From 89996b6bd9748c4c747f7ff0efee13d9304ff215 Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Fri, 9 Sep 2016 11:52:19 +1000 Subject: [PATCH] add CVE-2016-2776 --- doc/arm/notes.xml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/doc/arm/notes.xml b/doc/arm/notes.xml index 2be7340790..3150807116 100644 --- a/doc/arm/notes.xml +++ b/doc/arm/notes.xml @@ -41,6 +41,13 @@
Security Fixes + + + It was possible to trigger a assertion when rendering a + message using a specially crafted request. This flaw is + disclosed in CVE-2016-2776. [RT #43139] + + getrrsetbyname with a non absolute name could trigger an