Go to file
Peter Korsgaard f693ed7e42 package/bind: security bump to version 9.11.5-P4
Fixes the following security issues:

- named could crash during recursive processing of DNAME records when
  deny-answer-aliases was in use.  This flaw is disclosed in CVE-2018-5740.
  [GL #387]

- When recursion is enabled but the allow-recursion and allow-query-cache
  ACLs are not specified, they should be limited to local networks, but they
  were inadvertently set to match the default allow-query, thus allowing
  remote queries.  This flaw is disclosed in CVE-2018-5738.  [GL #309]

- Code change #4964, intended to prevent double signatures when deleting an
  inactive zone DNSKEY in some situations, introduced a new problem during
  zone processing in which some delegation glue RRsets are incorrectly
  identified as needing RRSIGs, which are then created for them using the
  current active ZSK for the zone.  In some, but not all cases, the
  newly-signed RRsets are added to the zone's NSEC/NSEC3 chain, but
  incompletely -- this can result in a broken chain, affecting validation of
  proof of nonexistence for records in the zone.  [GL #771]

- named could crash if it managed a DNSSEC security root with managed-keys
  and the authoritative zone rolled the key to an algorithm not supported by
  BIND 9.  This flaw is disclosed in CVE-2018-5745.  [GL #780]

- named leaked memory when processing a request with multiple Key Tag EDNS
  options present.  ISC would like to thank Toshifumi Sakaguchi for bringing
  this to our attention.  This flaw is disclosed in CVE-2018-5744.  [GL
  #772]

- Zone transfer controls for writable DLZ zones were not effective as the
  allowzonexfr method was not being called for such zones.  This flaw is
  disclosed in CVE-2019-6465.  [GL #790]

For more details, see the release notes:

http://ftp.isc.org/isc/bind9/9.11.5-P4/RELEASE-NOTES-bind-9.11.5-P4.html

Change the upstream URL to HTTPS as the webserver uses HSTS:

>>> bind 9.11.5-P4 Downloading
URL transformed to HTTPS due to an HSTS policy

Update the hash of the license file to account for a change of copyright
year:

-Copyright (C) 1996-2018  Internet Systems Consortium, Inc. ("ISC")
+Copyright (C) 1996-2019  Internet Systems Consortium, Inc. ("ISC")

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 12f644e2c5)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2019-02-23 19:36:26 +01:00
arch arch/arm: restrict more armv8a cores to aarch64 2019-01-18 15:54:19 +01:00
board qemu/aarch64-virt: Emulate cortex-a53 in qemu to match Buildroot config 2019-01-29 23:02:39 +01:00
boot boot/barebox: change download site to https 2019-01-24 16:51:45 +01:00
configs qemu/aarch64-virt: Emulate cortex-a53 in qemu to match Buildroot config 2019-01-29 23:02:39 +01:00
docs Makefile, manual, website: Bump copyright year 2019-01-24 12:26:30 +01:00
fs fs/tar: add support for xattrs (thus capabilties) 2018-11-26 17:24:45 +01:00
linux linux: don't check hashes for user-supplied patches 2019-02-22 12:45:42 +01:00
package package/bind: security bump to version 9.11.5-P4 2019-02-23 19:36:26 +01:00
support support/scripts/setlocalversion: ignore user settings for Mercurial 2019-02-18 17:12:55 +01:00
system skeleton: PAGER without blank and unset at end of for loop 2018-06-17 17:19:52 +02:00
toolchain toolchain/buildroot: fix default of C library choice 2018-05-28 16:12:14 +02:00
utils utils/scanpypi: protect against zip-slip vulnerability in zip/tar handling 2019-02-21 13:54:04 +01:00
.defconfig arch: remove support for sh64 2016-09-08 22:15:15 +02:00
.flake8 .flake8: add config file for Python code style 2017-10-06 19:05:18 +02:00
.gitignore
.gitlab-ci.yml .gitlab-ci.yml: do runtime tests only on explicit trigger 2018-10-26 21:38:10 +02:00
.gitlab-ci.yml.in .gitlab-ci.yml: do runtime tests only on explicit trigger 2018-10-26 21:38:10 +02:00
CHANGES Update for 2018.02.10 2019-01-31 17:37:58 +01:00
Config.in Config.in: security hardening: disable FORTIFY_SOURCE for gcc < 6 2018-11-25 21:48:40 +01:00
Config.in.legacy package/transmission: remove BR2_PACKAGE_TRANSMISSION_REMOTE 2018-06-11 22:57:19 +02:00
COPYING COPYING: add exception about patch licensing 2016-02-26 19:50:13 +01:00
DEVELOPERS DEVELOPERS: update email address for Gary Bisson 2019-02-22 13:29:35 +01:00
Makefile Makefile: unexport 'PLATFORM' and 'OS' environment variables 2019-02-18 17:15:27 +01:00
Makefile.legacy Remove BR2_DEPRECATED 2016-10-15 23:14:45 +02:00
README README: add reference to submitting-patches 2016-02-01 19:16:08 +01:00

Buildroot is a simple, efficient and easy-to-use tool to generate embedded
Linux systems through cross-compilation.

The documentation can be found in docs/manual. You can generate a text
document with 'make manual-text' and read output/docs/manual/manual.text.
Online documentation can be found at http://buildroot.org/docs.html

To build and use the buildroot stuff, do the following:

1) run 'make menuconfig'
2) select the target architecture and the packages you wish to compile
3) run 'make'
4) wait while it compiles
5) find the kernel, bootloader, root filesystem, etc. in output/images

You do not need to be root to build or run buildroot.  Have fun!

Buildroot comes with a basic configuration for a number of boards. Run
'make list-defconfigs' to view the list of provided configurations.

Please feed suggestions, bug reports, insults, and bribes back to the
buildroot mailing list: buildroot@buildroot.org
You can also find us on #buildroot on Freenode IRC.

If you would like to contribute patches, please read
https://buildroot.org/manual.html#submitting-patches