bind: bump to 9.18.7
authorNoah Meyerhans <redacted>
Wed, 21 Sep 2022 18:57:50 +0000 (11:57 -0700)
committerRosen Penev <redacted>
Thu, 22 Sep 2022 08:22:39 +0000 (01:22 -0700)
commitba76684a3d487fb92b3824aa3a0b7a20fd86ea9a
treed568249472b5b291a780a73fecbb4395c1191ef0
parent8cb0ed95dd101b1c8d4b44482ef2033a202b030f
bind: bump to 9.18.7

Fixes multiple security issues:

CVE-2022-38178 - Fix memory leak in EdDSA verify processing

CVE-2022-3080 - Fix serve-stale crash that could happen when
stale-answer-client-timeout was set to 0 and there was
a stale CNAME in the cache for an incoming query

CVE-2022-2906 - Fix memory leaks in the DH code when using OpenSSL 3.0.0
and later versions. The openssldh_compare(),
openssldh_paramcompare(), and openssldh_todns()
functions were affected

CVE-2022-2881 - When an HTTP connection was reused to get
statistics from the stats channel, and zlib
compression was in use, each successive
response sent larger and larger blocks of memory,
potentially reading past the end of the allocated
buffer

CVE-2022-2795 - Prevent excessive resource use while processing large
delegations

Signed-off-by: Noah Meyerhans <redacted>
net/bind/Makefile
git clone https://git.99rst.org/PROJECT