Commit Graph
267 Commits
Author SHA1 Message Date
Evan Hunt 8d00c66095 [v9_11_1_patch] address TSIG bypass/forgery vulnerabilities
4643.	[security]	An error in TSIG handling could permit unauthorized
			zone transfers or zone updates. (CVE-2017-3142)
			(CVE-2017-3143) [RT #45383]

(cherry picked from commit 581c1526ab)
(cherry picked from commit a03f4b1ea4)
2017-06-27 11:48:31 -07:00
Evan Hunt 91dfaf39a9 [v9_11_1_patch] quote service registry paths
4532.	[security]	The BIND installer on Windows used an unquoted
                        service path, which can enable privilege escalation.
			(CVE-2017-3141) [RT #45229]

(cherry picked from commit 967a3b9419)
(cherry picked from commit c28e44f3f8)
2017-05-30 13:43:41 -07:00
Evan Hunt 5e618a7edc [v9_11_1_patch] fix rpz formerr loop
4531.	[security]	Some RPZ configurations could go into an infinite
			query loop when encountering responses with TTL=0.
			(CVE-2017-3140) [RT #45181]

(cherry picked from commit 3440cf9c60)
2017-05-30 12:51:27 -07:00
Evan Hunt 62b5dd5b09 [v9_11] prep 9.11.1 2017-04-13 20:41:42 -07:00
Evan Hunt cf710c81ae [v9_11] document that delv should be used instead of sigchase
(cherry picked from commit db93f3d4b3)
2017-03-25 12:23:14 -07:00
Evan Hunt 559cbe04e7 [v9_11] remove unnecessary INSIST and prep 9.11.1rc2
4578.	[security]	Some chaining (CNAME or DNAME) responses to upstream
			queries could trigger assertion failures.
			(CVE-2017-3137) [RT #44734]

(cherry picked from commit a1365a0042)
2017-02-23 14:55:10 -08:00
Mark Andrews 6ef61e7645 9.11.1 2017-02-16 12:27:40 +11:00
Evan Hunt 43769594c0 [v9_11] prep 9.11.1rc1 2017-02-04 22:30:16 -08:00
Evan Hunt 971d346eae [v9_11] README 2016-12-28 20:39:00 -08:00
Mark Andrews b243aa40f9 4508. [security] Named incorrectly tried to cache TKEY records which
could trigger a assertion failure when there was
                            a class mismatch. (CVE-2016-9131) [RT #43522]

(cherry picked from commit 2c1c4b99a1)
2016-12-29 11:17:14 +11:00
Mark Andrews 76af83c9ad 4497. [port] Add support for OpenSSL 1.1.0. [RT #41284]
(cherry picked from commit 1fce0951ed)
2016-10-31 10:05:55 +11:00
Mark Andrews 97222baa4e add CVE-2016-2776
(cherry picked from commit 1090e198c4)
2016-09-09 11:39:47 +10:00
Evan Hunt 756b54c8ff [v9_11] add missing release notes and fix other doc nits
(cherry picked from commit 864dc79dce)
2016-08-24 16:25:51 -07:00
Mark Andrews b740318a42 add CVE-2016-2775
(cherry picked from commit 909d442cc0)
2016-07-12 01:09:37 +10:00
Evan Hunt d977bc3504 [master] reorder README, add catalog zones and minimal-any 2016-05-31 15:10:35 -07:00
Mark Andrews 704e905831 document python requirements 2016-05-26 15:38:32 +10:00
Mark Andrews 47d19078de note RNDC module 2016-05-24 10:47:58 +10:00
Mark Andrews 889a2f078e move 9.10.0 to HISTORY 2016-05-24 10:20:36 +10:00
Evan Hunt aa5506eda8 [master] update README 2016-04-28 00:29:25 -07:00
Jeremy C. Reed 5816d36671 minor grammar 2016-03-15 07:52:16 -04:00
Mark Andrews 7ffbf189be s/grand/grant/ 2016-03-15 12:35:37 +11:00
Evan Hunt 1a849dab19 [master] add missing functional changes to README 2016-03-14 18:00:15 -07:00
Mark Andrews 3d8078255f document --with-zlib 2016-03-10 16:38:14 +11:00
Mark Andrews d9ec4ca4b6 add CVE-2016-2088 2016-02-27 13:24:56 +11:00
Evan Hunt 5828f08714 [master] add [performance] 2016-02-01 09:52:06 -08:00
Mark Andrews 77daae1a07 add CVE-2015-8000 2015-11-17 15:29:10 +11:00
Evan Hunt b66b333f59 [master] dnstap
4235.	[func]		Added support in named for "dnstap", a fast method of
			capturing and logging DNS traffic, and a new command
			"dnstap-read" to read a dnstap log file.  Use
			"configure --enable-dnstap" to enable this
			feature (note that this requires libprotobuf-c
			and libfstrm). See the ARM for configuration details.

			Thanks to Robert Edmonds of Farsight Security.
			[RT #40211]
2015-10-02 12:32:42 -07:00
Evan Hunt afc3103851 [master] add CVE number 2015-08-13 15:30:49 -07:00
Evan Hunt ce9f893e21 [master] address buffer accounting error
4168.	[security]	A buffer accounting error could trigger an
			assertion failure when parsing certain malformed
			DNSSEC keys. (CVE-2015-5722) [RT #40212]
2015-08-07 13:16:10 -07:00
Evan Hunt 53b5a0377d [master] add fetchlimit to README 2015-08-03 12:48:05 -07:00
Mark Andrews c5eb9add52 add CVE-2015-5477 2015-07-15 07:51:06 +10:00
Mark Andrews f5e4daf2ba add CVE-2015-1349 2015-02-11 16:36:01 +11:00
Evan Hunt 67c6b5edd0 [master] backfill release notes 2014-10-21 16:42:23 -07:00
Evan Hunt c6e22bbaef [master] add a bit more info to CHANGES note, update README 2014-10-21 16:14:30 -07:00
Mark Andrews ed1c845c1d 3964. [func] nsupdate now performs check-names processing.
[RT #36266]
2014-10-02 09:35:43 +10:00
Jeremy C. Reed e7a1b21617 fix a few misspelling typos 2014-10-01 11:58:13 -05:00
Mark Andrews 10c12aa549 3956. [func] Notify messages are now rate limited by notify-rate and
startup-notify-rate instead of serial-query-rate.
                        [RT #24454]

3955.   [bug]           Notify messages due to changes are no longer queued
                        behind startup notify messages. [RT #24454]
2014-09-29 10:01:08 +10:00
Evan Hunt e1cd26e8f9 [master] update contact info in README and confiure --help 2014-09-16 12:27:03 -07:00
Mark Andrews cab0e126ca add +ednsopt and +ednsflags 2014-09-15 12:58:15 +10:00
Evan Hunt b969187234 [master] some new features had been omitted from README 2014-09-11 13:58:08 -07:00
Evan Hunt 1fe0d7f6d0 [master] fixed incorrect option name 2014-09-11 13:14:58 -07:00
Evan Hunt d46855caed [master] ECS authoritative support
3936.	[func]		Added authoritative support for the EDNS Client
			Subnet (ECS) option.

			ACLs can now include "ecs" elements which specify
			an address or network prefix; if an ECS option is
			included in a DNS query, then the address encoded
			in the option will be matched against "ecs" ACL
			elements.

			Also, if an ECS address is included in a query,
			then it will be used instead of the client source
			address when matching "geoip" ACL elements.  This
			behavior can be overridden with "geoip-use-ecs no;".

			When "ecs" or "geoip" ACL elements are used to
			select a view for a query, the response will include
			an ECS option to indicate which client network the
			answer is valid for.

			(Thanks to Vincent Bernat.) [RT #36781]
2014-08-28 22:05:57 -07:00
Jeremy C. Reed 821350367e fix typos or misspellings 2014-08-15 10:35:31 -05:00
Evan Hunt d0ffef73fd [35925] add more EDNS EXPIRE doc, clarify CHANGES note 3911 2014-08-05 19:32:46 -07:00
Mark Andrews 06ee28c48c add CVE-2014-3859 2014-05-26 13:12:54 +10:00
Mark Andrews 467a8a85d2 Add CVE-2014-3214 to README 2014-05-09 13:40:40 +10:00
Evan Hunt 44613d4d86 [master] named -L option for default logfile
3832.	[func]		"named -L <filename>" causes named to send log
			messages to the specified file by default instead
			of to the system log. (Thanks to Tony Finch.)
			[RT #35845]
2014-04-29 17:17:03 -07:00
Evan Hunt cd750f6e74 [master] dig +ttlunits
3829.	[func]		"dig +ttlunits" causes dig to print TTL values
			with time-unit suffixes: w, d, h, m, s for
			weeks, days, hours, minutes, and seconds. (Thanks
			to Tony Finch.) [RT #35823]
2014-04-29 16:58:36 -07:00
Evan Hunt b4ba66ba1e [master] "dnssec-signzone -N date"
3827.	[func]		"dnssec-signzone -N date" updates serial number
			to the current date in YYYYMMDDNN format.
			[RT #35800]
2014-04-29 16:29:20 -07:00
Evan Hunt 39a1cfa415 [master] update README, version
- README: clear out 9.9 features, add some missing 9.11 features
- version: update to 9.11.0pre-alpha.
2014-04-23 16:11:26 -07:00