From 94b2bea8ff6761ac89f591c1323bd29eb3e6e308 Mon Sep 17 00:00:00 2001 From: Petr Vorel Date: Wed, 15 Sep 2021 21:14:12 +0200 Subject: [PATCH] package/bind: security bump version to 9.11.35 Named failed to check the opcode of responses when performing zone refreshes, stub zone updates, and UPDATE forwarding. This could lead to an assertion failure under certain conditions and has been addressed by rejecting responses whose opcode does not match the expected value. [GL #2762] For details, see the release notes: https://downloads.isc.org/isc/bind9/9.11.35/RELEASE-NOTES-bind-9.11.35.html Signed-off-by: Petr Vorel Signed-off-by: Yann E. MORIN (cherry picked from commit 6977ee6e0ecf9cc9b24e5f41f9598f22fd0fcaf3) Signed-off-by: Peter Korsgaard --- package/bind/bind.hash | 6 +++--- package/bind/bind.mk | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/package/bind/bind.hash b/package/bind/bind.hash index 9311d82d6d..12b80149c5 100644 --- a/package/bind/bind.hash +++ b/package/bind/bind.hash @@ -1,4 +1,4 @@ -# Verified from https://ftp.isc.org/isc/bind9/9.11.31/bind-9.11.31.tar.gz.asc -# with key 2455774D42FDFE6B9C383EB8FE1002BC5970811F -sha256 f5f24457f42b2e86870d887596e47500e4d40521a098dcb96f3a06f18adfa36a bind-9.11.31.tar.gz +# Verified from https://ftp.isc.org/isc/bind9/9.11.35/bind-9.11.35.tar.gz.asc +# with key E9AB6E79233C0416E8993F450C03AFA90A5967C4 +sha256 1c882705827b6aafa45d917ae3b20eccccc8d5df3c4477df44b04382e6c47562 bind-9.11.35.tar.gz sha256 cad49daa42654bc241762cd998630168a2542c8fd6fad3881e2eac1510bb6fcd COPYRIGHT diff --git a/package/bind/bind.mk b/package/bind/bind.mk index a5c246a54a..0d95da209c 100644 --- a/package/bind/bind.mk +++ b/package/bind/bind.mk @@ -4,7 +4,7 @@ # ################################################################################ -BIND_VERSION = 9.11.31 +BIND_VERSION = 9.11.35 BIND_SITE = https://ftp.isc.org/isc/bind9/$(BIND_VERSION) # bind does not support parallel builds. BIND_MAKE = $(MAKE1)