Description (from 1.10.0 release notes): >- Fix out-of-bounds null-byte write in sldns_bget_token_par while > parsing type WKS, reported by Luis Merino from X41 D-Sec. Patch: https://github.com/NLnetLabs/unbound/commit/05a5dc2d0d7d1c9054af48913079abebff06a5a1 A few double frees were also fixed in this release.
@maintainer(s), please advise if ready for stabilisation, or call yourself.
@maintainer(s): ping
x86 stable
amd64 stable
arm stable
ppc stable
ppc64 stable. Maintainer(s), please cleanup. Security, please vote.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e72c01fbb1df2a7e21f3f6f7eb5ac69b11ee2c5e commit e72c01fbb1df2a7e21f3f6f7eb5ac69b11ee2c5e Author: Thomas Deutschmann <whissi@gentoo.org> AuthorDate: 2020-04-20 22:26:23 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2020-04-20 23:59:33 +0000 net-dns/unbound: security cleanup Bug: https://bugs.gentoo.org/715222 Package-Manager: Portage-2.3.99, Repoman-2.3.22 Signed-off-by: Thomas Deutschmann <whissi@gentoo.org> net-dns/unbound/Manifest | 1 - net-dns/unbound/unbound-1.9.6.ebuild | 183 ----------------------------------- 2 files changed, 184 deletions(-)
GLSA Vote: No Repository is clean, all done!