add CVE-2016-2776

This commit is contained in:
Mark Andrews 2016-09-09 11:52:19 +10:00
parent e1570b4fc0
commit fa1f25ce83

View file

@ -42,6 +42,13 @@
<section xml:id="relnotes_security"><info><title>Security Fixes</title></info>
<itemizedlist>
<listitem>
<para>
It was possible to trigger a assertion when rendering a
message using a specially crafted request. This flaw is
disclosed in CVE-2016-2776. [RT #43139]
</para>
</listitem>
<listitem>
<para>
getrrsetbyname with a non absolute name could trigger an