From owner-cvs-src-old@FreeBSD.ORG Sat Dec 4 05:59:18 2010 Return-Path: Delivered-To: cvs-src-old@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 527621065782 for ; Sat, 4 Dec 2010 05:59:18 +0000 (UTC) (envelope-from dougb@FreeBSD.org) Received: from repoman.freebsd.org (repoman.freebsd.org [IPv6:2001:4f8:fff6::29]) by mx1.freebsd.org (Postfix) with ESMTP id 3B1878FC1B for ; Sat, 4 Dec 2010 05:59:18 +0000 (UTC) Received: from repoman.freebsd.org (localhost [127.0.0.1]) by repoman.freebsd.org (8.14.4/8.14.4) with ESMTP id oB45xINp064479 for ; Sat, 4 Dec 2010 05:59:18 GMT (envelope-from dougb@repoman.freebsd.org) Received: (from svn2cvs@localhost) by repoman.freebsd.org (8.14.4/8.14.4/Submit) id oB45xIks064478 for cvs-src-old@freebsd.org; Sat, 4 Dec 2010 05:59:18 GMT (envelope-from dougb@repoman.freebsd.org) Message-Id: <201012040559.oB45xIks064478@repoman.freebsd.org> X-Authentication-Warning: repoman.freebsd.org: svn2cvs set sender to dougb@repoman.freebsd.org using -f From: Doug Barton Date: Sat, 4 Dec 2010 05:58:56 +0000 (UTC) To: cvs-src-old@freebsd.org X-FreeBSD-CVS-Branch: HEAD Subject: cvs commit: src/contrib/bind9 CHANGES RELEASE-NOTES-BIND-9.6-ESV.html RELEASE-NOTES-BIND-9.6-ESV.pdf RELEASE-NOTES-BIND-9.6-ESV.txt release-notes.css version src/contrib/bind9/bin/check check-tool.c check-tool.h named-checkconf.c named-checkzone.c src/contrib/bind9/bin/dig ... X-BeenThere: cvs-src-old@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: **OBSOLETE** CVS commit messages for the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 04 Dec 2010 05:59:18 -0000 dougb 2010-12-04 05:58:56 UTC FreeBSD src repository Modified files: contrib/bind9 CHANGES version contrib/bind9/bin/check check-tool.c check-tool.h named-checkconf.c named-checkzone.c contrib/bind9/bin/dig host.c contrib/bind9/bin/named client.c query.c server.c contrib/bind9/bin/named/include/named query.h contrib/bind9/lib/dns api journal.c rbtdb.c validator.c view.c contrib/bind9/lib/dns/include/dns view.h contrib/bind9/lib/isc api print.c Added files: contrib/bind9 RELEASE-NOTES-BIND-9.6-ESV.html RELEASE-NOTES-BIND-9.6-ESV.pdf RELEASE-NOTES-BIND-9.6-ESV.txt release-notes.css Log: SVN rev 216175 on 2010-12-04 05:58:56Z by dougb Update to version 9.6-ESV-R3, the latest from ISC, which addresses the following security vulnerabilities. For more information regarding these issues please see: http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisories 1. Cache incorrectly allows ncache and rrsig for the same type http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3613 Affects resolver operators whose servers are open to potential attackers. Triggering the bug will cause the server to crash. This bug applies even if you do not have DNSSEC enabled. 2. Key algorithm rollover http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3614 Affects resolver operators who are validating with DNSSEC, and querying zones which are in a key rollover period. The bug will cause answers to incorrectly be marked as insecure. Revision Changes Path 1.16 +52 -0 src/contrib/bind9/CHANGES 1.1 +225 -0 src/contrib/bind9/RELEASE-NOTES-BIND-9.6-ESV.html (new) 1.1 +321 -0 src/contrib/bind9/RELEASE-NOTES-BIND-9.6-ESV.pdf (new) 1.1 +133 -0 src/contrib/bind9/RELEASE-NOTES-BIND-9.6-ESV.txt (new) 1.4 +29 -2 src/contrib/bind9/bin/check/check-tool.c 1.3 +7 -2 src/contrib/bind9/bin/check/check-tool.h 1.4 +10 -2 src/contrib/bind9/bin/check/named-checkconf.c 1.6 +9 -2 src/contrib/bind9/bin/check/named-checkzone.c 1.4 +6 -4 src/contrib/bind9/bin/dig/host.c 1.6 +4 -4 src/contrib/bind9/bin/named/client.c 1.3 +4 -2 src/contrib/bind9/bin/named/include/named/query.h 1.8 +11 -14 src/contrib/bind9/bin/named/query.c 1.9 +23 -18 src/contrib/bind9/bin/named/server.c 1.13 +2 -2 src/contrib/bind9/lib/dns/api 1.3 +4 -2 src/contrib/bind9/lib/dns/include/dns/view.h 1.5 +14 -7 src/contrib/bind9/lib/dns/journal.c 1.9 +53 -12 src/contrib/bind9/lib/dns/rbtdb.c 1.11 +47 -11 src/contrib/bind9/lib/dns/validator.c 1.7 +7 -1 src/contrib/bind9/lib/dns/view.c 1.7 +1 -1 src/contrib/bind9/lib/isc/api 1.4 +3 -3 src/contrib/bind9/lib/isc/print.c 1.1 +60 -0 src/contrib/bind9/release-notes.css (new) 1.16 +2 -2 src/contrib/bind9/version