You are here
Home > Preporuke > Ranjivost programskog paketa unbound

Ranjivost programskog paketa unbound

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2014-16647
2014-12-12 02:49:56
——————————————————————————–

Name : unbound
Product : Fedora 21
Version : 1.5.1
Release : 2.fc21
URL : http://www.nlnetlabs.nl/unbound/
Summary : Validating, recursive, and caching DNS(SEC) resolver
Description :
Unbound is a validating, recursive, and caching DNS(SEC) resolver.

The C implementation of Unbound is developed and maintained by NLnet
Labs. It is based on ideas and algorithms taken from a java prototype
developed by Verisign labs, Nominet, Kirei and ep.net.

Unbound is designed as a set of modular components, so that also
DNSSEC (secure DNS) validation and stub-resolvers (that do not run
as a server, but are linked into an application) are easily possible.

——————————————————————————–
Update Information:

Security fix for CVE-2014-8602
new release
fix build on aarch64
new upstream version
——————————————————————————–
ChangeLog:

* Tue Dec 9 2014 Paul Wouters <pwouters@redhat.com> – 1.5.1-2
– Change systemd-units to systemd
– Use _tmpfilesdir macro, don’t mark tmpfiles as config
* Tue Dec 9 2014 Paul Wouters <pwouters@redhat.com> – 1.5.1-1
– Update to 1.5.1 for CVE-2014-8602 (rhbz#1172066)
– Removed unbound-aarch64.patch which was merged upstream
– Don’t require autotools for non snapshots or run autoreconf
* Fri Nov 28 2014 Tomas Hozza <thozza@redhat.com> – 1.5.1-0.1.rc1
– update to 1.5.1rc1
* Fri Nov 28 2014 Marcin Juszkiewicz <mjuszkiewicz@redhat.com> – 1.5.0-3
– fix build on aarch64
* Wed Nov 26 2014 Tomas Hozza <thozza@redhat.com> – 1.5.0-2
– Fix race condition in arc4random (#1166878)
* Wed Nov 19 2014 Tomas Hozza <thozza@redhat.com> – 1.5.0-1
– update to 1.5.0
* Wed Sep 24 2014 Pavel Šimerda <psimerda@redhat.com> – 1.4.22-6
– Resolves: #1115489 – build with python 3.x for fedora >= 22
——————————————————————————–
References:

[ 1 ] Bug #1172065 – CVE-2014-8602 unbound: specially crafted request can lead to denial of service
https://bugzilla.redhat.com/show_bug.cgi?id=1172065
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update unbound’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2014-16671
2014-12-12 02:51:01
——————————————————————————–

Name : unbound
Product : Fedora 20
Version : 1.5.1
Release : 2.fc20
URL : http://www.nlnetlabs.nl/unbound/
Summary : Validating, recursive, and caching DNS(SEC) resolver
Description :
Unbound is a validating, recursive, and caching DNS(SEC) resolver.

The C implementation of Unbound is developed and maintained by NLnet
Labs. It is based on ideas and algorithms taken from a java prototype
developed by Verisign labs, Nominet, Kirei and ep.net.

Unbound is designed as a set of modular components, so that also
DNSSEC (secure DNS) validation and stub-resolvers (that do not run
as a server, but are linked into an application) are easily possible.

——————————————————————————–
Update Information:

Security fix for CVE-2014-8602
——————————————————————————–
ChangeLog:

* Tue Dec 9 2014 Paul Wouters <pwouters@redhat.com> – 1.5.1-2
– Change systemd-units to systemd
– Use _tmpfilesdir macro, don’t mark tmpfiles as config
* Tue Dec 9 2014 Paul Wouters <pwouters@redhat.com> – 1.5.1-1
– Update to 1.5.1 for CVE-2014-8602 (rhbz#1172066)
– Removed unbound-aarch64.patch which was merged upstream
– Don’t require autotools for non snapshots or run autoreconf
* Fri Nov 28 2014 Tomas Hozza <thozza@redhat.com> – 1.5.1-0.1.rc1
– update to 1.5.1rc1
* Fri Nov 28 2014 Marcin Juszkiewicz <mjuszkiewicz@redhat.com> – 1.5.0-3
– fix build on aarch64
* Wed Nov 26 2014 Tomas Hozza <thozza@redhat.com> – 1.5.0-2
– Fix race condition in arc4random (#1166878)
* Wed Nov 19 2014 Tomas Hozza <thozza@redhat.com> – 1.5.0-1
– update to 1.5.0
* Wed Sep 24 2014 Pavel Šimerda <psimerda@redhat.com> – 1.4.22-6
– Resolves: #1115489 – build with python 3.x for fedora >= 22
* Thu Aug 21 2014 Kevin Fenzi <kevin@scrye.com> – 1.4.22-5
– Rebuild for rpm bug 1131960
* Mon Aug 18 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 1.4.22-4
– Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
* Sun Jun 8 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 1.4.22-3
– Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Thu May 1 2014 Paul Wouters <pwouters@redhat.com> – 1.4.22-2
– Added flushcache patch (SVN commit 3125)
* Thu Mar 13 2014 Paul Wouters <pwouters@redhat.com> – 1.4.22-1
– Updated to 1.4.22
– No longer requires the ldns library
* Thu Jan 16 2014 Tomas Hozza <thozza@redhat.com> – 1.4.21-3
– Fix segfault on adding insecure forward zone when using only iterator (#1054192)
* Mon Oct 21 2013 Tomas Hozza <thozza@redhat.com> – 1.4.21-2
– run test suite during the build
——————————————————————————–
References:

[ 1 ] Bug #1172065 – CVE-2014-8602 unbound: specially crafted request can lead to denial of service
https://bugzilla.redhat.com/show_bug.cgi?id=1172065
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update unbound’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
7e

AutorTomislav Protega
Cert idNCERT-REF-2014-12-0010-ADV
CveCVE-2014-8602
ID izvornikaFEDORA-2014-16647 FEDORA-2014-16671
Proizvodunbound
Izvorhttp://www.redhat.com
Top
More in Preporuke
Ranjivost programskog paketa firebird

Otkrivena je ranjivost u paketu firebird za Fedoru uzrokovana pokušajem pristupanja memorijskoj lokaciji kojoj nije dopušten pristup prilikom obrade posebno...

Close