sthen fcb33424c5 SECURITY update to Unbound 1.4.14, incorporating various diffs from Brad,
jakob@ and myself. See http://www.unbound.net/downloads/CVE-2011-4528.txt
for more details, summary from the above is below:

--
Unbound crashes when confronted with a non-standard response from a
server for a domain. This domain produces duplicate RRs from a certain
type and is DNSSEC signed.Unbound also crashes when confronted with a
query that eventually, and under specific circumstances, resolves to a
domain that misses expected NSEC3 records.

These two problems were discovered within 24 hours, hence a combined
vulnerability disclosure.

By constructing the non standard responses an attacker can use these
vulnerabilities for a DOS attack.

To our knowledge 'denial of service' is the only type of exploit possible.
--
2011-12-20 10:49:19 +00:00
2011-12-19 12:44:37 +00:00
2011-12-15 22:26:59 +00:00
2011-12-05 16:07:22 +00:00
2011-12-13 17:42:14 +00:00
2011-11-30 18:57:49 +00:00
2011-12-20 06:56:12 +00:00
2011-12-16 20:15:58 +00:00
2011-12-12 12:23:14 +00:00
2011-12-02 14:36:13 +00:00
2011-12-19 22:37:49 +00:00
2011-12-05 22:36:54 +00:00
2011-12-03 20:30:09 +00:00
2011-12-12 11:53:07 +00:00
2011-09-21 07:49:15 +00:00
2011-10-12 20:13:33 +00:00
2011-12-20 09:32:44 +00:00
2011-09-16 11:13:37 +00:00
2011-12-16 14:50:09 +00:00
2011-12-19 22:18:59 +00:00
2011-12-19 23:08:52 +00:00
2011-12-09 17:19:55 +00:00
2011-11-15 18:33:16 +00:00

Documentation for the ports tree: ports(7), packages(7), mirroring-ports(7),
library-specs(7), bsd.port.mk(5), bsd.port.arch.mk(5), port-modules(5).

dpb(1) (manpage under ${PORTSDIR}/man) for bulk builds.

See also the OpenBSD Porter's Handbook http://www.openbsd.org/faq/ports/

$OpenBSD: README,v 1.20 2011/11/15 18:33:16 espie Exp $
Description
Public git conversion mirror of OpenBSD's official cvs ports repository. Pull requests not accepted - send diffs to the ports@ mailing list.
Readme 554 MiB
Languages
Makefile 61%
PHP 18.9%
Perl 6.5%
C 4.6%
HTML 2.3%
Other 6.4%