[Pkg-dns-devel] Bug#864730: unbound: malformed packet DoS when "use-caps-for-id" enabled

Robert Edmonds edmonds at debian.org
Tue Jun 13 16:51:11 UTC 2017


Source: unbound
Tags: security

Unbound has a faulty assertion that can be triggered remotely when the
"use-caps-for-id" option is enabled (it is disabled in the default
configs shipped by upstream and Debian) when a response is received from
a nameserver. It was fixed in the upstream 1.6.3 release, and the
corresponding patch from the upstream SVN repository is attached.

-- 
Robert Edmonds
edmonds at debian.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-Fix-1280-Unbound-fails-assert-when-response-from-aut.patch
Type: text/x-diff
Size: 3956 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-dns-devel/attachments/20170613/05ed90ab/attachment.patch>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-dns-devel/attachments/20170613/05ed90ab/attachment.sig>


More information about the pkg-dns-devel mailing list