bind: security bump to version 9.9.6-P1
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Tue, 9 Dec 2014 11:34:51 +0000 (08:34 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 9 Dec 2014 11:40:32 +0000 (12:40 +0100)
Fixes CVE-2014-8500 - A flaw in delegation handling could be exploited
to put named into an infinite loop, in which each lookup of a name
server triggered additional lookups of more name servers.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/bind/bind.hash
package/bind/bind.mk

index 9cf98018f500823e75a2d84258e2b444412ea8ed..d715e541fc188a12c8c57ca8af9168f70f0b74c1 100644 (file)
@@ -1,2 +1,2 @@
-# Verified from ftp://ftp.isc.org/isc/bind9/9.9.6/bind-9.9.6.tar.gz.*.asc
-sha256 6b9432644a3bfa41695354543bd9e2547104e35f3c7354a416a030a4cdd1c514        bind-9.9.6.tar.gz
+# Verified from ftp://ftp.isc.org/isc/bind9/9.9.6-P1/bind-9.9.6-P1.tar.gz.sha256.asc
+sha256 dfedcb2b414d2803accd1a9c21d183178a288f40a2486af5ec0d3369a8cb8526        bind-9.9.6-P1.tar.gz
index 06c66017aa9f82d36090ce0aa8666e8f4d81ea3a..6c17b13d0165e1829a39c621d535ef76dd42f1ca 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-BIND_VERSION = 9.9.6
+BIND_VERSION = 9.9.6-P1
 BIND_SITE = ftp://ftp.isc.org/isc/bind9/$(BIND_VERSION)
 BIND_INSTALL_STAGING = YES
 BIND_CONFIG_SCRIPTS = bind9-config isc-config.sh