Summary: | dns/unbound: Uodate to 1.20.0 | ||||||
---|---|---|---|---|---|---|---|
Product: | Ports & Packages | Reporter: | Jaap Akkerhuis <jaap> | ||||
Component: | Individual Port(s) | Assignee: | Fernando Apesteguía <fernape> | ||||
Status: | Closed FIXED | ||||||
Severity: | Affects Many People | CC: | fernape, freebsdbugzilla, ports-secteam | ||||
Priority: | --- | Flags: | fernape:
merge-quarterly+
|
||||
Version: | Latest | ||||||
Hardware: | Any | ||||||
OS: | Any | ||||||
URL: | https://nlnetlabs.nl/news/2024/May/08/unbound-1.20.0-released/ | ||||||
Attachments: |
|
Description
Jaap Akkerhuis
2024-05-09 12:48:59 UTC
Reminder to self: add entry to VuXML Committed, Thanks! A commit in branch main references this bug: URL: https://cgit.FreeBSD.org/ports/commit/?id=a478d4b5e7ef58c06031c2e6802dc2a64bd5f4e9 commit a478d4b5e7ef58c06031c2e6802dc2a64bd5f4e9 Author: Jaap Akkerhuis <jaap@NLnetLabs.nl> AuthorDate: 2024-05-10 06:37:00 +0000 Commit: Fernando Apesteguía <fernape@FreeBSD.org> CommitDate: 2024-05-10 17:59:57 +0000 dns/unbound: Uodate to 1.20.0 ChangeLog: https://nlnetlabs.nl/news/2024/May/08/unbound-1.20.0-released/ Summary of the DNSBomb vulnerability CVE-2024-33655. The DNSBomb attack, via specially timed DNS queries and answers, can cause a Denial of Service on resolvers and spoofed targets. Unbound itself is not vulnerable for DoS, rather it can be used to take part in a pulsing DoS amplification attack. PR: 278870 Reported by: jaap@NLnetLabs.nl (maintainer) Security: CVE-2024-33655 dns/unbound/Makefile | 2 +- dns/unbound/distinfo | 6 +++--- dns/unbound/pkg-plist | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) (In reply to commit-hook from comment #3) Any idea when this commit will be in the branch (probably 2024Q2 ?) used by package build ? A commit in branch 2024Q2 references this bug: URL: https://cgit.FreeBSD.org/ports/commit/?id=3ab8e5ac0ada9e596702896dda8bb8cd44d0b2ef commit 3ab8e5ac0ada9e596702896dda8bb8cd44d0b2ef Author: Jaap Akkerhuis <jaap@NLnetLabs.nl> AuthorDate: 2024-05-10 06:37:00 +0000 Commit: Fernando Apesteguía <fernape@FreeBSD.org> CommitDate: 2024-05-30 14:00:56 +0000 dns/unbound: Uodate to 1.20.0 ChangeLog: https://nlnetlabs.nl/news/2024/May/08/unbound-1.20.0-released/ Summary of the DNSBomb vulnerability CVE-2024-33655. The DNSBomb attack, via specially timed DNS queries and answers, can cause a Denial of Service on resolvers and spoofed targets. Unbound itself is not vulnerable for DoS, rather it can be used to take part in a pulsing DoS amplification attack. PR: 278870 Reported by: jaap@NLnetLabs.nl (maintainer) Security: CVE-2024-33655 (cherry picked from commit a478d4b5e7ef58c06031c2e6802dc2a64bd5f4e9) dns/unbound/Makefile | 2 +- dns/unbound/distinfo | 6 +++--- dns/unbound/pkg-plist | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) (In reply to Laurent Frigault from comment #4) Done. Thanks for the remainder! |