add CVE-2016-2776

This commit is contained in:
Mark Andrews 2016-09-09 11:52:19 +10:00
parent 49f80e0fc5
commit 89996b6bd9

View file

@ -41,6 +41,13 @@
<section xml:id="relnotes_security"><info><title>Security Fixes</title></info>
<itemizedlist>
<listitem>
<para>
It was possible to trigger a assertion when rendering a
message using a specially crafted request. This flaw is
disclosed in CVE-2016-2776. [RT #43139]
</para>
</listitem>
<listitem>
<para>
getrrsetbyname with a non absolute name could trigger an