Bug#830806: [Pkg-dns-devel] Bug#830806: nsd: CVE-2016-6173: Improper restriction of zone size limit

2016-07-11 Thread Salvatore Bonaccorso
Hi Ondrej, On Mon, Jul 11, 2016 at 08:36:07PM +0200, Ondřej Surý wrote: > Hi Salvatore, > > the common agreement between DNS Vendors (that includes me) is that this > shouldn't have been assigned CVE as it is an operational issue as you > have an established trust between DNS master-slave for

Bug#830806: [Pkg-dns-devel] Bug#830806: nsd: CVE-2016-6173: Improper restriction of zone size limit

2016-07-11 Thread Ondřej Surý
Hi Salvatore, the common agreement between DNS Vendors (that includes me) is that this shouldn't have been assigned CVE as it is an operational issue as you have an established trust between DNS master-slave for transfers. (And all DNS servers are affected.) I don't think this really needs

Bug#830806: nsd: CVE-2016-6173: Improper restriction of zone size limit

2016-07-11 Thread Salvatore Bonaccorso
Source: nsd Version: 4.1.10-1 Severity: important Tags: security upstream patch Forwarded: https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=790 Hi, the following vulnerability was published for nsd. CVE-2016-6173[0]: Improper restriction of zone size limit If you fix the vulnerability