Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
unbound: Update version from 1.6.3 to 1.6.8
Am 05.02.2018 um 17:29 schrieb Viktor Dukhovni: > > If you're using unbound as your local DNSSEC-validating > resolver and have enabled DANE, an issue is resolved in > unbound 1.6.8 where NSEC records for wildcards could be > misused for invalid denial-of-existence proofs. See: > > https://medium.com/nlnetlabs/the-peculiar-case-of-nsec-processing-using-expanded-wildcard-records-ae8285f236be > https://unbound.net/downloads/CVE-2017-15105.txt > > The first article mentions that the same issue affected > PowerDNS and Dnsmasq. So if you're using one of those, > you might also need to update. While Google's public > DNS was also affected, this is out of scope for DANE, > as you get little security from relying on the AD bit > from remote resolvers.
- Loading branch information