package/unbound: security bump to version 1.13.0
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Sat, 12 Dec 2020 21:55:58 +0000 (22:55 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Mon, 14 Dec 2020 14:47:43 +0000 (15:47 +0100)
commit4eb320112037445b8310f0fde1cde511ed05ecb3
tree0ac1620bf9aa7966b6000de18d53c4eafc05d796
parentcad3da5f18b5ae75aff24d1ae109ddb8ec359a25
package/unbound: security bump to version 1.13.0

This version has fixes to connect for UDP sockets, slowing down
potential ICMP side channel leakage. The fix can be controlled with the
option udp-connect: yes, it is enabled by default.

Additionally CVE-2020-28935 is fixed, this solves a problem where the
pidfile is altered by a symlink, and fails if a symlink is encountered.
See https://nlnetlabs.nl/downloads/unbound/CVE-2020-28935.txt for more
information.

https://github.com/NLnetLabs/unbound/releases/tag/release-1.13.0

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/unbound/unbound.hash
package/unbound/unbound.mk