From fab382315ad3be7c773aaf7ca49c053cf91755fe Mon Sep 17 00:00:00 2001 From: Florian Weimer Date: Fri, 29 Jul 2016 17:34:17 -0400 Subject: CVE-2016-5417 was assigned to bug 19257 --- NEWS | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'NEWS') diff --git a/NEWS b/NEWS index e2737d5f47..680f792685 100644 --- a/NEWS +++ b/NEWS @@ -66,6 +66,11 @@ Security related changes: flooded with crafted ICMP and UDP messages. Reported by Aldy Hernandez' alloca plugin for GCC. (CVE-2016-4429) +* The IPv6 name server management code in libresolv could result in a memory + leak for each thread which is created, performs a failing naming lookup, + and exits. Over time, this could result in a denial of service due to + memory exhaustion. Reported by Matthias Schiffer. (CVE-2016-5417) + The following bugs are resolved with this release: [The release manager will add the list generated by -- cgit 1.4.1