-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 21 Feb 2024 12:06:49 CET Source: unbound Architecture: source Version: 1.9.0-2+deb10u4 Distribution: buster-security Urgency: medium Maintainer: unbound packagers <unbound@packages.debian.org> Changed-By: Markus Koschany <apo@debian.org> Checksums-Sha1: cb19ae9923fd9576dd338e5ac77e3d56734be91d 3209 unbound_1.9.0-2+deb10u4.dsc 746f1e7b96789c9b76b40c18abfb815ea129e0a9 50628 unbound_1.9.0-2+deb10u4.debian.tar.xz 15f6bcf6b8d78857e4bc3a19cc38f51c5b085191 11519 unbound_1.9.0-2+deb10u4_amd64.buildinfo Checksums-Sha256: eb3725142a45ff8211d8b2f8ab0506a58cb5503a6c7527cafb5fe072c4912fa1 3209 unbound_1.9.0-2+deb10u4.dsc 37e6fa5153d01ce11240287feb874978c7d3ab76b7f1203050a9a1a7bd2be5be 50628 unbound_1.9.0-2+deb10u4.debian.tar.xz 5a72c23c90ff576e7e0fde4a37e22007454f046901b0a02a602622f2c26af6be 11519 unbound_1.9.0-2+deb10u4_amd64.buildinfo Changes: unbound (1.9.0-2+deb10u4) buster-security; urgency=medium . * Non-maintainer upload by the LTS team. * Fix CVE-2023-50387 and CVE-2023-50868: Two vulnerabilities were discovered in unbound, a validating, recursive, caching DNS resolver. Specially crafted DNSSEC answers could lead unbound down a very CPU intensive and time costly DNSSEC (CVE-2023-50387) or NSEC3 hash (CVE-2023-50868) validation path, resulting in denial of service. Files: bc808249dc6f81fea9fbefad3192a597 3209 net optional unbound_1.9.0-2+deb10u4.dsc 6a7f4a95afcbeba56da58e8a1c02dc65 50628 net optional unbound_1.9.0-2+deb10u4.debian.tar.xz 1b6953ed8a5df9b4880becaee239dc03 11519 net optional unbound_1.9.0-2+deb10u4_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmXV2Y9fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkpFMP/i4KGn/jNxHxImceBerVMXTuIwFozIQrG8ES 5Hs7lB77jkMDZTV5n8IOjiO3vVKxUpDp+ydyPbv1fbDx8iU1dtOm1Dc7d5Smbm+Q jvBviG62CEfN7vfebomFGCTRmjK5IynddNZhj+GPEVApXoJJtnc2sLbtU2lCEIsO wnfnJMlo7IpAwZ6sK7w9HNy+X5lIX1ZwQF8+DH9EPWlxRlcFtS/CgO0p/nksHYSG c2Hka9MklV0A+PLqx/Kl8KYOZNdf9ubWb9Yjc03qZwFNxl1yRDqueYyE3FNT1yG9 UI2CepqfvNqbVjX6xogeP6ZQUu/ZsaDdY5iiM+76jkdpZgkUFinyyKvV8IfHO6Fq /XAjCM33UWwRQojdxWhj6ueidsuyA3rRZr155QP15INR/ip7mqmHKuCujtmaqnwb tqG3lBAW4K1fIAgt8hEbz5M98pROhhrGb8z71pX7q06tYFNNvFVvC1USf4DJNGIS 8i1A0LWzU4S6yISpOWWvqo/hRUpXROfYUN79saJkpSbNPr5If/KmZhBypyszuIOW ST2KsyTNWnFrX5rhHN/9X55VhdRh1Et85UMo/zCKJtCgcCRWQMx7Zg5CUZThq0k7 vfAsMzJB8gHih5OizGb/KgbiCo2Osko/IiKSHTPHl6kywlBp0F3bs0eFbBgwbzqo 6GkkO8A0 =/ePO -----END PGP SIGNATURE-----
Attachment:
pgppv5Mul7GrY.pgp
Description: PGP signature