From 3fa6d28ea316d9c3a39fbc2deffceccdc7f7670d Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Wed, 15 Jul 2015 08:01:11 +1000 Subject: [PATCH] add CVE-2015-5477 --- README | 5 +++++ doc/arm/notes.xml | 14 ++++++++++++-- 2 files changed, 17 insertions(+), 2 deletions(-) diff --git a/README b/README index 21817d32e8..d3df48d313 100644 --- a/README +++ b/README @@ -51,6 +51,11 @@ BIND 9 For up-to-date release notes and errata, see http://www.isc.org/software/bind9/releasenotes +BIND 9.9.8 + + BIND 9.9.8 is a maintenance release and addresses bugs + found in BIND 9.9.7 and earlier, as well as the security + flaws described in CVE-2015-4620 and CVE-2015-5477. BIND 9.9.7 diff --git a/doc/arm/notes.xml b/doc/arm/notes.xml index 5b66d1bc96..5eaa5053e0 100644 --- a/doc/arm/notes.xml +++ b/doc/arm/notes.xml @@ -38,6 +38,16 @@ Security Fixes + + + A specially crafted query could trigger an assertion failure + in message.c. + + + This flaw was discovered by Jonathan Foote, and is disclosed + in CVE-2015-5477. [RT #39795] + + On servers configured to perform DNSSEC validation, an @@ -70,7 +80,7 @@ them in the build. - + limits the number of simultaneous queries that can be sent to any single @@ -81,7 +91,7 @@ option. - + limits the number of simultaneous queries that can be sent for names within a