-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 23 Jul 2024 15:15:18 +0200 Source: bind9 Binary: bind9 bind9-dbgsym bind9-dev bind9-dnsutils bind9-dnsutils-dbgsym bind9-host bind9-host-dbgsym bind9-libs bind9-libs-dbgsym bind9-utils bind9-utils-dbgsym Architecture: amd64 Version: 1:9.16.50-1~deb11u1 Distribution: bullseye-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Ondřej Surý Description: bind9 - Internet Domain Name Server bind9-dev - Static Libraries and Headers used by BIND 9 bind9-dnsutils - Clients provided with BIND 9 bind9-host - DNS Lookup Utility bind9-libs - Shared Libraries used by BIND 9 bind9-utils - Utilities for BIND 9 Changes: bind9 (1:9.16.50-1~deb11u1) bullseye-security; urgency=high . * Backported from BIND 9.18.28 + CVE-2024-1737: It is possible to craft excessively large resource records sets, which have the effect of slowing down database processing. This has been addressed by adding a fixed limit to the number of records that can be stored per name and type in a cache or zone database. + CVE-2024-1737: It is possible to craft excessively large numbers of resource record types for a given owner name, which has the effect of slowing down database processing. This has been addressed by adding a fixed limit to the number of records that can be stored per name and type in a cache or zone database. + CVE-2024-1975: Validating DNS messages signed using the SIG(0) protocol could cause excessive CPU load, leading to a denial-of-service condition. Support for SIG(0) message validation was removed from this version. + CVE-2024-4076: Due to a logic error, lookups that triggered serving stale data and required lookups in local authoritative zone data could have resulted in an assertion failure. Checksums-Sha1: 9fa419bab648853b07ad30cb72cc98c2966ec870 517620 bind9-dbgsym_9.16.50-1~deb11u1_amd64.deb 680f52aaaa29baa08e872803e6638dfaff43b269 1789692 bind9-dev_9.16.50-1~deb11u1_amd64.deb f6bab17d951e0e4c2529230eff98ee237f58c0e3 287444 bind9-dnsutils-dbgsym_9.16.50-1~deb11u1_amd64.deb 59878c9f84e969a9151307e3cdeee8c32dc92950 407628 bind9-dnsutils_9.16.50-1~deb11u1_amd64.deb 09f103c0a6e3cc9e28c4d50a6693f861d66fa871 81696 bind9-host-dbgsym_9.16.50-1~deb11u1_amd64.deb c27929e3cb1900879aa4d446c9c9620c07763d31 311908 bind9-host_9.16.50-1~deb11u1_amd64.deb 966fb1a74914b37480bf66101cb7f162e8087509 3446904 bind9-libs-dbgsym_9.16.50-1~deb11u1_amd64.deb 4943c9268156ec19b3c783ae63e18f0b603e2d8d 1430404 bind9-libs_9.16.50-1~deb11u1_amd64.deb b7b9fa2b90b5686b6e0a5e98a3394d9cf132ba31 265412 bind9-utils-dbgsym_9.16.50-1~deb11u1_amd64.deb 3b2893c642009e7666688a40cb4eec028eb9b480 439084 bind9-utils_9.16.50-1~deb11u1_amd64.deb 1c5cdd40eae765de9b0bc6cd456a2402e1d082a9 10954 bind9_9.16.50-1~deb11u1_amd64-buildd.buildinfo 2b21995d8172b4b5dd5bee62e1a56e9597854981 499896 bind9_9.16.50-1~deb11u1_amd64.deb Checksums-Sha256: 6b66b8d8e0167637dafab9f5bdf2746e36a4a21efc2f1d6918ad20b7e5610af3 517620 bind9-dbgsym_9.16.50-1~deb11u1_amd64.deb ac3bd89cbd4207f73aa54f92e96ff9f708060b74aaeb05e2ac00db28d6f6183a 1789692 bind9-dev_9.16.50-1~deb11u1_amd64.deb b8260302acfbd982821279964c3ddb3708ba02d6b0827fea62e7d3df74f1f4d0 287444 bind9-dnsutils-dbgsym_9.16.50-1~deb11u1_amd64.deb 7f0ea3259028ceeddb90caf08d9443ee3f514a57192a70afa516267df380f584 407628 bind9-dnsutils_9.16.50-1~deb11u1_amd64.deb 48947e19740f0624d20d38761c577d66538ff77cc5efae7e7220e47dd3ebf4c7 81696 bind9-host-dbgsym_9.16.50-1~deb11u1_amd64.deb 21b4115e4777a14f91c90840ac934f2612fa2705e29147ae49211a9377cb5cbb 311908 bind9-host_9.16.50-1~deb11u1_amd64.deb 49164f4890528048038e9d64380ebd5fa92f24960b19ea1998f0837384aaa248 3446904 bind9-libs-dbgsym_9.16.50-1~deb11u1_amd64.deb 766f072456b3cb2a2e73576fca2116ba5527a5afc7a801fd57737ff37faccc38 1430404 bind9-libs_9.16.50-1~deb11u1_amd64.deb e27515097899852e4f1a54d418298962037d62e2cb2ff534eef22bac43e90562 265412 bind9-utils-dbgsym_9.16.50-1~deb11u1_amd64.deb c42fbf9d4b5acd8d41541c3a7bd77086eef6386766d4cf0cb4ce3ec0994de9f8 439084 bind9-utils_9.16.50-1~deb11u1_amd64.deb 680d2dd5e155de1cb0c4d42eb0d3bafae911f96c9b812dd58fe61fafe8435e84 10954 bind9_9.16.50-1~deb11u1_amd64-buildd.buildinfo 47bb6d201ab6c9ef7750c20811a56551da7be176b976f109398928c7a7a7bf41 499896 bind9_9.16.50-1~deb11u1_amd64.deb Files: c80bc8a0f26e96153e2168a10a026cdd 517620 debug optional bind9-dbgsym_9.16.50-1~deb11u1_amd64.deb ca8646578118a9433bc59ae952218daa 1789692 devel optional bind9-dev_9.16.50-1~deb11u1_amd64.deb 9387e3bfd222a58581e1427076f5151e 287444 debug optional bind9-dnsutils-dbgsym_9.16.50-1~deb11u1_amd64.deb e316f5a32ed2c1c22d6473e35bdec325 407628 net standard bind9-dnsutils_9.16.50-1~deb11u1_amd64.deb b315addddc652480a436a2e1332fbbff 81696 debug optional bind9-host-dbgsym_9.16.50-1~deb11u1_amd64.deb 9a9c5ec47b18ae74443dcc3374fb3a86 311908 net standard bind9-host_9.16.50-1~deb11u1_amd64.deb d93ebddee67dcfcf0a6a3b8305a51662 3446904 debug optional bind9-libs-dbgsym_9.16.50-1~deb11u1_amd64.deb c0d129b37e32959b88a199448b882df2 1430404 libs standard bind9-libs_9.16.50-1~deb11u1_amd64.deb c1f28c5f51e86a7d6c33574a5305fdde 265412 debug optional bind9-utils-dbgsym_9.16.50-1~deb11u1_amd64.deb 3090dad40d11ff74a20972f338337ee7 439084 net optional bind9-utils_9.16.50-1~deb11u1_amd64.deb c3288f64cdf39dee6f47c6e829b2ffa6 10954 net optional bind9_9.16.50-1~deb11u1_amd64-buildd.buildinfo 8f250dc7226ce089cae70c505d897f40 499896 net optional bind9_9.16.50-1~deb11u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE4Unr4QHS5Yi4rr9Q3KGKEAtjIVgFAmaf8PEACgkQ3KGKEAtj IVhuoA/5AcrLbwBcwzMG91e9q7F7tODnDi+9wh39bd2sOubjBenoGweesOzJpLwk N8z4EV0qcypgsio8tLAMpxbtc2jYtVBsNrCY6fTFpLfD54qj7zHbsQNUwGT0Ty3c H0i9zLtXezAbS3mcdIdafpFaMo5m3A/bYuSXjTVpvCj8U3oP5mo7gatloWhYAjp/ 34NCxNAPW7E74ACfhmq9q/OG4Yj2zLngJQbHy+2FmvYOt1k9dVSE3LGTFNKJie66 R5Mx/buNrLzJACIgW8rDTkoZ66zJv8QlTUNMDK8kb9paj34bj1Ma8m3yyjt3t+YG Irm2zYWruswnM3sbVfUjYMRpO0LEqA43u9nT1H5M3wgE8BEX5QSrl2ZGpw6lqK05 LbfN4ubcLg5bUbHKZtglRwBKOT5U03tpCzt5QPjOoqHfammaYZ4phoF7qQJPPl40 3QSwikBkK3JsPdsTq79lB4a2WzPRe2LMwK3Bwj/6TXM/Djj77I+XL4yXTeEXKRzb qpI1wo8ghPgrE4J0sRL13fuyPCGoCV3mBzw4pinXWNPJp3Z2WZMVDPTJd9Hi4TzL UqACcXfAlaTgKJFMGlj1wRSft+qssx88Db7PnO2Won/L3bDnNcw3R1ghaq2p04EO 0FFOKTGdVwE6ha353nPDOT/1QtSFXy2misX7ch0edu6MbUrz4eY= =gvet -----END PGP SIGNATURE-----