Format: 1.8 Date: Tue, 18 Aug 2020 07:38:53 -0400 Source: bind9 Binary: bind9 bind9-dnsutils bind9-doc bind9-host bind9-libs bind9-utils bind9utils dnsutils Architecture: amd64 all amd64_translations Version: 1:9.16.1-0ubuntu2.3 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: bind9 - Internet Domain Name Server bind9-dnsutils - Clients provided with BIND 9 bind9-doc - Documentation for BIND 9 bind9-host - DNS Lookup Utility bind9-libs - Shared Libraries used by BIND 9 bind9-utils - Utilities for BIND 9 bind9utils - Transitional package for bind9-utils dnsutils - Transitional package for bind9-dnsutils Changes: bind9 (1:9.16.1-0ubuntu2.3) focal-security; urgency=medium . * SECURITY UPDATE: A specially crafted large TCP payload can trigger an assertion failure - debian/patches/CVE-2020-8620.patch: add extra checks to lib/isc/netmgr/netmgr-int.h, lib/isc/netmgr/netmgr.c, lib/isc/netmgr/tcp.c, lib/isc/netmgr/udp.c. - CVE-2020-8620 * SECURITY UPDATE: Attempting QNAME minimization after forwarding can lead to an assertion failure - debian/patches/CVE-2020-8621.patch: disable QNAME minimization in lib/dns/resolver.c. - CVE-2020-8621 * SECURITY UPDATE: A truncated TSIG response can lead to an assertion failure - debian/patches/CVE-2020-8622.patch: move code in lib/dns/message.c. - CVE-2020-8622 * SECURITY UPDATE: A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure - debian/patches/CVE-2020-8623.patch: add extra checks in lib/dns/pkcs11rsa_link.c, lib/isc/include/pk11/internal.h, lib/isc/pk11.c. - CVE-2020-8623 * SECURITY UPDATE: update-policy rules of type subdomain were enforced incorrectly - debian/patches/CVE-2020-8624.patch: add extra check in bin/named/zoneconf.c. - CVE-2020-8624 Checksums-Sha1: ae8878c350e6829d7879e5496f4c1fd4f9166628 540076 bind9-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb e486a902c47990b7cd6c4bf3a2c7d3b9544d71c5 299200 bind9-dnsutils-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb 669c87581bc0362e57425b763c36068273f87962 134108 bind9-dnsutils_9.16.1-0ubuntu2.3_amd64.deb 43fc977397050090194807d3f0889e2fdc6fc32b 254224 bind9-doc_9.16.1-0ubuntu2.3_all.deb c938987e1bc4214969d5a391420e9315e4e20fc2 84428 bind9-host-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb 25ecd08eabcfa8ad25d496eeaab91cb069b2942e 43008 bind9-host_9.16.1-0ubuntu2.3_amd64.deb fb042d38dd0750071e4ca3dbb45c14e90b6f7876 3495080 bind9-libs-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb 8f0b87eafc28b26b330235ede7d4459624c1d9b7 1115016 bind9-libs_9.16.1-0ubuntu2.3_amd64.deb 6f0cb4037fa82e9dfe6c15fb490fa3cdd41fcca0 297620 bind9-utils-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb cb84e4753f6fdc0703a2682d03971424aec85c6a 172012 bind9-utils_9.16.1-0ubuntu2.3_amd64.deb 7af583ca7eea6b77efdc55f65d2f4ee2d1ea0147 11785 bind9_9.16.1-0ubuntu2.3_amd64.buildinfo a0a9c2abfddfcf9241ac3bb27951b81768afa843 233160 bind9_9.16.1-0ubuntu2.3_amd64.deb dc21b0ea96978d5bcb8fcabe3577247de2456260 12985 bind9_9.16.1-0ubuntu2.3_amd64_translations.tar.gz 0c24a0602611c0c9c4a8cadcfe538d632f4abc51 2756 bind9utils_9.16.1-0ubuntu2.3_all.deb 3f39fc166c26a013f242de0dd0de688290ddc640 2756 dnsutils_9.16.1-0ubuntu2.3_all.deb Checksums-Sha256: fcbe75c1af8ce54d19db15b2c876cfb161aa2fcde4019cdbc54c21ca7622c866 540076 bind9-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb 6af5b4ffd3aa218ebcf54c545e7d53014c3fec28955771c70d004bc8a009614e 299200 bind9-dnsutils-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb 58db0bc4131c2b51017a2892971e9e5caaac645a86e107a911cd54a73ffab081 134108 bind9-dnsutils_9.16.1-0ubuntu2.3_amd64.deb f38f6a28fc930769d63b30ceca064c3588279113a787484ca00bed7ae8c8563d 254224 bind9-doc_9.16.1-0ubuntu2.3_all.deb 008b1ee05d3544eedb2d296b34d3b30d740158d338a078b6777b0e8d017f4a3e 84428 bind9-host-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb 85185cad65635aeb1105d7299a042822d8e039f7d0c8db1cadb537787000a6a5 43008 bind9-host_9.16.1-0ubuntu2.3_amd64.deb 1b2799f97aa782e4694ce0bd41c56b1de2230bade0c3016bbd92748f76bc1629 3495080 bind9-libs-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb ea73973d18a457940ed681a3792f504c0d4ab1f4e939bdf203fc256b586fa33d 1115016 bind9-libs_9.16.1-0ubuntu2.3_amd64.deb 13088a4f7beb1374fa8f7d1d6c2c8d21f514bd80aea549e450f38acc53f62c20 297620 bind9-utils-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb f7c4f2c2b905fa1fde96c00f2113283667e5d7972777b08c5a0d9a8465570646 172012 bind9-utils_9.16.1-0ubuntu2.3_amd64.deb 56ef9fa6860a897b87af3779f7460cbe6de8df28d707b16e5347034b7fcd8e8e 11785 bind9_9.16.1-0ubuntu2.3_amd64.buildinfo 08beee86586654dfd5f06baf549604f5dcbf802870c71222315ec5341afb2ab2 233160 bind9_9.16.1-0ubuntu2.3_amd64.deb 21c2a03a804b12abbf364336336d65c3b2c441a64bb064422b545c7d72fe7506 12985 bind9_9.16.1-0ubuntu2.3_amd64_translations.tar.gz 5134c4e754c475251591f8b355a5847fc58a00218d8c773544d270f1a992448d 2756 bind9utils_9.16.1-0ubuntu2.3_all.deb 2ace5813c4561efc4157d8b2fa1f36bc619572bd47661aaf7003640a371ec32d 2756 dnsutils_9.16.1-0ubuntu2.3_all.deb Files: 01ff43479dd04b1f3db72a3d44ecee0b 540076 debug optional bind9-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb d2903520c0ec421bc10663abc9305812 299200 debug optional bind9-dnsutils-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb cc624e04d363bfc7729fa94f7739645d 134108 net standard bind9-dnsutils_9.16.1-0ubuntu2.3_amd64.deb b82188c7dccd2fdf64bb4e6982a2b672 254224 doc optional bind9-doc_9.16.1-0ubuntu2.3_all.deb d76c9bff12006eee02d118354385c2cf 84428 debug optional bind9-host-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb 2e3e91b49409cf713e6f574cdb403fd8 43008 net standard bind9-host_9.16.1-0ubuntu2.3_amd64.deb 4948307942aa14add9172a285db06bbf 3495080 debug optional bind9-libs-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb 94c1620397efd1d653808b3548be367e 1115016 libs standard bind9-libs_9.16.1-0ubuntu2.3_amd64.deb 781af9c0dad10b4bcf2ca41f87a336e2 297620 debug optional bind9-utils-dbgsym_9.16.1-0ubuntu2.3_amd64.ddeb accc86ce944126ebac2506603fbfa510 172012 net optional bind9-utils_9.16.1-0ubuntu2.3_amd64.deb dea4c7c2ca4a16874826f1429c30f81f 11785 net optional bind9_9.16.1-0ubuntu2.3_amd64.buildinfo c9d3f49873c5e707c22ec0afc984db0d 233160 net optional bind9_9.16.1-0ubuntu2.3_amd64.deb 77d655f62c83df98aa3a09b551e6b398 12985 raw-translations - bind9_9.16.1-0ubuntu2.3_amd64_translations.tar.gz 0e5fe9352f0d891aea3a90c4ef8980a4 2756 oldlibs optional bind9utils_9.16.1-0ubuntu2.3_all.deb 3037c296d86ceaaf58b16a4023a818a3 2756 oldlibs optional dnsutils_9.16.1-0ubuntu2.3_all.deb Original-Maintainer: Debian DNS Team