openbsd-ports/net/isc-bind
sthen 115e360822 security update to isc-bind 9.11.5-P4
CVE-2018-5744: A specially crafted packet can cause named to leak memory
...
A failure to free memory can occur when processing messages
having a specific combination of EDNS options.

By exploiting this condition, an attacker can potentially cause
named's memory use to grow without bounds until all memory
available to the process is exhausted. Typically a server process
is limited as to the amount of memory it can use but if the named
process is not limited by the operating system all free memory
on the server could be exhausted.
...

CVE-2018-5745: An assertion failure can occur if a trust anchor
rolls over to an unsupported key algorithm when using managed-keys

(there is also CVE-2019-6465 but we don't build dlz)
2019-02-21 23:35:34 +00:00
..
files
patches drop back to isc-bind 9.11.x pending investigation into how to fix the 2018-12-02 13:25:44 +00:00
pkg drop back to isc-bind 9.11.x pending investigation into how to fix the 2018-12-02 13:25:44 +00:00
distinfo security update to isc-bind 9.11.5-P4 2019-02-21 23:35:34 +00:00
Makefile security update to isc-bind 9.11.5-P4 2019-02-21 23:35:34 +00:00