2
0
mirror of https://gitlab.isc.org/isc-projects/bind9 synced 2025-08-30 22:15:20 +00:00

Add CHANGES and release notes for [GL #4124]

This commit is contained in:
Ondřej Surý
2023-08-14 11:20:41 +02:00
parent b22c87ca61
commit 57c8bdaff5
2 changed files with 11 additions and 0 deletions

View File

@@ -1,3 +1,6 @@
6224. [bug] Check the If-Modified-Since value length to prevent
out-of-bounds write. [GL #4124]
6223. [func] Make -E engine option for OpenSSL Engine API use only.
OpenSSL Provider API will now require engine to not be
set. [GL #8153]

View File

@@ -37,6 +37,14 @@ Bug Fixes
- None.
- The value of If-Modified-Since header in statistics channel was not checked
for length leading to possible buffer overflow by an authorized user. We
would like to emphasize that statistics channel must be properly setup to
allow access only from authorized users of the system. :gl:`#4124`
This was reported independently by Eric Sesterhenn of X41 D-SEC and Cameron
Whitehead.
Known Issues
~~~~~~~~~~~~