~ahasenack/ubuntu/+source/bind9:eoan-bind-merge-9.11.5.p4-4

Last commit made on 2019-05-02
Get this branch:
git clone -b eoan-bind-merge-9.11.5.p4-4 https://git.launchpad.net/~ahasenack/ubuntu/+source/bind9
Only Andreas Hasenack can upload to this branch. If you are Andreas Hasenack please log in for upload directions.

Branch merges

Branch information

Name:
eoan-bind-merge-9.11.5.p4-4
Repository:
lp:~ahasenack/ubuntu/+source/bind9

Recent commits

5de12eb... by Andreas Hasenack

update-maintainer

aa0333e... by Andreas Hasenack

reconstruct-changelog

54d5829... by Andreas Hasenack

merge-changelogs

a531bdf... by Andreas Hasenack

    - d/rules: add back EdDSA support (LP: #1825712)
      [Fixed in 1:9.11.5.P4+dfsg-4]

dd16d24... by Andreas Hasenack

    - SECURITY UPDATE: limiting simultaneous TCP clients is ineffective
      + debian/patches/CVE-2018-5743.patch: add reference counting in
        bin/named/client.c, bin/named/include/named/client.h,
        bin/named/include/named/interfacemgr.h, bin/named/interfacemgr.c,
        lib/isc/include/isc/quota.h, lib/isc/quota.c,
        lib/isc/win32/libisc.def.in.
      + debian/patches/CVE-2018-5743-atomic-fix.patch: replace atomic
        operations with isc_refcount reference counting in
        bin/named/client.c, bin/named/include/named/interfacemgr.h,
        bin/named/interfacemgr.c.
      + debian/libisc1100.symbols: added new symbols.
      + CVE-2018-5743
      [Fixed in 1:9.11.5.P4+dfsg-4]

547409b... by Andreas Hasenack

    - SECURITY UPDATE: Controls for zone transfers may not be properly
      applied to Dynamically Loadable Zones (DLZs) if the zones are writable
      + debian/patches/CVE-2019-6465.patch: handle zone transfers marked in
        the zone table as a DLZ zone bin/named/xfrout.c.
      + CVE-2019-6465
      [Fixed upstream in 9.11.5-P3]

d7fefd7... by Andreas Hasenack

    - SECURITY UPDATE: assertion failure when a trust anchor rolls over to an
      unsupported key algorithm when using managed-keys
      + debian/patches/CVE-2018-5745.patch: properly handle situations when
        the key tag cannot be computed in lib/dns/include/dst/dst.h,
        lib/dns/zone.c.
      + CVE-2018-5745
      [Fixed upstream in 9.11.5-P2]

5aab03c... by Andreas Hasenack

  * Dropped:
    - SECURITY UPDATE: memory leak via specially crafted packet
      + debian/patches/CVE-2018-5744.patch: silently drop additional keytag
        options in bin/named/client.c.
      + CVE-2018-5744
      [Fixed upstream in 9.11.5-P2]

8902c20... by Andreas Hasenack

    - d/t/simpletest: drop the internetsociety.org test as it requires
      network egress access that is not available in the Ubuntu autopkgtest
      farm.

e3febe2... by Andreas Hasenack

    - d/p/fix-shutdown-race.diff: dig/host/nslookup could crash when interrupted
      close to a query timeout (LP: #1797926)