Skip to content

Update Unbound from 1.6.3 to 1.6.8 #603

Merged
merged 1 commit into from
Feb 7, 2018

Commits on Feb 5, 2018

  1. unbound: Update version from 1.6.3 to 1.6.8

    Am 05.02.2018 um 17:29 schrieb Viktor Dukhovni:
    >
    > If you're using unbound as your local DNSSEC-validating
    > resolver and have enabled DANE, an issue is resolved in
    > unbound 1.6.8 where NSEC records for wildcards could be
    > misused for invalid denial-of-existence proofs.  See:
    >
    >    https://medium.com/nlnetlabs/the-peculiar-case-of-nsec-processing-using-expanded-wildcard-records-ae8285f236be
    >    https://unbound.net/downloads/CVE-2017-15105.txt
    >
    > The first article mentions that the same issue affected
    > PowerDNS and Dnsmasq.  So if you're using one of those,
    > you might also need to update.  While Google's public
    > DNS was also affected, this is out of scope for DANE,
    > as you get little security from relying on the AD bit
    > from remote resolvers.
    pmenzel committed Feb 5, 2018
    Configuration menu
    Copy the full SHA
    973171b View commit details
    Browse the repository at this point in the history