-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 19 May 2020 11:36:53 -0400 Source: unbound Architecture: source Version: 1.10.1-1 Distribution: unstable Urgency: high Maintainer: unbound packagers <unbound@packages.debian.org> Changed-By: Robert Edmonds <edmonds@debian.org> Changes: unbound (1.10.1-1) unstable; urgency=high . * New upstream version 1.10.1 - Fix CVE-2020-12662: Unbound can be tricked into amplifying an incoming query into a large number of queries directed to a target. - Fix CVE-2020-12663: Malformed answers from upstream name servers can be used to make Unbound unresponsive. Checksums-Sha1: 5e125f6b09a9219b55e6d17892c87eaa2a9293d8 3048 unbound_1.10.1-1.dsc 9932931d495248b4e45d278b4679efae29238772 5729334 unbound_1.10.1.orig.tar.gz c9869c64962cf3ba190cf168e946e4a0a285fb76 833 unbound_1.10.1.orig.tar.gz.asc ffa945dc6c9a2c1d9583ab0ae79f87a9b9481417 19504 unbound_1.10.1-1.debian.tar.xz d0cab585ea9b33ed03b657625a8cd9ed9703cade 9672 unbound_1.10.1-1_amd64.buildinfo Checksums-Sha256: f912bb1fe0c139b80d5e5cb873890ca52780be4b2684349db4829e91ae8e6c71 3048 unbound_1.10.1-1.dsc b73677c21a71cf92f15cc8cfe76a3d875e40f65b6150081c39620b286582d536 5729334 unbound_1.10.1.orig.tar.gz bceef22440a6ff97fe70d8a9bddcd999b70d41f2567d4b897ecf3e90c3aee48a 833 unbound_1.10.1.orig.tar.gz.asc 590a76965450a7c1d008b5d02b661bab898c311c2c826465339843d61fcdd4c4 19504 unbound_1.10.1-1.debian.tar.xz 20395202cbed0edaca7a2d65884d91416874bc40fd9595a99c6200effa97a629 9672 unbound_1.10.1-1_amd64.buildinfo Files: 518db1eb2b52a1d9676300d07bb04241 3048 net optional unbound_1.10.1-1.dsc 48f8ee02d0d92603a8d7f4fda7152da0 5729334 net optional unbound_1.10.1.orig.tar.gz f1f461020d0bc0c0d16a7741db4020b7 833 net optional unbound_1.10.1.orig.tar.gz.asc 05b51584dccf2161fa97d2aab40a5965 19504 net optional unbound_1.10.1-1.debian.tar.xz 84c3fc58e9b22fe6a8d4947ebe21d154 9672 net optional unbound_1.10.1-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEE3z2W7rOCeCDzAmZcAYF6sKr2za4FAl7EABIACgkQAYF6sKr2 za4gMw//fr1KTZO6/LUcBfB4D7Hn8PwTwax20bLLRzJcz51bMiP8FJFdkFhpjzpO 7R2zYAdWT2IeLVWQtUdhPOzB1iz4kTHP6pf84XC+/bIQkhqV3aRGc9c2EC41EOyM 77hIW0ZqJ4m6rMei3weci5CWPI6ORaPwEHzF2Cc4gnF2WUvioNny8fn/0Yed9GDB +cIqWeukHUiRuaj4grtbthHuhdNNwCA3H4SCXDpcnywTpA5Mpcm8yQOlO6ypVe0i DWWbMsvUv6n+WjMT/b+K/KfI9knUniNu5060yrwJ6wVkCmo1Bd+1bneG2N71VIxz kRZS/oml/ZdZLlRb/qe95jJcvHzLUjjzIsSawyQIKBxbH+93e9msMnQnWRPTL1H2 pbZESs3tDW2NfRSewRsHA8wuqbL8dgY11SkFkGhn5kJuSWemZDVGE1dM1JyGWGFB Jr6tWX4v9RRNHuYvAFu2S8D1cF/10whzvx8ykz8x5St7CrYfPn/Cz9ArBVIAr3cU lO0cv764i6DBJ7bDThiHKVP+o+Sbn9AVhtXjxdrYxoPh1RSRT4AKPnmsFI1IdMs0 fpN9KcuacoF6ZIW3sVW3cdLvzHZxoThKdA8I2JtDhB9XqKNfkxAhrJvn+I1zEM37 8aSfaquCbz2fyTrxL/vO9rnOHlBqtJWVI3GevGDS34ezCmBYxzc= =d/r6 -----END PGP SIGNATURE-----