From owner-cvs-ports@FreeBSD.ORG Tue Jul 5 21:18:25 2011 Return-Path: Delivered-To: cvs-ports@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 0AEFF106566C; Tue, 5 Jul 2011 21:18:25 +0000 (UTC) (envelope-from dougb@FreeBSD.org) Received: from repoman.freebsd.org (repoman.freebsd.org [IPv6:2001:4f8:fff6::29]) by mx1.freebsd.org (Postfix) with ESMTP id F11688FC08; Tue, 5 Jul 2011 21:18:24 +0000 (UTC) Received: from repoman.freebsd.org (localhost [127.0.0.1]) by repoman.freebsd.org (8.14.4/8.14.4) with ESMTP id p65LION1016435; Tue, 5 Jul 2011 21:18:24 GMT (envelope-from dougb@repoman.freebsd.org) Received: (from dougb@localhost) by repoman.freebsd.org (8.14.4/8.14.4/Submit) id p65LIOrq016434; Tue, 5 Jul 2011 21:18:24 GMT (envelope-from dougb) Message-Id: <201107052118.p65LIOrq016434@repoman.freebsd.org> From: Doug Barton Date: Tue, 5 Jul 2011 21:18:24 +0000 (UTC) To: ports-committers@FreeBSD.org, cvs-ports@FreeBSD.org, cvs-all@FreeBSD.org X-FreeBSD-CVS-Branch: HEAD Cc: Subject: cvs commit: ports/dns/bind96 Makefile distinfo ports/dns/bind97 Makefile distinfo X-BeenThere: cvs-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: CVS commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 05 Jul 2011 21:18:25 -0000 dougb 2011-07-05 21:18:24 UTC FreeBSD ports repository Modified files: dns/bind96 Makefile distinfo dns/bind97 Makefile distinfo Log: Update to versions 9.7.3-P3, and 9.6-ESV-R4-P3. ALL BIND USERS ARE ENCOURAGED TO UPGRADE IMMEDIATELY This update addresses the following vulnerability: CVE-2011-2464 ============= Severity: High Exploitable: Remotely Description: A defect in the affected BIND 9 versions allows an attacker to remotely cause the "named" process to exit using a specially crafted packet. This defect affects both recursive and authoritative servers. The code location of the defect makes it impossible to protect BIND using ACLs configured within named.conf or by disabling any features at compile-time or run-time. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2464 https://www.isc.org/software/bind/advisories/cve-2011-2464 Revision Changes Path 1.116 +2 -2 ports/dns/bind96/Makefile 1.68 +4 -4 ports/dns/bind96/distinfo 1.18 +2 -2 ports/dns/bind97/Makefile 1.14 +4 -4 ports/dns/bind97/distinfo