-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 16 Feb 2024 12:21:56 +0100 Source: pdns-recursor Architecture: source Version: 4.8.6-1 Distribution: bookworm-security Urgency: medium Maintainer: pdns-recursor packagers Changed-By: Chris Hofstaedtler Changes: pdns-recursor (4.8.6-1) bookworm-security; urgency=medium . * New upstream version 4.8.6 * Fixes CVE-2023-50387 and CVE-2023-50868, see https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.html Introduces new configuration settings: * aggressive-cache-max-nsec3-hash-cost * max-dnskeys * max-ds-per-zone * max-nsec3-hash-computations-per-query * max-nsec3s-per-record * max-rrsigs-per-record * max-signature-validations-per-query * Fixes integer overflow in yahttp (webserver) * Fixes partial reads in ixfrdist * Fixes setting of policy tags for packet cache hits * Setup gbp.conf for Debian bookworm * d/watch: set to 4.8 branch Checksums-Sha1: 6133e131a092f0a06f55a797abac841dc43f2184 2829 pdns-recursor_4.8.6-1.dsc c37ab1cc20ada380c4bfffbd1f874d31964e6c30 1533869 pdns-recursor_4.8.6.orig.tar.bz2 ab8ee0475c80ed95a15e8f1d5f06f75840259898 488 pdns-recursor_4.8.6.orig.tar.bz2.asc bb0566a5fa2ce443f4e9ffc64d6df06925675994 23460 pdns-recursor_4.8.6-1.debian.tar.xz b2103593c25feb863b86322b1c0d0f01a3839f75 9511 pdns-recursor_4.8.6-1_arm64.buildinfo Checksums-Sha256: 2805c6a0d0d1dd136a9f3de017665d3662f3cb4547be69c77c06440f3aec2569 2829 pdns-recursor_4.8.6-1.dsc 1ff4087ef12e6fc68fccd22c97215fd7f01038d7ad46715e9ffe7494e9926d95 1533869 pdns-recursor_4.8.6.orig.tar.bz2 fff09f200e11d335eed1fd3147159b336a69b49b19fc37f471eafee7eb348139 488 pdns-recursor_4.8.6.orig.tar.bz2.asc 0bb430a9b8aac0291feb836fd2a985af43c8f384a4b8e2eb58e6e83ba9bc1d7d 23460 pdns-recursor_4.8.6-1.debian.tar.xz e52bc327a5581fc668498c508f33e6fd946994b8461682ebf2d0a969feb9497d 9511 pdns-recursor_4.8.6-1_arm64.buildinfo Files: c40687608d3730b43d834aeba14133ca 2829 net optional pdns-recursor_4.8.6-1.dsc 0d41e054d301cfcd84bf04ac8f270610 1533869 net optional pdns-recursor_4.8.6.orig.tar.bz2 acb5451ea898a73477ca6d375cc31975 488 net optional pdns-recursor_4.8.6.orig.tar.bz2.asc 86eb153b983bb0763726598dcbb9fb4b 23460 net optional pdns-recursor_4.8.6-1.debian.tar.xz 4f2701c3f0b12308b0aa6b127bc1108d 9511 net optional pdns-recursor_4.8.6-1_arm64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEfRrP+tnggGycTNOSXBPW25MFLgMFAmXP8xAACgkQXBPW25MF LgOIxxAAqTRvJS8MuR/OFhbWspWxlortXRuG3X3bCpAIce9cKZFoTA7hNsIansx6 t4vlsGqlckCvvbRXox8S2yLmk75vfQpWMV1+Nzk4jEvhpH6wisJoJBQQjGLZrCcQ q/oaccnZd4imMfLUMsqW5xW65McHw9LJCU1iQtTkwO2qP5gsDMQvs0MBgplunbkl BPSeIEaIC5P+VYVUVzzMJJOi0ilmnsJhZ79W5wpIfoJ/oxzlZJ2MjZSd57A+FgPf G02K2JI6G5V5s335JFEMUBH4UtnNTM0JLdSAvTOH++Yz/aVTwjtv03VyAVkgDAhW Jtlk0COlFZWVXQR3NVXf1q2RlOzKSNN/ZQgeFVQFbQ0zFEa3NqmDv8BnLgXb2rZl E1R6VSc8veirJckXyq1pgv7ffV58H99KmsJy8N+MnWduvBHG/PHULLS3Bi7nVy9C 7a+Tq8+4kDlbiNPuP9mHU1H1tWxjtMNLIvBDhLXli+4HNE/rXWlIgGSZ2dOcxdHQ ZVboIz4ejANjHp/pNwrluWWCkBg8DYpJwVay67ooufeN/XaBmQ28ZE7IxpdmZyL9 mossqCg+j6A1DjwWRM9X8OJd7bLim5fCZWoXjnnlylToZCRz9t4tfC2evMi0ZB01 r/5Avdo3SpVQUx3o4Es45MubcK/9DSLItU/LcimgfHjbyagNaec= =RTgt -----END PGP SIGNATURE-----