poky/meta
Sona Sarmadi a8ff4c8f42 bind: CVE-2016-1285 CVE-2016-1286
CVE-2016-1285 bind: malformed packet sent to rndc can trigger assertion failure
CVE-2016-1286 bind: malformed signature records for DNAME records can
trigger assertion failure

[YOCTO #9400]

External References:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1285
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1286
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1285
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1286

References to the Upstream commits and Security Advisories:

CVE-2016-1285: https://kb.isc.org/article/AA-01352
https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=patch;
h=31e4657cf246e41d4c5c890315cb6cf89a0db25a

CVE-2016-1286_1: https://kb.isc.org/article/AA-01353
https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=patch;
h=76c3c9fe9f3f1353b47214b8f98b3d7f53e10bc7

CVE-2016-1286_2: https://kb.isc.org/article/AA-01353
https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=patch;
h=ce3cd91caee698cb144e1350c6c78292c6be6339

(From OE-Core rev: e289df4daa4b90fb95ae3602c244cba9d56a8c2f)

Signed-off-by: Sona Sarmadi <sona.sarmadi@enea.com>
Signed-off-by: Tudor Florea <tudor.florea@enea.com>
Signed-off-by: Joshua Lock <joshua.g.lock@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2016-05-09 08:11:34 +01:00
..
classes populate_sdk_base: Ensure PKGDATA_DIR exists 2016-05-09 08:11:33 +01:00
conf feature-arm-thumb.inc: Fix ARMPKGSFX_THUMB value 2016-01-15 13:14:34 +00:00
files toolchain-shar-template.sh: Make relocation optional. 2015-02-24 17:41:43 +00:00
lib rootfs.py: show intercept script output in log.do_rootfs 2015-09-18 19:22:26 +01:00
recipes-bsp grub2: Fix CVE-2015-8370 2016-01-15 13:14:35 +00:00
recipes-connectivity bind: CVE-2016-1285 CVE-2016-1286 2016-05-09 08:11:34 +01:00
recipes-core busybox_git: Fix SRCREV 2016-05-09 08:11:34 +01:00
recipes-devtools git: Security fixes CVE-2015-7545 2016-03-03 11:11:40 +00:00
recipes-extended rpcbind: Security Advisory - rpcbind - CVE-2015-7236 2016-03-03 11:11:40 +00:00
recipes-gnome gdk-pixbuf: Security fix CVE-2015-7674 2016-03-03 11:11:39 +00:00
recipes-graphics xorg-lib: allow native building without x11 DISTRO_FEATURES 2016-05-09 08:11:33 +01:00
recipes-kernel linux-dtb.inc: drop unused DTB_NAME variable from do_install 2016-01-15 13:14:34 +00:00
recipes-lsb4 libpng12: upgrade to 1.2.52 2015-01-07 23:35:01 +00:00
recipes-multimedia libpng: Security fix CVE-2015-8472 2016-03-03 11:11:40 +00:00
recipes-qt qt4: fix CVE issues 2015-06-28 09:44:17 +01:00
recipes-rt rt-tests: fix gzip command 2015-02-15 21:58:25 +00:00
recipes-sato webkit-gtk: disable JIT for armv5/armv6 2015-03-25 12:39:37 +00:00
recipes-support nettle: The variable named p in the patch file was incorrectly named. 2016-03-11 10:56:02 +00:00
site siteinfo: account for 32 and 64 bit arm 2014-12-23 10:18:17 +00:00
COPYING.GPLv2
COPYING.MIT
recipes.txt