NSD 4.2.2rc2 pre-release
Wouter Wijngaards <[email protected]>
| Newsgroups | gmane.network.dns.nsd.general |
|---|---|
| Message-ID | <[email protected]> |
Hi, NSD 4.2.2rc2 maintainer's pre-release is available: https://nlnetlabs.nl/downloads/nsd/nsd-4.2.2rc2.tar.gz sha256 22b59d6e749322e7fc83b3fda12c5bf8c6a1a7b83f9dda0bd278f25d7dd2b02d pgp https://nlnetlabs.nl/downloads/nsd/nsd-4.2.2rc2.tar.gz This RC2 is made because there is a last-minute bugfix that fixes a segfault, and it is nice to fold this into the release in progress. Additional changes: - Fix #33: Fix segfault in service of remaining streams on exit. - Fix error message for out of zone data to have more information. Best regards, Wouter On 8/6/19 11:55 AM, Wouter Wijngaards wrote: > Hi, > > NSD 4.2.2rc1 maintainer's pre-release is available: > https://nlnetlabs.nl/downloads/nsd/nsd-4.2.2rc1.tar.gz > sha256 7edc758b8700d53a10f613730a77702a0ab345259f24508584fe2f5ff8b37614 > pgp https://nlnetlabs.nl/downloads/nsd/nsd-4.2.2rc1.tar.gz.asc > > > This release fixes a number of, smaller, bugs. Several failures are > fixed in the zone file parser, reported by fuzzing from Frederic Cambus. > > NSD now warns when a zonefile is parsed with SSHFP records in it with > wrong lengths. The record itself is still managed normally, eg. does > not cause the zone to stop loading. They are output into log, but the > warnings are easily visible from the commandline using nsd-checkzone. > > > 4.2.2 > ================ > BUG FIXES: > - Fix #20: CVE-2019-13207 Stack-based Buffer Overflow in the > dname_concatenate() function. Reported by Frederic Cambus. > It causes the zone parser to crash on a malformed zone file, > with assertions enabled, an assertion catches it. > - Fix #19: Out-of-bounds read caused by improper validation of > array index. Reported by Frederic Cambus. The zone parser > fails on type SIG because of mismatched definition with RRSIG. > - PR #23: Fix typo in nsd.conf man-page. > - Fix that NSD warns for wrong length of the hash in SSHFP records. > - Fix #25: NSD doesn't refresh zones after extended downtime, > it refreshes the old zones. > - Set no renegotiation on the SSL context to stop client > session renegotiation. > - Fix #29: SSHFP check NULL pointer dereference. > - Fix #30: SSHFP check failure due to missing domain name. > - Fix to timeval_add in minievent for remaining second in microseconds. > - PR #31: nsd-control: Add missing stdio header. > - PR #32: tsig: Fix compilation without HAVE_SSL. > - Cleanup tls context on xfrd exit. > > > Best regards, Wouter > > > _______________________________________________ > maintainers mailing list > [email protected] > https://nlnetlabs.nl/mailman/listinfo/maintainers > _______________________________________________ nsd-users mailing list [email protected] https://open.nlnetlabs.nl/mailman/listinfo/nsd-users
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEE7fqj8spObrBWga+On28cLX4EX40FAl1SuS4ACgkQn28cLX4E X40BzBAAlPyAnRw+Ufl/NyV8DWrLUMXDsW+zg94tGvtOKaVk3tJY567Tc3Z//bPw sbfCXxRV4qrzc/dkw3hCxa/MZ7FlN2g/0cO0FgcGnbqgnuWzVyOima0t/iwbPhbz /gkZlaMnCASHGTxARdolyVvYcu22ZLNygYAZaFvjKd6XhW+cPdReUgROSibbEYHM 0BvKcyEKHtkab0817gTaiGTvwyTzE4PddO2gC04jNNueX6zPo/GkoCMaqe9qzAyL MvvUdQyBFccMF6i2C90goIVnrXfxqbaxMRDvMNELguhyjlFpch84h/ex8LNdaCH6 V0+PlUmGH3QwtZiX/hTpafL/xkJ1RxT47TaVYEPWDP/DR4aHOoilqgZiHj7LbM3Z vr58lAkSOBVgWbvUnlkDgZ2IQcsnEsEnKPyocQ9jchwNjUoKLIsTzcI2WnQAsNI+ A0Gf2MEFq8gWwk8OxxVOY58645VSSLELo7ic9/dEGX2/wvplAkkWpfLMLsDlv7qW veFgIU2APEWou4yoDDDQlyieymw2bax/iI1ZDnWMs2na8ojVQ0i2jaQ/plR44vcX N41lOfO2wXMjpu1+BWyviFkE+6mkvxBHdkYS/+HeOuO+gktjdN1bIQkRRVoGhPFP wb/Zpb3i/6v5EwvY2kBer+ntemCfa4oIv94TV7HD8nZ5hAgLnRs= =vxfZ -----END PGP SIGNATURE-----