bind: bump to 9.18.19
authorNoah Meyerhans <frodo@morgul.net>
Wed, 27 Sep 2023 17:42:59 +0000 (10:42 -0700)
committerNoah Meyerhans <frodo@morgul.net>
Wed, 27 Sep 2023 23:02:27 +0000 (16:02 -0700)
commit029d2de98c562c878f5e4e97d07ccaab9e91d38f
tree888640b1a15a4371a8fe1b9d59566b64efb5632d
parenta2fd53756b1c35576ae59d787c62040200710cd6
bind: bump to 9.18.19

Fixes CVEs:

CVE-2023-3341 - Previously, sending a specially crafted message over the
control channel could cause the packet-parsing code to run out of available
stack memory, causing named to terminate unexpectedly.

CVE-2023-4236 - A flaw in the networking code handling DNS-over-TLS queries
could cause named to terminate unexpectedly due to an assertion failure under
significant DNS-over-TLS query load.

Signed-off-by: Noah Meyerhans <frodo@morgul.net>
(cherry picked from commit 835b1051511b592d69bc0b8a7d5d993337f890da)
net/bind/Makefile