Commit Graph

10 Commits

Author SHA1 Message Date
sthen
73f342959a update to unbound 1.4.18; includes a crash fix (assertion failure).
- rc.d script now generates the unbound-control keys if they don't exist
and the sample config file is patched to enable this, various rc.d/unbound
actions depend on this, pointed out/ok aja@
2012-08-04 20:43:54 +00:00
sthen
fcb33424c5 SECURITY update to Unbound 1.4.14, incorporating various diffs from Brad,
jakob@ and myself. See http://www.unbound.net/downloads/CVE-2011-4528.txt
for more details, summary from the above is below:

--
Unbound crashes when confronted with a non-standard response from a
server for a domain. This domain produces duplicate RRs from a certain
type and is DNSSEC signed.Unbound also crashes when confronted with a
query that eventually, and under specific circumstances, resolves to a
domain that misses expected NSEC3 records.

These two problems were discovered within 24 hours, hence a combined
vulnerability disclosure.

By constructing the non standard responses an attacker can use these
vulnerabilities for a DOS attack.

To our knowledge 'denial of service' is the only type of exploit possible.
--
2011-12-20 10:49:19 +00:00
jakob
d978636a3c upgrade to Unbound 1.4.8; mostly from sthen@ 2011-03-06 09:24:41 +00:00
jakob
a23d402776 update to Unbound v1.4.6 2010-08-22 09:03:11 +00:00
jakob
b023b4d16a update unbound to 1.4.1 2009-12-18 07:49:22 +00:00
jakob
d4fc627dcd update to unbound v1.4.0 2009-11-27 18:34:25 +00:00
jakob
42bc4a94c3 upgrade to Unbound 1.3.0 2009-06-15 19:03:23 +00:00
jakob
9590ff9609 upgrade to unbound v1.2.0; from brad 2009-01-14 17:44:51 +00:00
jakob
dc8544a725 upgrade to unbound 1.0.2 2008-08-20 08:25:41 +00:00
jakob
2d9513a060 unbound 1.0.1; bugfix release 2008-07-16 20:34:10 +00:00