Compare commits
25
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
40edd31a39 | ||
|
|
7a0c2ebac1 | ||
|
|
aed3c57da2 | ||
|
|
ed08dad79b | ||
|
|
63ab79731e | ||
|
|
8b34d90c16 | ||
|
|
ea4826f9b2 | ||
|
|
1a7c6f9dc8 | ||
|
|
9bd65261f6 | ||
|
|
1398f719a6 | ||
|
|
a27daee583 | ||
|
|
835485d6a7 | ||
|
|
42bd0776fd | ||
|
|
88036745f4 | ||
|
|
efd33e0dec | ||
|
|
e6732ebd6f | ||
|
|
abaf4a6a5c | ||
|
|
1e6bd6b53a | ||
|
|
91adc7a4da | ||
|
|
07967caf75 | ||
|
|
bb0783f9e8 | ||
|
|
8c2d209f09 | ||
|
|
fbe9182ffd | ||
|
|
c43edd377b | ||
|
|
17776a169c |
@@ -1,3 +1,23 @@
|
||||
--- 9.9.10-P1 released ---
|
||||
|
||||
4632. [security] The BIND installer on Windows used an unquoted
|
||||
service path, which can enable privilege escalation.
|
||||
(CVE-2017-3141) [RT #45229]
|
||||
|
||||
4631. [security] Some RPZ configurations could go into an infinite
|
||||
query loop when encountering responses with TTL=0.
|
||||
(CVE-2017-3140) [RT #45181]
|
||||
|
||||
--- 9.9.10 released ---
|
||||
|
||||
--- 9.9.10rc3 released ---
|
||||
|
||||
4582. [security] 'rndc ""' could trigger a assertion failure in named.
|
||||
(CVE-2017-3138) [RT #44924]
|
||||
|
||||
4580. [bug] 4578 introduced a regression when handling CNAME to
|
||||
referral below the current domain. [RT #44850]
|
||||
|
||||
--- 9.9.10rc2 released ---
|
||||
|
||||
4578. [security] Some chaining (CNAME or DNAME) responses to upstream
|
||||
|
||||
@@ -51,12 +51,17 @@ BIND 9
|
||||
For up-to-date release notes and errata, see
|
||||
http://www.isc.org/software/bind9/releasenotes
|
||||
|
||||
BIND 9.9.10-P1
|
||||
|
||||
This version contains a fix for the security flaws
|
||||
disclosed in CVE-2017-3140 and CVE-2017-3141.
|
||||
|
||||
BIND 9.9.10
|
||||
|
||||
BIND 9.9.10 is a maintenance release and addresses the security
|
||||
flaws disclosed in CVE-2016-2775, CVE-2016-2776, CVE-2016-6170,
|
||||
CVE-2016-8864, CVE-2016-9131, CVE-2016-9147, CVE-2016-9444,
|
||||
CVE-2017-3135, CVE-2017-3136, and CVE-2017-3137.
|
||||
CVE-2017-3135, CVE-2017-3136, CVE-2017-3137, and CVE-2017-3138.
|
||||
|
||||
BIND 9.9.9
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
.\" Copyright (C) 2004-2009, 2011, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\" Copyright (C) 2004-2009, 2011, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\" Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
.\"
|
||||
.\" Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -48,7 +48,7 @@
|
||||
dnssec-signzone \- DNSSEC zone signing tool
|
||||
.SH "SYNOPSIS"
|
||||
.HP \w'\fBdnssec\-signzone\fR\ 'u
|
||||
\fBdnssec\-signzone\fR [\fB\-a\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-d\ \fR\fB\fIdirectory\fR\fR] [\fB\-D\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-e\ \fR\fB\fIend\-time\fR\fR] [\fB\-f\ \fR\fB\fIoutput\-file\fR\fR] [\fB\-g\fR] [\fB\-h\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\ \fR\fB\fIkey\fR\fR] [\fB\-L\ \fR\fB\fIserial\fR\fR] [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-I\ \fR\fB\fIinput\-format\fR\fR] [\fB\-j\ \fR\fB\fIjitter\fR\fR] [\fB\-N\ \fR\fB\fIsoa\-serial\-format\fR\fR] [\fB\-o\ \fR\fB\fIorigin\fR\fR] [\fB\-O\ \fR\fB\fIoutput\-format\fR\fR] [\fB\-P\fR] [\fB\-p\fR] [\fB\-R\fR] [\fB\-r\ \fR\fB\fIrandomdev\fR\fR] [\fB\-S\fR] [\fB\-s\ \fR\fB\fIstart\-time\fR\fR] [\fB\-T\ \fR\fB\fIttl\fR\fR] [\fB\-t\fR] [\fB\-u\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-V\fR] [\fB\-X\ \fR\fB\fIextended\ end\-time\fR\fR] [\fB\-x\fR] [\fB\-z\fR] [\fB\-3\ \fR\fB\fIsalt\fR\fR] [\fB\-H\ \fR\fB\fIiterations\fR\fR] [\fB\-A\fR] {zonefile} [key...]
|
||||
\fBdnssec\-signzone\fR [\fB\-a\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-d\ \fR\fB\fIdirectory\fR\fR] [\fB\-D\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-e\ \fR\fB\fIend\-time\fR\fR] [\fB\-f\ \fR\fB\fIoutput\-file\fR\fR] [\fB\-g\fR] [\fB\-h\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-I\ \fR\fB\fIinput\-format\fR\fR] [\fB\-j\ \fR\fB\fIjitter\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\ \fR\fB\fIkey\fR\fR] [\fB\-L\ \fR\fB\fIserial\fR\fR] [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-N\ \fR\fB\fIsoa\-serial\-format\fR\fR] [\fB\-o\ \fR\fB\fIorigin\fR\fR] [\fB\-O\ \fR\fB\fIoutput\-format\fR\fR] [\fB\-P\fR] [\fB\-p\fR] [\fB\-R\fR] [\fB\-r\ \fR\fB\fIrandomdev\fR\fR] [\fB\-S\fR] [\fB\-s\ \fR\fB\fIstart\-time\fR\fR] [\fB\-T\ \fR\fB\fIttl\fR\fR] [\fB\-t\fR] [\fB\-u\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-V\fR] [\fB\-X\ \fR\fB\fIextended\ end\-time\fR\fR] [\fB\-x\fR] [\fB\-z\fR] [\fB\-3\ \fR\fB\fIsalt\fR\fR] [\fB\-H\ \fR\fB\fIiterations\fR\fR] [\fB\-A\fR] {zonefile} [key...]
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
\fBdnssec\-signzone\fR
|
||||
@@ -464,7 +464,7 @@ RFC 4641\&.
|
||||
\fBInternet Systems Consortium, Inc\&.\fR
|
||||
.SH "COPYRIGHT"
|
||||
.br
|
||||
Copyright \(co 2004-2009, 2011, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
Copyright \(co 2004-2009, 2011, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
Copyright \(co 2000-2003 Internet Software Consortium.
|
||||
.br
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
<!--
|
||||
- Copyright (C) 2004-2009, 2011, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2004-2009, 2011, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -49,6 +49,7 @@
|
||||
<year>2014</year>
|
||||
<year>2015</year>
|
||||
<year>2016</year>
|
||||
<year>2017</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
<copyright>
|
||||
@@ -72,13 +73,13 @@
|
||||
<arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">output-file</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-g</option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-h</option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-I <replaceable class="parameter">input-format</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-j <replaceable class="parameter">jitter</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-k <replaceable class="parameter">key</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-L <replaceable class="parameter">serial</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-I <replaceable class="parameter">input-format</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-j <replaceable class="parameter">jitter</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-N <replaceable class="parameter">soa-serial-format</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-o <replaceable class="parameter">origin</replaceable></option></arg>
|
||||
<arg choice="opt" rep="norepeat"><option>-O <replaceable class="parameter">output-format</replaceable></option></arg>
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||
<!--
|
||||
- Copyright (C) 2004-2009, 2011, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2004-2009, 2011, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
- Copyright (C) 2000-2003 Internet Software Consortium.
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -51,13 +51,13 @@
|
||||
[<code class="option">-f <em class="replaceable"><code>output-file</code></em></code>]
|
||||
[<code class="option">-g</code>]
|
||||
[<code class="option">-h</code>]
|
||||
[<code class="option">-i <em class="replaceable"><code>interval</code></em></code>]
|
||||
[<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>]
|
||||
[<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>]
|
||||
[<code class="option">-K <em class="replaceable"><code>directory</code></em></code>]
|
||||
[<code class="option">-k <em class="replaceable"><code>key</code></em></code>]
|
||||
[<code class="option">-L <em class="replaceable"><code>serial</code></em></code>]
|
||||
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
||||
[<code class="option">-i <em class="replaceable"><code>interval</code></em></code>]
|
||||
[<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>]
|
||||
[<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>]
|
||||
[<code class="option">-N <em class="replaceable"><code>soa-serial-format</code></em></code>]
|
||||
[<code class="option">-o <em class="replaceable"><code>origin</code></em></code>]
|
||||
[<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>]
|
||||
|
||||
+2
-2
@@ -7004,7 +7004,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
/*
|
||||
* If we have a zero ttl from the cache refetch it.
|
||||
*/
|
||||
if (!is_zone && event == NULL && rdataset->ttl == 0 &&
|
||||
if (!is_zone && !resuming && rdataset->ttl == 0 &&
|
||||
RECURSIONOK(client))
|
||||
{
|
||||
if (dns_rdataset_isassociated(rdataset))
|
||||
@@ -7426,7 +7426,7 @@ query_find(ns_client_t *client, dns_fetchevent_t *event, dns_rdatatype_t qtype)
|
||||
/*
|
||||
* If we have a zero ttl from the cache refetch it.
|
||||
*/
|
||||
if (!is_zone && event == NULL && rdataset->ttl == 0 &&
|
||||
if (!is_zone && !resuming && rdataset->ttl == 0 &&
|
||||
RECURSIONOK(client))
|
||||
{
|
||||
if (dns_rdataset_isassociated(rdataset))
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) 2011, 2012, 2014-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
# Copyright (C) 2011, 2012, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
@@ -329,5 +329,13 @@ grep "received control channel command 'null with extra arguments'" ns2/named.ru
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo "I:check 'rndc \"\"' is handled ($n)"
|
||||
ret=0
|
||||
$RNDCCMD "" > rndc.out.test$n 2>&1 && ret=1
|
||||
grep "rndc: '' failed: failure" rndc.out.test$n > /dev/null
|
||||
if [ $ret != 0 ]; then echo "I:failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo "I:exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Portions Copyright (C) 2004-2010, 2013-2016 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Portions Copyright (C) 2004-2010, 2013-2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Portions Copyright (C) 2001, 2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -59,6 +59,7 @@
|
||||
#include "DirBrowse.h"
|
||||
#include <winsvc.h>
|
||||
#include <shlobj.h>
|
||||
#include <shlwapi.h>
|
||||
#include <named/ntservice.h>
|
||||
#include <isc/bind_registry.h>
|
||||
#include <isc/ntgroups.h>
|
||||
@@ -615,8 +616,16 @@ void CBINDInstallDlg::OnInstall() {
|
||||
(LPBYTE)(LPCTSTR)buf, buf.GetLength());
|
||||
|
||||
buf.Format("%s\\BINDInstall.exe", m_binDir);
|
||||
|
||||
CStringA installLocA(buf);
|
||||
const char *str = (const char *) installLocA;
|
||||
char pathBuffer[2 * MAX_PATH];
|
||||
strncpy(pathBuffer, str, sizeof(pathBuffer) - 1);
|
||||
pathBuffer[sizeof(pathBuffer) - 1] = 0;
|
||||
PathQuoteSpaces(pathBuffer);
|
||||
|
||||
RegSetValueEx(hKey, "UninstallString", 0, REG_SZ,
|
||||
(LPBYTE)(LPCTSTR)buf, buf.GetLength());
|
||||
(LPBYTE)(LPCTSTR)pathBuffer, strlen(pathBuffer));
|
||||
RegCloseKey(hKey);
|
||||
}
|
||||
|
||||
@@ -1011,10 +1020,17 @@ CBINDInstallDlg::RegisterService() {
|
||||
CString namedLoc;
|
||||
namedLoc.Format("%s\\bin\\named.exe", m_targetDir);
|
||||
|
||||
CStringA namedLocA(namedLoc);
|
||||
const char *str = (const char *) namedLocA;
|
||||
char pathBuffer[2 * MAX_PATH];
|
||||
strncpy(pathBuffer, str, sizeof(pathBuffer) - 1);
|
||||
pathBuffer[sizeof(pathBuffer) - 1] = 0;
|
||||
PathQuoteSpaces(pathBuffer);
|
||||
|
||||
SetCurrent(IDS_CREATE_SERVICE);
|
||||
hService = CreateService(hSCManager, BIND_SERVICE_NAME,
|
||||
BIND_DISPLAY_NAME, SERVICE_ALL_ACCESS, dwServiceType, dwStart,
|
||||
SERVICE_ERROR_NORMAL, namedLoc, NULL, NULL, NULL, StartName,
|
||||
SERVICE_ERROR_NORMAL, pathBuffer, NULL, NULL, NULL, StartName,
|
||||
m_accountPassword);
|
||||
|
||||
if (!hService && GetLastError() != ERROR_SERVICE_EXISTS)
|
||||
@@ -1053,6 +1069,13 @@ CBINDInstallDlg::UpdateService(CString StartName) {
|
||||
CString namedLoc;
|
||||
namedLoc.Format("%s\\bin\\named.exe", m_targetDir);
|
||||
|
||||
CStringA namedLocA(namedLoc);
|
||||
const char *str = (const char *) namedLocA;
|
||||
char pathBuffer[2 * MAX_PATH];
|
||||
strncpy(pathBuffer, str, sizeof(pathBuffer) - 1);
|
||||
pathBuffer[sizeof(pathBuffer) - 1] = 0;
|
||||
PathQuoteSpaces(pathBuffer);
|
||||
|
||||
SetCurrent(IDS_OPEN_SERVICE);
|
||||
hService = OpenService(hSCManager, BIND_SERVICE_NAME,
|
||||
SERVICE_CHANGE_CONFIG);
|
||||
@@ -1064,7 +1087,7 @@ CBINDInstallDlg::UpdateService(CString StartName) {
|
||||
return;
|
||||
} else {
|
||||
if (ChangeServiceConfig(hService, dwServiceType, dwStart,
|
||||
SERVICE_ERROR_NORMAL, namedLoc, NULL, NULL, NULL,
|
||||
SERVICE_ERROR_NORMAL, pathBuffer, NULL, NULL, NULL,
|
||||
StartName, m_accountPassword, BIND_DISPLAY_NAME)
|
||||
!= TRUE) {
|
||||
DWORD err = GetLastError();
|
||||
|
||||
@@ -611,6 +611,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -160,6 +160,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -762,6 +762,6 @@ controls {
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -2131,6 +2131,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -146,6 +146,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -13199,6 +13199,6 @@ HOST-127.EXAMPLE. MX 0 .
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -262,6 +262,6 @@ zone "example.com" {
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -145,6 +145,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+16
-235
@@ -45,15 +45,12 @@
|
||||
<div class="toc">
|
||||
<p><b>Table of Contents</b></p>
|
||||
<dl class="toc">
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.9.10rc2</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.9.10-P1</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#root_key">New DNSSEC Root Key</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_maint">Maintenance</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_thanks">Thank You</a></span></dt>
|
||||
</dl></dd>
|
||||
@@ -61,21 +58,22 @@
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h2 class="title" style="clear: both">
|
||||
<a name="id-1.10.2"></a>Release Notes for BIND Version 9.9.10rc2</h2></div></div></div>
|
||||
<a name="id-1.10.2"></a>Release Notes for BIND Version 9.9.10-P1</h2></div></div></div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_intro"></a>Introduction</h3></div></div></div>
|
||||
<p>
|
||||
This document summarizes significant changes since the last
|
||||
production release of BIND on the corresponding major release
|
||||
branch.
|
||||
Please see the CHANGES file for a further list of bug fixes and
|
||||
other changes.
|
||||
This document summarizes changes since BIND 9.9.10:
|
||||
</p>
|
||||
<p>
|
||||
BIND 9.9.10-P1 addresses the security issues described in
|
||||
CVE-2017-3140 and CVE-2017-3141.
|
||||
</p>
|
||||
|
||||
</div>
|
||||
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_download"></a>Download</h3></div></div></div>
|
||||
@@ -124,83 +122,17 @@
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Some chaining (i.e., type CNAME or DNAME) responses to upstream
|
||||
queries could trigger assertion failures. This flaw is disclosed
|
||||
in CVE-2017-3137. [RT #44734]
|
||||
The BIND installer on Windows used an unquoted service path,
|
||||
which can enable privilege escalation. This flaw is disclosed
|
||||
in CVE-2017-3141. [RT #45229]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>dns64</strong></span> with <span class="command"><strong>break-dnssec yes;</strong></span>
|
||||
can result in an assertion failure. This flaw is disclosed in
|
||||
CVE-2017-3136. [RT #44653]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
If a server is configured with a response policy zone (RPZ)
|
||||
that rewrites an answer with local data, and is also configured
|
||||
for DNS64 address mapping, a NULL pointer can be read
|
||||
triggering a server crash. This flaw is disclosed in
|
||||
CVE-2017-3135. [RT #44434]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> could mishandle authority sections
|
||||
with missing RRSIGs, triggering an assertion failure. This
|
||||
flaw is disclosed in CVE-2016-9444. [RT #43632]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> mishandled some responses where
|
||||
covering RRSIG records were returned without the requested
|
||||
data, resulting in an assertion failure. This flaw is
|
||||
disclosed in CVE-2016-9147. [RT #43548]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> incorrectly tried to cache TKEY
|
||||
records which could trigger an assertion failure when there was
|
||||
a class mismatch. This flaw is disclosed in CVE-2016-9131.
|
||||
[RT #43522]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
It was possible to trigger assertions when processing
|
||||
responses containing answers of type DNAME. This flaw is
|
||||
disclosed in CVE-2016-8864. [RT #43465]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Added the ability to specify the maximum number of records
|
||||
permitted in a zone (<code class="option">max-records #;</code>).
|
||||
This provides a mechanism to block overly large zone
|
||||
transfers, which is a potential risk with slave zones from
|
||||
other parties, as described in CVE-2016-6170.
|
||||
[RT #42143]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
It was possible to trigger an assertion when rendering a
|
||||
message using a specially crafted request. This flaw is
|
||||
disclosed in CVE-2016-2776. [RT #43139]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Calling <span class="command"><strong>getrrsetbyname()</strong></span> with a non-
|
||||
absolute name could trigger an infinite recursion bug in
|
||||
<span class="command"><strong>lwresd</strong></span> or <span class="command"><strong>named</strong></span> with
|
||||
<span class="command"><strong>lwres</strong></span> configured if, when combined with
|
||||
a search list entry from <code class="filename">resolv.conf</code>,
|
||||
the resulting name is too long. This flaw is disclosed in
|
||||
CVE-2016-2775. [RT #42694]
|
||||
With certain RPZ configurations, a response with TTL 0
|
||||
could cause <span class="command"><strong>named</strong></span> to go into an infinite
|
||||
query loop. This flaw is disclosed in CVE-2017-3140.
|
||||
[RT #45181]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
@@ -208,157 +140,6 @@
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The ISC DNSSEC Lookaside Validation (DLV) service is scheduled
|
||||
to be disabled in 2017. A warning is now logged when
|
||||
<span class="command"><strong>named</strong></span> is configured to use this service,
|
||||
either explicitly or via <code class="option">dnssec-lookaside auto;</code>.
|
||||
[RT #42207]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
If an ACL is specified with an address prefix in which the
|
||||
prefix length is longer than the address portion (for example,
|
||||
192.0.2.1/8), <span class="command"><strong>named</strong></span> will now log a warning.
|
||||
In future releases this will be a fatal configuration error.
|
||||
[RT #43367]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
A synthesized CNAME record appearing in a response before the
|
||||
associated DNAME could be cached, when it should not have been.
|
||||
This was a regression introduced while addressing CVE-2016-8864.
|
||||
[RT #44318]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> could deadlock if multiple changes
|
||||
to NSEC/NSEC3 parameters for the same zone were being processed
|
||||
at the same time. [RT #42770]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> could trigger an assertion when
|
||||
sending NOTIFY messages. [RT #44019]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Windows installs were failing due to triggering UAC without
|
||||
the installation binary being signed.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
A change in the internal binary representation of the RBT database
|
||||
node structure enabled a race condition to occur (especially when
|
||||
BIND was built with certain compilers or optimizer settings),
|
||||
leading to inconsistent database state which caused random
|
||||
assertion failures. [RT #42380]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Referencing a nonexistent zone in a <span class="command"><strong>response-policy</strong></span>
|
||||
statement could cause an assertion failure during configuration.
|
||||
[RT #43787]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>rndc addzone</strong></span> could cause a crash
|
||||
when attempting to add a zone with a type other than
|
||||
<span class="command"><strong>master</strong></span> or <span class="command"><strong>slave</strong></span>.
|
||||
Such zones are now rejected. [RT #43665]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> could hang when encountering log
|
||||
file names with large apparent gaps in version number (for
|
||||
example, when files exist called "logfile.0", "logfile.1",
|
||||
and "logfile.1482954169"). This is now handled correctly.
|
||||
[RT #38688]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
If a zone was updated while <span class="command"><strong>named</strong></span> was
|
||||
processing a query for nonexistent data, it could return
|
||||
out-of-sync NSEC3 records causing potential DNSSEC validation
|
||||
failure. [RT #43247]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> could crash when loading a zone
|
||||
which had RRISG records whose expiry fields were far enough
|
||||
apart to cause an integer overflow when comparing them.
|
||||
[RT #40571]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The <span class="command"><strong>arpaname</strong></span> command was not installed into
|
||||
the correct <span class="command"><strong>prefix</strong></span><code class="filename">/bin</code>
|
||||
directory. [RT #42910]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
When receiving a response from an authoritative server with
|
||||
a TTL value of zero, <span class="command"><strong>named></strong></span> will now only use
|
||||
that response once, to answer the currently active clients that
|
||||
were waiting for it. Previously, such response could be cached
|
||||
and reused for up to one second. [RT #42142]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Corrected a bug in the <span class="command"><strong>rndc</strong></span> control channel
|
||||
that could allow a read past the end of a buffer, crashing
|
||||
<span class="command"><strong>named</strong></span>. Thanks to Lian Yihan for reporting
|
||||
this error.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Reverted a change to the query logging format that was
|
||||
inadvertently backported from the 9.11 branch. [RT #43238]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_maint"></a>Maintenance</h3></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
|
||||
<p>
|
||||
The built-in root hints have been updated to include
|
||||
IPv6 addresses for B.ROOT-SERVERS.NET (2001:500:84::b),
|
||||
E.ROOT-SERVERS.NET (2001:500:a8::e) and
|
||||
G.ROOT-SERVERS.NET (2001:500:12::d0d).
|
||||
</p>
|
||||
</li></ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="end_of_life"></a>End of Life</h3></div></div></div>
|
||||
<p>
|
||||
BIND 9.9 (Extended Support Version) will be supported until
|
||||
@@ -397,6 +178,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -157,6 +157,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -923,6 +923,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -580,6 +580,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -176,6 +176,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+3
-6
@@ -41,7 +41,7 @@
|
||||
<div>
|
||||
<div><h1 class="title">
|
||||
<a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
|
||||
<div><p class="releaseinfo">BIND Version 9.9.10rc2</p></div>
|
||||
<div><p class="releaseinfo">BIND Version 9.9.10-P1</p></div>
|
||||
<div><p class="copyright">Copyright © 2004-2016 Internet Systems Consortium, Inc. ("ISC")</p></div>
|
||||
<div><p class="copyright">Copyright © 2000-2003 Internet Software Consortium.</p></div>
|
||||
</div>
|
||||
@@ -234,15 +234,12 @@
|
||||
</dl></dd>
|
||||
<dt><span class="appendix"><a href="Bv9ARM.ch09.html">A. Release Notes</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.9.10rc2</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.9.10-P1</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#root_key">New DNSSEC Root Key</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_maint">Maintenance</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_thanks">Thank You</a></span></dt>
|
||||
</dl></dd>
|
||||
@@ -401,6 +398,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
Binary file not shown.
@@ -100,6 +100,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -224,6 +224,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -950,6 +950,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -160,6 +160,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -250,6 +250,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -298,6 +298,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -241,6 +241,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -454,6 +454,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -567,6 +567,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -172,6 +172,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -330,6 +330,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -69,13 +69,13 @@
|
||||
[<code class="option">-f <em class="replaceable"><code>output-file</code></em></code>]
|
||||
[<code class="option">-g</code>]
|
||||
[<code class="option">-h</code>]
|
||||
[<code class="option">-i <em class="replaceable"><code>interval</code></em></code>]
|
||||
[<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>]
|
||||
[<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>]
|
||||
[<code class="option">-K <em class="replaceable"><code>directory</code></em></code>]
|
||||
[<code class="option">-k <em class="replaceable"><code>key</code></em></code>]
|
||||
[<code class="option">-L <em class="replaceable"><code>serial</code></em></code>]
|
||||
[<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
|
||||
[<code class="option">-i <em class="replaceable"><code>interval</code></em></code>]
|
||||
[<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>]
|
||||
[<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>]
|
||||
[<code class="option">-N <em class="replaceable"><code>soa-serial-format</code></em></code>]
|
||||
[<code class="option">-o <em class="replaceable"><code>origin</code></em></code>]
|
||||
[<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>]
|
||||
@@ -684,6 +684,6 @@ db.example.com.signed
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -197,6 +197,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -136,6 +136,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -363,6 +363,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -135,6 +135,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -336,6 +336,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -201,6 +201,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -447,6 +447,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -126,6 +126,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -731,6 +731,6 @@ zone
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -457,6 +457,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -136,6 +136,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -774,6 +774,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -275,6 +275,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -276,6 +276,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -676,6 +676,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10rc2 (Extended Support Version)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+14
-230
@@ -23,21 +23,22 @@
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h2 class="title" style="clear: both">
|
||||
<a name="id-1.2"></a>Release Notes for BIND Version 9.9.10rc2</h2></div></div></div>
|
||||
<a name="id-1.2"></a>Release Notes for BIND Version 9.9.10-P1</h2></div></div></div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_intro"></a>Introduction</h3></div></div></div>
|
||||
<p>
|
||||
This document summarizes significant changes since the last
|
||||
production release of BIND on the corresponding major release
|
||||
branch.
|
||||
Please see the CHANGES file for a further list of bug fixes and
|
||||
other changes.
|
||||
This document summarizes changes since BIND 9.9.10:
|
||||
</p>
|
||||
<p>
|
||||
BIND 9.9.10-P1 addresses the security issues described in
|
||||
CVE-2017-3140 and CVE-2017-3141.
|
||||
</p>
|
||||
|
||||
</div>
|
||||
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_download"></a>Download</h3></div></div></div>
|
||||
@@ -86,83 +87,17 @@
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Some chaining (i.e., type CNAME or DNAME) responses to upstream
|
||||
queries could trigger assertion failures. This flaw is disclosed
|
||||
in CVE-2017-3137. [RT #44734]
|
||||
The BIND installer on Windows used an unquoted service path,
|
||||
which can enable privilege escalation. This flaw is disclosed
|
||||
in CVE-2017-3141. [RT #45229]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>dns64</strong></span> with <span class="command"><strong>break-dnssec yes;</strong></span>
|
||||
can result in an assertion failure. This flaw is disclosed in
|
||||
CVE-2017-3136. [RT #44653]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
If a server is configured with a response policy zone (RPZ)
|
||||
that rewrites an answer with local data, and is also configured
|
||||
for DNS64 address mapping, a NULL pointer can be read
|
||||
triggering a server crash. This flaw is disclosed in
|
||||
CVE-2017-3135. [RT #44434]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> could mishandle authority sections
|
||||
with missing RRSIGs, triggering an assertion failure. This
|
||||
flaw is disclosed in CVE-2016-9444. [RT #43632]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> mishandled some responses where
|
||||
covering RRSIG records were returned without the requested
|
||||
data, resulting in an assertion failure. This flaw is
|
||||
disclosed in CVE-2016-9147. [RT #43548]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> incorrectly tried to cache TKEY
|
||||
records which could trigger an assertion failure when there was
|
||||
a class mismatch. This flaw is disclosed in CVE-2016-9131.
|
||||
[RT #43522]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
It was possible to trigger assertions when processing
|
||||
responses containing answers of type DNAME. This flaw is
|
||||
disclosed in CVE-2016-8864. [RT #43465]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Added the ability to specify the maximum number of records
|
||||
permitted in a zone (<code class="option">max-records #;</code>).
|
||||
This provides a mechanism to block overly large zone
|
||||
transfers, which is a potential risk with slave zones from
|
||||
other parties, as described in CVE-2016-6170.
|
||||
[RT #42143]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
It was possible to trigger an assertion when rendering a
|
||||
message using a specially crafted request. This flaw is
|
||||
disclosed in CVE-2016-2776. [RT #43139]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Calling <span class="command"><strong>getrrsetbyname()</strong></span> with a non-
|
||||
absolute name could trigger an infinite recursion bug in
|
||||
<span class="command"><strong>lwresd</strong></span> or <span class="command"><strong>named</strong></span> with
|
||||
<span class="command"><strong>lwres</strong></span> configured if, when combined with
|
||||
a search list entry from <code class="filename">resolv.conf</code>,
|
||||
the resulting name is too long. This flaw is disclosed in
|
||||
CVE-2016-2775. [RT #42694]
|
||||
With certain RPZ configurations, a response with TTL 0
|
||||
could cause <span class="command"><strong>named</strong></span> to go into an infinite
|
||||
query loop. This flaw is disclosed in CVE-2017-3140.
|
||||
[RT #45181]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
@@ -170,157 +105,6 @@
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The ISC DNSSEC Lookaside Validation (DLV) service is scheduled
|
||||
to be disabled in 2017. A warning is now logged when
|
||||
<span class="command"><strong>named</strong></span> is configured to use this service,
|
||||
either explicitly or via <code class="option">dnssec-lookaside auto;</code>.
|
||||
[RT #42207]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
If an ACL is specified with an address prefix in which the
|
||||
prefix length is longer than the address portion (for example,
|
||||
192.0.2.1/8), <span class="command"><strong>named</strong></span> will now log a warning.
|
||||
In future releases this will be a fatal configuration error.
|
||||
[RT #43367]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
A synthesized CNAME record appearing in a response before the
|
||||
associated DNAME could be cached, when it should not have been.
|
||||
This was a regression introduced while addressing CVE-2016-8864.
|
||||
[RT #44318]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> could deadlock if multiple changes
|
||||
to NSEC/NSEC3 parameters for the same zone were being processed
|
||||
at the same time. [RT #42770]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> could trigger an assertion when
|
||||
sending NOTIFY messages. [RT #44019]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Windows installs were failing due to triggering UAC without
|
||||
the installation binary being signed.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
A change in the internal binary representation of the RBT database
|
||||
node structure enabled a race condition to occur (especially when
|
||||
BIND was built with certain compilers or optimizer settings),
|
||||
leading to inconsistent database state which caused random
|
||||
assertion failures. [RT #42380]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Referencing a nonexistent zone in a <span class="command"><strong>response-policy</strong></span>
|
||||
statement could cause an assertion failure during configuration.
|
||||
[RT #43787]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>rndc addzone</strong></span> could cause a crash
|
||||
when attempting to add a zone with a type other than
|
||||
<span class="command"><strong>master</strong></span> or <span class="command"><strong>slave</strong></span>.
|
||||
Such zones are now rejected. [RT #43665]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> could hang when encountering log
|
||||
file names with large apparent gaps in version number (for
|
||||
example, when files exist called "logfile.0", "logfile.1",
|
||||
and "logfile.1482954169"). This is now handled correctly.
|
||||
[RT #38688]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
If a zone was updated while <span class="command"><strong>named</strong></span> was
|
||||
processing a query for nonexistent data, it could return
|
||||
out-of-sync NSEC3 records causing potential DNSSEC validation
|
||||
failure. [RT #43247]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> could crash when loading a zone
|
||||
which had RRISG records whose expiry fields were far enough
|
||||
apart to cause an integer overflow when comparing them.
|
||||
[RT #40571]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The <span class="command"><strong>arpaname</strong></span> command was not installed into
|
||||
the correct <span class="command"><strong>prefix</strong></span><code class="filename">/bin</code>
|
||||
directory. [RT #42910]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
When receiving a response from an authoritative server with
|
||||
a TTL value of zero, <span class="command"><strong>named></strong></span> will now only use
|
||||
that response once, to answer the currently active clients that
|
||||
were waiting for it. Previously, such response could be cached
|
||||
and reused for up to one second. [RT #42142]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Corrected a bug in the <span class="command"><strong>rndc</strong></span> control channel
|
||||
that could allow a read past the end of a buffer, crashing
|
||||
<span class="command"><strong>named</strong></span>. Thanks to Lian Yihan for reporting
|
||||
this error.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Reverted a change to the query logging format that was
|
||||
inadvertently backported from the 9.11 branch. [RT #43238]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_maint"></a>Maintenance</h3></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
|
||||
<p>
|
||||
The built-in root hints have been updated to include
|
||||
IPv6 addresses for B.ROOT-SERVERS.NET (2001:500:84::b),
|
||||
E.ROOT-SERVERS.NET (2001:500:a8::e) and
|
||||
G.ROOT-SERVERS.NET (2001:500:12::d0d).
|
||||
</p>
|
||||
</li></ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="end_of_life"></a>End of Life</h3></div></div></div>
|
||||
<p>
|
||||
BIND 9.9 (Extended Support Version) will be supported until
|
||||
|
||||
Binary file not shown.
+13
-225
@@ -21,15 +21,16 @@
|
||||
<xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="noteversion.xml"/>
|
||||
<section xml:id="relnotes_intro"><info><title>Introduction</title></info>
|
||||
<para>
|
||||
This document summarizes significant changes since the last
|
||||
production release of BIND on the corresponding major release
|
||||
branch.
|
||||
Please see the CHANGES file for a further list of bug fixes and
|
||||
other changes.
|
||||
This document summarizes changes since BIND 9.9.10:
|
||||
</para>
|
||||
<para>
|
||||
BIND 9.9.10-P1 addresses the security issues described in
|
||||
CVE-2017-3140 and CVE-2017-3141.
|
||||
</para>
|
||||
|
||||
</section>
|
||||
|
||||
|
||||
<section xml:id="relnotes_download"><info><title>Download</title></info>
|
||||
<para>
|
||||
The latest versions of BIND 9 software can always be found at
|
||||
@@ -73,230 +74,17 @@
|
||||
<itemizedlist>
|
||||
<listitem>
|
||||
<para>
|
||||
Some chaining (i.e., type CNAME or DNAME) responses to upstream
|
||||
queries could trigger assertion failures. This flaw is disclosed
|
||||
in CVE-2017-3137. [RT #44734]
|
||||
The BIND installer on Windows used an unquoted service path,
|
||||
which can enable privilege escalation. This flaw is disclosed
|
||||
in CVE-2017-3141. [RT #45229]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
<command>dns64</command> with <command>break-dnssec yes;</command>
|
||||
can result in an assertion failure. This flaw is disclosed in
|
||||
CVE-2017-3136. [RT #44653]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
If a server is configured with a response policy zone (RPZ)
|
||||
that rewrites an answer with local data, and is also configured
|
||||
for DNS64 address mapping, a NULL pointer can be read
|
||||
triggering a server crash. This flaw is disclosed in
|
||||
CVE-2017-3135. [RT #44434]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
<command>named</command> could mishandle authority sections
|
||||
with missing RRSIGs, triggering an assertion failure. This
|
||||
flaw is disclosed in CVE-2016-9444. [RT #43632]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
<command>named</command> mishandled some responses where
|
||||
covering RRSIG records were returned without the requested
|
||||
data, resulting in an assertion failure. This flaw is
|
||||
disclosed in CVE-2016-9147. [RT #43548]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
<command>named</command> incorrectly tried to cache TKEY
|
||||
records which could trigger an assertion failure when there was
|
||||
a class mismatch. This flaw is disclosed in CVE-2016-9131.
|
||||
[RT #43522]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
It was possible to trigger assertions when processing
|
||||
responses containing answers of type DNAME. This flaw is
|
||||
disclosed in CVE-2016-8864. [RT #43465]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
Added the ability to specify the maximum number of records
|
||||
permitted in a zone (<option>max-records #;</option>).
|
||||
This provides a mechanism to block overly large zone
|
||||
transfers, which is a potential risk with slave zones from
|
||||
other parties, as described in CVE-2016-6170.
|
||||
[RT #42143]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
It was possible to trigger an assertion when rendering a
|
||||
message using a specially crafted request. This flaw is
|
||||
disclosed in CVE-2016-2776. [RT #43139]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
Calling <command>getrrsetbyname()</command> with a non-
|
||||
absolute name could trigger an infinite recursion bug in
|
||||
<command>lwresd</command> or <command>named</command> with
|
||||
<command>lwres</command> configured if, when combined with
|
||||
a search list entry from <filename>resolv.conf</filename>,
|
||||
the resulting name is too long. This flaw is disclosed in
|
||||
CVE-2016-2775. [RT #42694]
|
||||
</para>
|
||||
</listitem>
|
||||
</itemizedlist>
|
||||
</section>
|
||||
|
||||
<section xml:id="relnotes_changes"><info><title>Feature Changes</title></info>
|
||||
<itemizedlist>
|
||||
<listitem>
|
||||
<para>
|
||||
The ISC DNSSEC Lookaside Validation (DLV) service is scheduled
|
||||
to be disabled in 2017. A warning is now logged when
|
||||
<command>named</command> is configured to use this service,
|
||||
either explicitly or via <option>dnssec-lookaside auto;</option>.
|
||||
[RT #42207]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
If an ACL is specified with an address prefix in which the
|
||||
prefix length is longer than the address portion (for example,
|
||||
192.0.2.1/8), <command>named</command> will now log a warning.
|
||||
In future releases this will be a fatal configuration error.
|
||||
[RT #43367]
|
||||
</para>
|
||||
</listitem>
|
||||
</itemizedlist>
|
||||
</section>
|
||||
|
||||
<section xml:id="relnotes_bugs"><info><title>Bug Fixes</title></info>
|
||||
<itemizedlist>
|
||||
<listitem>
|
||||
<para>
|
||||
A synthesized CNAME record appearing in a response before the
|
||||
associated DNAME could be cached, when it should not have been.
|
||||
This was a regression introduced while addressing CVE-2016-8864.
|
||||
[RT #44318]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
<command>named</command> could deadlock if multiple changes
|
||||
to NSEC/NSEC3 parameters for the same zone were being processed
|
||||
at the same time. [RT #42770]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
<command>named</command> could trigger an assertion when
|
||||
sending NOTIFY messages. [RT #44019]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
Windows installs were failing due to triggering UAC without
|
||||
the installation binary being signed.
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
A change in the internal binary representation of the RBT database
|
||||
node structure enabled a race condition to occur (especially when
|
||||
BIND was built with certain compilers or optimizer settings),
|
||||
leading to inconsistent database state which caused random
|
||||
assertion failures. [RT #42380]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
Referencing a nonexistent zone in a <command>response-policy</command>
|
||||
statement could cause an assertion failure during configuration.
|
||||
[RT #43787]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
<command>rndc addzone</command> could cause a crash
|
||||
when attempting to add a zone with a type other than
|
||||
<command>master</command> or <command>slave</command>.
|
||||
Such zones are now rejected. [RT #43665]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
<command>named</command> could hang when encountering log
|
||||
file names with large apparent gaps in version number (for
|
||||
example, when files exist called "logfile.0", "logfile.1",
|
||||
and "logfile.1482954169"). This is now handled correctly.
|
||||
[RT #38688]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
If a zone was updated while <command>named</command> was
|
||||
processing a query for nonexistent data, it could return
|
||||
out-of-sync NSEC3 records causing potential DNSSEC validation
|
||||
failure. [RT #43247]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
<command>named</command> could crash when loading a zone
|
||||
which had RRISG records whose expiry fields were far enough
|
||||
apart to cause an integer overflow when comparing them.
|
||||
[RT #40571]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
The <command>arpaname</command> command was not installed into
|
||||
the correct <command>prefix</command><filename>/bin</filename>
|
||||
directory. [RT #42910]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
When receiving a response from an authoritative server with
|
||||
a TTL value of zero, <command>named></command> will now only use
|
||||
that response once, to answer the currently active clients that
|
||||
were waiting for it. Previously, such response could be cached
|
||||
and reused for up to one second. [RT #42142]
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
Corrected a bug in the <command>rndc</command> control channel
|
||||
that could allow a read past the end of a buffer, crashing
|
||||
<command>named</command>. Thanks to Lian Yihan for reporting
|
||||
this error.
|
||||
</para>
|
||||
</listitem>
|
||||
<listitem>
|
||||
<para>
|
||||
Reverted a change to the query logging format that was
|
||||
inadvertently backported from the 9.11 branch. [RT #43238]
|
||||
</para>
|
||||
</listitem>
|
||||
</itemizedlist>
|
||||
</section>
|
||||
|
||||
<section xml:id="relnotes_maint"><info><title>Maintenance</title></info>
|
||||
<itemizedlist>
|
||||
<listitem>
|
||||
<para>
|
||||
The built-in root hints have been updated to include
|
||||
IPv6 addresses for B.ROOT-SERVERS.NET (2001:500:84::b),
|
||||
E.ROOT-SERVERS.NET (2001:500:a8::e) and
|
||||
G.ROOT-SERVERS.NET (2001:500:12::d0d).
|
||||
With certain RPZ configurations, a response with TTL 0
|
||||
could cause <command>named</command> to go into an infinite
|
||||
query loop. This flaw is disclosed in CVE-2017-3140.
|
||||
[RT #45181]
|
||||
</para>
|
||||
</listitem>
|
||||
</itemizedlist>
|
||||
|
||||
+1
-1
@@ -7,5 +7,5 @@
|
||||
# 9.10: 140-149, 170-179
|
||||
# 9.11: 160-169
|
||||
LIBINTERFACE = 173
|
||||
LIBREVISION = 1
|
||||
LIBREVISION = 2
|
||||
LIBAGE = 0
|
||||
|
||||
+23
-16
@@ -5875,7 +5875,7 @@ is_answeraddress_allowed(dns_view_t *view, dns_name_t *name,
|
||||
|
||||
static isc_boolean_t
|
||||
is_answertarget_allowed(fetchctx_t *fctx, dns_name_t *qname, dns_name_t *rname,
|
||||
dns_rdataset_t *rdataset)
|
||||
dns_rdataset_t *rdataset, isc_boolean_t *chainingp)
|
||||
{
|
||||
isc_result_t result;
|
||||
dns_rbtnode_t *node = NULL;
|
||||
@@ -5896,8 +5896,11 @@ is_answertarget_allowed(fetchctx_t *fctx, dns_name_t *qname, dns_name_t *rname,
|
||||
REQUIRE(rdataset->type == dns_rdatatype_cname ||
|
||||
rdataset->type == dns_rdatatype_dname);
|
||||
|
||||
/* By default, we allow any target name. */
|
||||
if (view->denyanswernames == NULL)
|
||||
/*
|
||||
* By default, we allow any target name.
|
||||
* If newqname != NULL we also need to extract the newqname.
|
||||
*/
|
||||
if (chainingp == NULL && view->denyanswernames == NULL)
|
||||
return (ISC_TRUE);
|
||||
|
||||
result = dns_rdataset_first(rdataset);
|
||||
@@ -5920,7 +5923,7 @@ is_answertarget_allowed(fetchctx_t *fctx, dns_name_t *qname, dns_name_t *rname,
|
||||
dns_name_split(qname, nlabels, &prefix, NULL);
|
||||
result = dns_name_concatenate(&prefix, &dname.dname, tname,
|
||||
NULL);
|
||||
if (result == ISC_R_NOSPACE)
|
||||
if (result == DNS_R_NAMETOOLONG)
|
||||
return (ISC_TRUE);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
break;
|
||||
@@ -5928,6 +5931,12 @@ is_answertarget_allowed(fetchctx_t *fctx, dns_name_t *qname, dns_name_t *rname,
|
||||
INSIST(0);
|
||||
}
|
||||
|
||||
if (chainingp != NULL)
|
||||
*chainingp = ISC_TRUE;
|
||||
|
||||
if (view->denyanswernames == NULL)
|
||||
return (ISC_TRUE);
|
||||
|
||||
/*
|
||||
* If the owner name matches one in the exclusion list, either exactly
|
||||
* or partially, allow it.
|
||||
@@ -6621,7 +6630,7 @@ answer_response(fetchctx_t *fctx) {
|
||||
if ((rdataset->type == dns_rdatatype_cname ||
|
||||
rdataset->type == dns_rdatatype_dname) &&
|
||||
!is_answertarget_allowed(fctx, qname, aname,
|
||||
rdataset))
|
||||
rdataset, NULL))
|
||||
{
|
||||
return (DNS_R_SERVFAIL);
|
||||
}
|
||||
@@ -6644,7 +6653,9 @@ answer_response(fetchctx_t *fctx) {
|
||||
}
|
||||
if ((ardataset->type == dns_rdatatype_cname ||
|
||||
ardataset->type == dns_rdatatype_dname) &&
|
||||
!is_answertarget_allowed(fctx, qname, aname, ardataset)) {
|
||||
!is_answertarget_allowed(fctx, qname, aname, ardataset,
|
||||
NULL))
|
||||
{
|
||||
return (DNS_R_SERVFAIL);
|
||||
}
|
||||
aname->attributes |= DNS_NAMEATTR_CACHE;
|
||||
@@ -6679,7 +6690,9 @@ answer_response(fetchctx_t *fctx) {
|
||||
log_formerr(fctx, "CNAME response for %s RR", buf);
|
||||
return (DNS_R_FORMERR);
|
||||
}
|
||||
if (!is_answertarget_allowed(fctx, qname, cname, crdataset)) {
|
||||
if (!is_answertarget_allowed(fctx, qname, cname, crdataset,
|
||||
NULL))
|
||||
{
|
||||
return (DNS_R_SERVFAIL);
|
||||
}
|
||||
cname->attributes |= DNS_NAMEATTR_CACHE;
|
||||
@@ -6711,7 +6724,8 @@ answer_response(fetchctx_t *fctx) {
|
||||
if (!validinanswer(drdataset, fctx)) {
|
||||
return (DNS_R_FORMERR);
|
||||
}
|
||||
if (!is_answertarget_allowed(fctx, qname, dname, drdataset)) {
|
||||
if (!is_answertarget_allowed(fctx, qname, dname, drdataset,
|
||||
&chaining)) {
|
||||
return (DNS_R_SERVFAIL);
|
||||
}
|
||||
dname->attributes |= DNS_NAMEATTR_CACHE;
|
||||
@@ -6738,7 +6752,6 @@ answer_response(fetchctx_t *fctx) {
|
||||
sigrdataset->trust = trust;
|
||||
break;
|
||||
}
|
||||
chaining = ISC_TRUE;
|
||||
} else {
|
||||
log_formerr(fctx, "reply has no answer");
|
||||
return (DNS_R_FORMERR);
|
||||
@@ -6753,13 +6766,7 @@ answer_response(fetchctx_t *fctx) {
|
||||
* Did chaining end before we got the final answer?
|
||||
*/
|
||||
if (chaining) {
|
||||
/*
|
||||
* Yes. This may be a negative reply, so hand off
|
||||
* authority section processing to the noanswer code.
|
||||
* If it isn't a noanswer response, no harm will be
|
||||
* done.
|
||||
*/
|
||||
return (noanswer_response(fctx, qname, 0));
|
||||
return (ISC_R_SUCCESS);
|
||||
}
|
||||
|
||||
/*
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005, 2007, 2008 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2005, 2007, 2008, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1998-2002 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -152,8 +152,6 @@ isc_lex_create(isc_mem_t *mctx, size_t max_token, isc_lex_t **lexp);
|
||||
* Requires:
|
||||
*\li '*lexp' is a valid lexer.
|
||||
*
|
||||
*\li max_token > 0.
|
||||
*
|
||||
* Ensures:
|
||||
*\li On success, *lexp is attached to the newly created lexer.
|
||||
*
|
||||
|
||||
+4
-3
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005, 2007, 2013-2015 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 2004, 2005, 2007, 2013-2015, 2017 Internet Systems Consortium, Inc. ("ISC")
|
||||
* Copyright (C) 1998-2003 Internet Software Consortium.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
@@ -94,9 +94,10 @@ isc_lex_create(isc_mem_t *mctx, size_t max_token, isc_lex_t **lexp) {
|
||||
/*
|
||||
* Create a lexer.
|
||||
*/
|
||||
|
||||
REQUIRE(lexp != NULL && *lexp == NULL);
|
||||
REQUIRE(max_token > 0U);
|
||||
|
||||
if (max_token == 0U)
|
||||
max_token = 1;
|
||||
|
||||
lex = isc_mem_get(mctx, sizeof(*lex));
|
||||
if (lex == NULL)
|
||||
|
||||
+5
-5
@@ -143,7 +143,7 @@
|
||||
./bin/dnssec/dnssec-settime.html HTML DOCBOOK
|
||||
./bin/dnssec/dnssec-signzone.8 MAN DOCBOOK
|
||||
./bin/dnssec/dnssec-signzone.c C.NAI 1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010,2011,2012,2013,2014,2015,2016
|
||||
./bin/dnssec/dnssec-signzone.docbook SGML 2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2011,2013,2014,2015,2016
|
||||
./bin/dnssec/dnssec-signzone.docbook SGML 2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2011,2013,2014,2015,2016,2017
|
||||
./bin/dnssec/dnssec-signzone.html HTML DOCBOOK
|
||||
./bin/dnssec/dnssec-verify.8 MAN DOCBOOK
|
||||
./bin/dnssec/dnssec-verify.c C 2012,2014,2015
|
||||
@@ -1622,7 +1622,7 @@
|
||||
./bin/tests/system/rndc/ns3/named.conf CONF-C 2012,2013
|
||||
./bin/tests/system/rndc/ns4/named.conf CONF-C 2015
|
||||
./bin/tests/system/rndc/setup.sh SH 2011,2012,2014
|
||||
./bin/tests/system/rndc/tests.sh SH 2011,2012,2014,2015,2016
|
||||
./bin/tests/system/rndc/tests.sh SH 2011,2012,2014,2015,2016,2017
|
||||
./bin/tests/system/rpz/clean.sh SH 2011,2012,2013,2014
|
||||
./bin/tests/system/rpz/ns1/named.conf CONF-C 2011,2013
|
||||
./bin/tests/system/rpz/ns1/root.db ZONE 2011,2012,2013
|
||||
@@ -2148,7 +2148,7 @@
|
||||
./bin/win32/BINDInstall/BINDInstall.vcxproj.filters.in X 2013,2015
|
||||
./bin/win32/BINDInstall/BINDInstall.vcxproj.in X 2013,2015,2016
|
||||
./bin/win32/BINDInstall/BINDInstall.vcxproj.user X 2013
|
||||
./bin/win32/BINDInstall/BINDInstallDlg.cpp C.PORTION 2001,2003,2004,2005,2006,2007,2008,2009,2010,2013,2014,2015,2016
|
||||
./bin/win32/BINDInstall/BINDInstallDlg.cpp C.PORTION 2001,2003,2004,2005,2006,2007,2008,2009,2010,2013,2014,2015,2016,2017
|
||||
./bin/win32/BINDInstall/BINDInstallDlg.h C.PORTION 2001,2004,2007,2009,2015
|
||||
./bin/win32/BINDInstall/DirBrowse.cpp C.PORTION 2001,2004,2007
|
||||
./bin/win32/BINDInstall/DirBrowse.h C.PORTION 2001,2004,2007
|
||||
@@ -3376,7 +3376,7 @@
|
||||
./lib/isc/include/isc/ipv6.h C 1999,2000,2001,2002,2004,2005,2007
|
||||
./lib/isc/include/isc/iterated_hash.h C 2008,2014
|
||||
./lib/isc/include/isc/lang.h C 1999,2000,2001,2004,2005,2006,2007
|
||||
./lib/isc/include/isc/lex.h C 1998,1999,2000,2001,2002,2004,2005,2007,2008
|
||||
./lib/isc/include/isc/lex.h C 1998,1999,2000,2001,2002,2004,2005,2007,2008,2017
|
||||
./lib/isc/include/isc/lfsr.h C 1999,2000,2001,2004,2005,2006,2007
|
||||
./lib/isc/include/isc/lib.h C 1999,2000,2001,2004,2005,2006,2007,2009
|
||||
./lib/isc/include/isc/list.h C 1997,1998,1999,2000,2001,2002,2004,2006,2007,2011,2012,2013
|
||||
@@ -3432,7 +3432,7 @@
|
||||
./lib/isc/inet_ntop.c C 1996,1997,1998,1999,2000,2001,2004,2005,2007,2009
|
||||
./lib/isc/inet_pton.c C 1996,1997,1998,1999,2000,2001,2002,2003,2004,2005,2007,2013,2014
|
||||
./lib/isc/iterated_hash.c C 2006,2008,2009
|
||||
./lib/isc/lex.c C 1998,1999,2000,2001,2002,2003,2004,2005,2007,2013,2014,2015
|
||||
./lib/isc/lex.c C 1998,1999,2000,2001,2002,2003,2004,2005,2007,2013,2014,2015,2017
|
||||
./lib/isc/lfsr.c C 1999,2000,2001,2002,2004,2005,2007
|
||||
./lib/isc/lib.c C 1999,2000,2001,2004,2005,2007,2009,2014,2015
|
||||
./lib/isc/log.c C 1999,2000,2001,2002,2003,2004,2005,2006,2007,2009,2011,2012,2013,2014,2016
|
||||
|
||||
@@ -6,6 +6,6 @@ DESCRIPTION="(Extended Support Version)"
|
||||
MAJORVER=9
|
||||
MINORVER=9
|
||||
PATCHVER=10
|
||||
RELEASETYPE=rc
|
||||
RELEASEVER=2
|
||||
RELEASETYPE=-P
|
||||
RELEASEVER=1
|
||||
EXTENSIONS=
|
||||
|
||||
@@ -2857,7 +2857,7 @@ exit 0;
|
||||
# --with-dlz-* ?
|
||||
#
|
||||
# Notes: MSVC versions
|
||||
# MSVC 15.0 _MSC_VER == 1910 (VS 2017 RC)
|
||||
# MSVC 15.0 _MSC_VER == 1910 (VS 2017)
|
||||
# MSVC 14.0 _MSC_VER == 1900 (VS 2015)
|
||||
# MSVC 12.0 _MSC_VER == 1800 (VS 2013)
|
||||
# MSVC 11.0 _MSC_VER == 1700 (VS 2012)
|
||||
|
||||
Reference in New Issue
Block a user