package/bind: security bump to version 9.11.6-P1
authorPeter Korsgaard <peter@korsgaard.com>
Fri, 26 Apr 2019 11:32:56 +0000 (13:32 +0200)
committerPeter Korsgaard <peter@korsgaard.com>
Fri, 26 Apr 2019 14:15:37 +0000 (16:15 +0200)
commitfc8ace0938a0bcf2e9fa628a88853252eabc991d
tree8315466ae6fefc063c43bf848328ac24499da008
parentb7650ae940ff8f79c78366793b8286ed0e580b6e
package/bind: security bump to version 9.11.6-P1

Fixes the following security issues:

 - CVE-2018-5743: Limiting simultaneous TCP clients is ineffective
   https://kb.isc.org/docs/cve-2018-5743

 - CVE-2019-6467: An error in the nxdomain redirect feature can cause
   BIND to exit with an INSIST assertion failure in query.c
   https://kb.isc.org/docs/cve-2019-6467

 - CVE-2019-6468: BIND Supported Preview Edition can exit with an
   assertion failure if nxdomain-redirect is used
   https://kb.isc.org/docs/cve-2019-6468

Add an upstream patch to fix building on architectures where bind does not
implement isc_atomic_*.

Upstream moved to a 2019 signing key, so update comment in .hash file.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/bind/0002-Replace-atomic-operations-in-bin-named-client.c-with.patch [new file with mode: 0644]
package/bind/bind.hash
package/bind/bind.mk