bind: security bump to version 9.9.7-P3
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Fri, 4 Sep 2015 12:39:52 +0000 (09:39 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Fri, 4 Sep 2015 14:07:37 +0000 (16:07 +0200)
Fixes:
CVE-2015-5722 - denial-of-service vector which can be exploited remotely
against a BIND server that is performing validation on DNSSEC-signed
records.
CVE-2015-5986 - denial-of-service vector which can be used against a
BIND server that is performing recursion and (under limited conditions)
an authoritative-only nameserver.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Reviewed-by: Vicente Olivert Riera <Vincent.Riera@imgtec.com>
Tested-by: Vicente Olivert Riera <Vincent.Riera@imgtec.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/bind/bind.hash
package/bind/bind.mk

index 6bc2d1b645bd9f217d6681a1f0a3a7b5de10eedd..4c9fc406b09a8cd3741323aafc81b86c10b9bd1c 100644 (file)
@@ -1,2 +1,2 @@
-# Verified from ftp://ftp.isc.org/isc/bind9/9.9.7-P2/bind-9.9.7-P2.tar.gz.sha256.asc
-sha256 f5f433567e5f68d61460d86f691471259a49b6d10d7422acbd88b7fdb038b518        bind-9.9.7-P2.tar.gz
+# Verified from ftp://ftp.isc.org/isc/bind9/9.9.7-P3/bind-9.9.7-P3.tar.gz.sha256.asc
+sha256 cb737dce18350890f350dd7d3bc836c62ea440103dfde184c09bc18cfad8a844        bind-9.9.7-P3.tar.gz
index 6201991302576b1d1786748cad6f4a98b0c0b833..95051d1e07e83a5c047451bb5f018df473837634 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-BIND_VERSION = 9.9.7-P2
+BIND_VERSION = 9.9.7-P3
 BIND_SITE = ftp://ftp.isc.org/isc/bind9/$(BIND_VERSION)
 BIND_INSTALL_STAGING = YES
 BIND_CONFIG_SCRIPTS = bind9-config isc-config.sh