES
+++ b/CHANGES
@@ -1,4 +1,12 @@
-       --- 9.9.8-P1 released ---
+       --- 9.9.8-P2 released ---
+
+4270.  [security]      Update allowed OpenSSL versions as named is
+                       potentially vulnerable to CVE-2015-3193.
+
+4253.  [security]      Address fetch context reference count handling error
+                       on socket error. (CVE-2015-8461) [RT#40945]
+
+       --- 9.9.8-P1 (withdrawn) ---
 
 4261.  [maint]         H.ROOT-SERVERS.NET is 198.97.190.53 and 2001:500:1::53.
                        [RT #40556]
@@ -8,9 +16,6 @@
                        triggering a REQUIRE failure when those records
                        were subsequently cached. (CVE-2015-8000) [RT #40987]
 
-4253.  [security]      Address fetch context reference count handling error
-                       on socket error. (CVE-2015-8461) [RT#40945]
-
        --- 9.9.8 released ---
 
        --- 9.9.8rc1 released ---
index 1c6c6cd50bd1cb850feae96ee3ad8dd6907f4b4e..bbe6357bff395e04a33637732457299195c029bb 100755 (executable)
--- a/configure
+++ b/configure
@@ -13796,12 +13796,17 @@ else
 int main() {
        if ((OPENSSL_VERSION_NUMBER >= 0x009070cfL &&
             OPENSSL_VERSION_NUMBER < 0x00908000L) ||
-            OPENSSL_VERSION_NUMBER >= 0x0090804fL)
+            OPENSSL_VERSION_NUMBER >= 0x0090804fL &&
+            OPENSSL_VERSION_NUMBER < 0x10002000L) ||
+            OPENSSL_VERSION_NUMBER >= 0x1000205fL)
                return (0);
        printf("\n\nFound   OPENSSL_VERSION_NUMBER %#010x\n",
                OPENSSL_VERSION_NUMBER);
        printf("Require OPENSSL_VERSION_NUMBER 0x009070cf or greater (0.9.7l)\n"
-              "Require OPENSSL_VERSION_NUMBER 0x0090804f or greater (0.9.8d)\n\n");
+              "Require OPENSSL_VERSION_NUMBER 0x0090804f or greater (0.9.8d)\n"
+              "Require OPENSSL_VERSION_NUMBER 0x1000000f or greater (1.0.0)\n"
+              "Require OPENSSL_VERSION_NUMBER 0x1000100f or greater (1.0.1)\n"
+              "Require OPENSSL_VERSION_NUMBER 0x1000205f or greater (1.0.2e)\n\n");
        return (1);
 }
 
@@ -23467,15 +23472,16 @@ WARNING         Your OpenSSL crypto library may be vulnerable to        WARNING
 WARNING         one or more of the the following known security         WARNING
 WARNING         flaws:                                                  WARNING
 WARNING                                                                 WARNING
-WARNING         CAN-2002-0659, CAN-2006-4339, CVE-2006-2937 and         WARNING
-WARNING         CVE-2006-2940.                                          WARNING
+WARNING         CAN-2002-0659, CAN-2006-4339, CVE-2006-2937,            WARNING
+WARNING         CVE-2006-2940 and CVE-2015-3193.                        WARNING
 WARNING                                                                 WARNING
 WARNING         It is recommended that you upgrade to OpenSSL           WARNING
-WARNING         version 0.9.8d/0.9.7l (or greater).                     WARNING
+WARNING         version 1.0.2e/1.0.1/1.0.0/0.9.9/0.9.8d/0.9.7l          WARNING
+WARNING         (or greater).                                           WARNING
 WARNING                                                                 WARNING
 WARNING         You can disable this warning by specifying:             WARNING
 WARNING                                                                 WARNING
-WARNING               --disable-openssl-version-check                          WARNING
+WARNING               --disable-openssl-version-check                   WARNING
 WARNING                                                                 WARNING
 WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING
 WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING
index 6909b69460fc7d0426e9bf9faab0c7692f5f0b83..4e7b919b95bc279f5036c2df1eda8f14fddaf6a1 100644 (file)
@@ -810,12 +810,17 @@ yes|'')
 int main() {
        if ((OPENSSL_VERSION_NUMBER >= 0x009070cfL &&
             OPENSSL_VERSION_NUMBER < 0x00908000L) ||
-            OPENSSL_VERSION_NUMBER >= 0x0090804fL)
+            OPENSSL_VERSION_NUMBER >= 0x0090804fL &&
+            OPENSSL_VERSION_NUMBER < 0x10002000L) ||
+            OPENSSL_VERSION_NUMBER >= 0x1000205fL)
                return (0);
        printf("\n\nFound   OPENSSL_VERSION_NUMBER %#010x\n",
                OPENSSL_VERSION_NUMBER);
        printf("Require OPENSSL_VERSION_NUMBER 0x009070cf or greater (0.9.7l)\n"
-              "Require OPENSSL_VERSION_NUMBER 0x0090804f or greater (0.9.8d)\n\n");
+              "Require OPENSSL_VERSION_NUMBER 0x0090804f or greater (0.9.8d)\n"
+              "Require OPENSSL_VERSION_NUMBER 0x1000000f or greater (1.0.0)\n"
+              "Require OPENSSL_VERSION_NUMBER 0x1000100f or greater (1.0.1)\n"
+              "Require OPENSSL_VERSION_NUMBER 0x1000205f or greater (1.0.2e)\n\n");
        return (1);
 }
                ],
@@ -4282,15 +4287,16 @@ WARNING         Your OpenSSL crypto library may be vulnerable to        WARNING
 WARNING         one or more of the the following known security         WARNING
 WARNING         flaws:                                                  WARNING
 WARNING                                                                 WARNING
-WARNING         CAN-2002-0659, CAN-2006-4339, CVE-2006-2937 and         WARNING
-WARNING         CVE-2006-2940.                                          WARNING
+WARNING         CAN-2002-0659, CAN-2006-4339, CVE-2006-2937,            WARNING
+WARNING         CVE-2006-2940 and CVE-2015-3193.                        WARNING
 WARNING                                                                 WARNING
 WARNING         It is recommended that you upgrade to OpenSSL           WARNING
-WARNING         version 0.9.8d/0.9.7l (or greater).                     WARNING
+WARNING         version 1.0.2e/1.0.1/1.0.0/0.9.9/0.9.8d/0.9.7l          WARNING
+WARNING         (or greater).                                           WARNING
 WARNING                                                                 WARNING
 WARNING         You can disable this warning by specifying:             WARNING
 WARNING                                                                 WARNING
-WARNING               --disable-openssl-version-check                          WARNING
+WARNING               --disable-openssl-version-check                   WARNING
 WARNING                                                                 WARNING
 WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING
 WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING WARNING