]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
regen v9_10
authorTinderbox User <tbox@isc.org>
Wed, 31 May 2017 01:22:10 +0000 (01:22 +0000)
committerTinderbox User <tbox@isc.org>
Wed, 31 May 2017 01:22:10 +0000 (01:22 +0000)
doc/arm/Bv9ARM.ch09.html
doc/arm/notes.html

index 32f1e6efa8bba785f5c8432dbb11713f65e82aec..9568a3a8cbe95a085e7928a1080194933bc110ff 100644 (file)
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
        <p>
-         None.
+         The BIND installer on Windows used an unquoted service path,
+         which can enable privilege escalation. This flaw is disclosed
+         in CVE-2017-3141. [RT #45229]
        </p>
-      </li></ul></div>
+      </li>
+<li class="listitem">
+       <p>
+         With certain RPZ configurations, a response with TTL 0
+         could cause <span class="command"><strong>named</strong></span> to go into an infinite
+         query loop. This flaw is disclosed in CVE-2017-3140.
+         [RT #45181]
+       </p>
+      </li>
+</ul></div>
   </div>
 
   <div class="section">
index 737f3c6701fee8fb748007b9ab86ceb1acbde9cf..f92b1d1cb1dedfdb1074afb7e2d6576e611b1f24 100644 (file)
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
        <p>
-         None.
+         The BIND installer on Windows used an unquoted service path,
+         which can enable privilege escalation. This flaw is disclosed
+         in CVE-2017-3141. [RT #45229]
        </p>
-      </li></ul></div>
+      </li>
+<li class="listitem">
+       <p>
+         With certain RPZ configurations, a response with TTL 0
+         could cause <span class="command"><strong>named</strong></span> to go into an infinite
+         query loop. This flaw is disclosed in CVE-2017-3140.
+         [RT #45181]
+       </p>
+      </li>
+</ul></div>
   </div>
 
   <div class="section">