diff --git a/doc/arm/Bv9ARM.ch09.html b/doc/arm/Bv9ARM.ch09.html index 783a2199ce..5ff5f7d080 100644 --- a/doc/arm/Bv9ARM.ch09.html +++ b/doc/arm/Bv9ARM.ch09.html @@ -107,13 +107,20 @@

Security Fixes

-

diff --git a/doc/arm/notes.html b/doc/arm/notes.html index 8e8531556f..7a8d704362 100644 --- a/doc/arm/notes.html +++ b/doc/arm/notes.html @@ -68,13 +68,20 @@

Security Fixes

-
  • +

      +
    • + It was possible to trigger a assertion when rendering a + message using a specially crafted request. This flaw is + disclosed in CVE-2016-2776. [RT #43139] +

    • +
    • getrrsetbyname with a non absolute name could trigger an infinite recursion bug in lwresd and named with lwres configured if when combined with a search list entry the resulting name is too long. This flaw is disclosed in CVE-2016-2775. [RT #42694] -

    +

  • +