]> CyberLeo.Net >> Repos - FreeBSD/stable/8.git/commit
Update to version 9.6-ESV-R4, the latest from ISC, which addresses
authordougb <dougb@ccf9f872-aa2e-dd11-9fc8-001c23d0bc1f>
Wed, 8 Dec 2010 19:59:53 +0000 (19:59 +0000)
committerdougb <dougb@ccf9f872-aa2e-dd11-9fc8-001c23d0bc1f>
Wed, 8 Dec 2010 19:59:53 +0000 (19:59 +0000)
commitb9729ee9082fca3e15e6d8aabed82de35ef1f416
treee8c142b3ece6500673f2ed539766531a6f5fd021
parent9019e80862c5634472fc9dc8a1ad037c41e50495
Update to version 9.6-ESV-R4, the latest from ISC, which addresses
the following security vulnerabilities.

For more information regarding these issues please see:
http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisories

1. Cache incorrectly allows ncache and rrsig for the same type

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3613

   Affects resolver operators whose servers are open to potential
   attackers. Triggering the bug will cause the server to crash.

   This bug applies even if you do not have DNSSEC enabled.

2. Key algorithm rollover

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3614

   Affects resolver operators who are validating with DNSSEC, and
   querying zones which are in a key rollover period. The bug will
   cause answers to incorrectly be marked as insecure.

Approved by: re (kensmith)

git-svn-id: svn://svn.freebsd.org/base/stable/8@216307 ccf9f872-aa2e-dd11-9fc8-001c23d0bc1f
23 files changed:
contrib/bind9/CHANGES
contrib/bind9/RELEASE-NOTES-BIND-9.6-ESV.html [new file with mode: 0644]
contrib/bind9/RELEASE-NOTES-BIND-9.6-ESV.pdf [new file with mode: 0644]
contrib/bind9/RELEASE-NOTES-BIND-9.6-ESV.txt [new file with mode: 0644]
contrib/bind9/bin/check/check-tool.c
contrib/bind9/bin/check/check-tool.h
contrib/bind9/bin/check/named-checkconf.c
contrib/bind9/bin/check/named-checkzone.c
contrib/bind9/bin/dig/host.c
contrib/bind9/bin/named/client.c
contrib/bind9/bin/named/include/named/query.h
contrib/bind9/bin/named/query.c
contrib/bind9/bin/named/server.c
contrib/bind9/lib/dns/api
contrib/bind9/lib/dns/include/dns/view.h
contrib/bind9/lib/dns/journal.c
contrib/bind9/lib/dns/rbtdb.c
contrib/bind9/lib/dns/validator.c
contrib/bind9/lib/dns/view.c
contrib/bind9/lib/isc/api
contrib/bind9/lib/isc/print.c
contrib/bind9/release-notes.css [new file with mode: 0644]
contrib/bind9/version