HomeFreeBSD

dns/nsd: update 4.1.10 -> 4.1.11

Description

dns/nsd: update 4.1.10 -> 4.1.11

  • Restore configurable IPV6 option. Upstream integrated fix for issue.
  • FEATURES:
  • When tcp is more than half full, use short timeout for tcp session.
  • Patch for {max,min}-{refresh,retry}-time from YAMAGUCHI Takanori.
  • Fix #790: size-limit-xfr can stop NSD from downloading infinite zone transfer data size, from Toshifumi Sakaguchi. Fixes CVE-2016-6173 JVN#63359718 JPCERT#91251865.
  • BUGFIXES:
  • Fix build without IPv6, patch from Zdenek Kaspar.
  • Fix #783: Trying to run a root server without having configured it silently gives wrong answers.
  • Fix #782: Serve DS record but parent zone has no NS record.
  • Fix nsec3 missing for nsec3 signed parent and child for DS at zonecut.

PR: 211693
Submitted by: jaap@NLnetLabs.nl (maintainer)
Security: CVE-2016-6173
Security: https://vuxml.FreeBSD.org/freebsd/7d08e608-5e95-11e6-b334-002590263bf5.html
MFH: 2016Q3

Details

Provenance
junovitchAuthored on
Parents
rP419979: Document denial of service vector via oversized AXFR, IXFR, or Dynamic DNS
Branches
Unknown
Tags
Unknown