Change log for bind9 package in Ubuntu

301375 of 445 results
Superseded in quantal-release
bind9 (1:9.8.1.dfsg.P1-4.2) unstable; urgency=high


  * Non-maintainer upload by the Security Team.
  * Fix denial of service vulnerability triggered
    through an assert because of using bad cache
    (CVE-2012-3817; Closes: #683259).

 -- Nico Golde <email address hidden>  Mon, 30 Jul 2012 20:56:10 +0200
Superseded in quantal-release
bind9 (1:9.8.1.dfsg.P1-4ubuntu2) quantal; urgency=low

  * SECURITY UPDATE: denial of service via dnssec validation load
    - lib/dns/resolver.c: don't use bad->expire before it has been set.
    - Patch backported from 9.8.3-P2.
    - CVE-2012-3817
 -- Marc Deslauriers <email address hidden>   Thu, 26 Jul 2012 10:45:31 -0400
Superseded in natty-updates
Superseded in natty-security
bind9 (1:9.7.3.dfsg-1ubuntu2.5) natty-security; urgency=low

  * SECURITY UPDATE: denial of service via dnssec validation load
    - lib/dns/resolver.c: don't use bad->expire before it has been set.
    - Patch backported from 9.7.6-P2.
    - CVE-2012-3817
 -- Marc Deslauriers <email address hidden>   Wed, 25 Jul 2012 16:26:07 -0400
Superseded in oneiric-updates
Superseded in oneiric-security
bind9 (1:9.7.3.dfsg-1ubuntu4.3) oneiric-security; urgency=low

  * SECURITY UPDATE: denial of service via dnssec validation load
    - lib/dns/resolver.c: don't use bad->expire before it has been set.
    - Patch backported from 9.7.6-P2.
    - CVE-2012-3817
 -- Marc Deslauriers <email address hidden>   Wed, 25 Jul 2012 16:24:44 -0400
Superseded in lucid-updates
Superseded in lucid-security
bind9 (1:9.7.0.dfsg.P1-1ubuntu0.6) lucid-security; urgency=low

  * SECURITY UPDATE: denial of service via dnssec validation load
    - lib/dns/resolver.c: don't use bad->expire before it has been set.
    - Patch backported from 9.7.6-P2.
    - CVE-2012-3817
 -- Marc Deslauriers <email address hidden>   Wed, 25 Jul 2012 16:27:13 -0400
Superseded in precise-updates
Superseded in precise-security
bind9 (1:9.8.1.dfsg.P1-4ubuntu0.2) precise-security; urgency=low

  * SECURITY UPDATE: denial of service via dnssec validation load
    - lib/dns/resolver.c: don't use bad->expire before it has been set.
    - Patch backported from 9.8.3-P2.
    - CVE-2012-3817
 -- Marc Deslauriers <email address hidden>   Wed, 25 Jul 2012 16:21:36 -0400
Superseded in quantal-release
bind9 (1:9.8.1.dfsg.P1-4ubuntu1) quantal; urgency=low

  * SECURITY UPDATE: ghost domain names attack
    - lib/dns/rbtdb.c: Restrict the TTL of NS RRset to no more than that
      of the old NS RRset when replacing it.
    - Patch backported from 9.8.2.
    - CVE-2012-1033
  * SECURITY UPDATE: denial of service via zero length rdata handling
    - lib/dns/rdata.c,lib/dns/rdataslab.c: use sentinel pointer for
      duplicate rdata.
    - Patch backported from 9.8.3-P1.
    - CVE-2012-1667
 -- Marc Deslauriers <email address hidden>   Wed, 20 Jun 2012 15:26:09 -0400
Superseded in hardy-updates
Superseded in hardy-security
bind9 (1:9.4.2.dfsg.P2-2ubuntu0.10) hardy-security; urgency=low

  * SECURITY UPDATE: ghost domain names attack
    - lib/dns/rbtdb.c: Restrict the TTL of NS RRset to no more than that
      of the old NS RRset when replacing it.
    - Patch backported from 9.6-ESV-R6.
    - CVE-2012-1033
  * SECURITY UPDATE: denial of service via zero length rdata handling
    - lib/dns/rdata.c,lib/dns/rdataslab.c: use sentinel pointer for
      duplicate rdata.
    - Patch backported from 9.6-ESV-R7-P1.
    - CVE-2012-1667
 -- Marc Deslauriers <email address hidden>   Mon, 04 Jun 2012 13:53:06 -0400
Superseded in lucid-updates
Superseded in lucid-security
bind9 (1:9.7.0.dfsg.P1-1ubuntu0.5) lucid-security; urgency=low

  * SECURITY UPDATE: ghost domain names attack
    - lib/dns/rbtdb.c: Restrict the TTL of NS RRset to no more than that
      of the old NS RRset when replacing it.
    - Patch backported from 9.7.5.
    - CVE-2012-1033
  * SECURITY UPDATE: denial of service via zero length rdata handling
    - lib/dns/rdata.c,lib/dns/rdataslab.c: use sentinel pointer for
      duplicate rdata.
    - Patch backported from 9.7.6-P1.
    - CVE-2012-1667
 -- Marc Deslauriers <email address hidden>   Mon, 04 Jun 2012 13:47:38 -0400
Superseded in natty-updates
Superseded in natty-security
bind9 (1:9.7.3.dfsg-1ubuntu2.4) natty-security; urgency=low

  * SECURITY UPDATE: ghost domain names attack
    - lib/dns/rbtdb.c: Restrict the TTL of NS RRset to no more than that
      of the old NS RRset when replacing it.
    - Patch backported from 9.7.5.
    - CVE-2012-1033
  * SECURITY UPDATE: denial of service via zero length rdata handling
    - lib/dns/rdata.c,lib/dns/rdataslab.c: use sentinel pointer for
      duplicate rdata.
    - Patch backported from 9.7.6-P1.
    - CVE-2012-1667
 -- Marc Deslauriers <email address hidden>   Mon, 04 Jun 2012 13:27:50 -0400
Superseded in oneiric-updates
Superseded in oneiric-security
bind9 (1:9.7.3.dfsg-1ubuntu4.2) oneiric-security; urgency=low

  * SECURITY UPDATE: ghost domain names attack
    - lib/dns/rbtdb.c: Restrict the TTL of NS RRset to no more than that
      of the old NS RRset when replacing it.
    - Patch backported from 9.7.5.
    - CVE-2012-1033
  * SECURITY UPDATE: denial of service via zero length rdata handling
    - lib/dns/rdata.c,lib/dns/rdataslab.c: use sentinel pointer for
      duplicate rdata.
    - Patch backported from 9.7.6-P1.
    - CVE-2012-1667
 -- Marc Deslauriers <email address hidden>   Mon, 04 Jun 2012 13:26:07 -0400
Superseded in precise-updates
Superseded in precise-security
bind9 (1:9.8.1.dfsg.P1-4ubuntu0.1) precise-security; urgency=low

  * SECURITY UPDATE: ghost domain names attack
    - lib/dns/rbtdb.c: Restrict the TTL of NS RRset to no more than that
      of the old NS RRset when replacing it.
    - Patch backported from 9.8.2.
    - CVE-2012-1033
  * SECURITY UPDATE: denial of service via zero length rdata handling
    - lib/dns/rdata.c,lib/dns/rdataslab.c: use sentinel pointer for
      duplicate rdata.
    - Patch backported from 9.8.3-P1.
    - CVE-2012-1667
 -- Marc Deslauriers <email address hidden>   Mon, 04 Jun 2012 13:12:43 -0400
Superseded in quantal-release
Published in precise-release
bind9 (1:9.8.1.dfsg.P1-4) unstable; urgency=low

  [Christoph Egger]

  * define _GNU_SOURCE on kfreebsd et al.  Closes: #658201

  [LaMont Jones]

  * chmod typo in postinst.  LP: #980798
  * Correctly order debhelper bits in postrm.  Closes: #661040
 -- LaMont Jones <email address hidden>   Fri, 13 Apr 2012 12:09:24 -0600
Superseded in precise-release
bind9 (1:9.8.1.dfsg.P1-3) unstable; urgency=low


  [Zlatan Todoric]

  * fixed Serbian latin translation of debconf template.  Closes: #634951

  [Peter Eisentraut]

  * Add support for "status" action to lwresd init script.  Closes: #651540

  [Bjørn Steensrud]

  * NB Translations.  Closes: #654454

  [LaMont Jones]

  * Default to run_resolvconf=false.  LP: #933723
  * Deliver named.conf.options on fresh install.  Closes: #657042  LP: #920202
  * Do not deliver /usr/share/bind9/bind9-default.md5sum in the bind9 deb. 
    Closes: #620007  LP: #681536
  * Deliver and use /etc/apparmor.d/local/usr.sbin.named for local overrides.
    LP: #929563

 -- LaMont Jones <email address hidden>  Fri, 17 Feb 2012 14:40:29 -0800
Superseded in precise-release
bind9 (1:9.8.1.dfsg.P1-2) unstable; urgency=low


  * Deliver named.conf.options on fresh install.  Closes: #657042  LP: #920202

 -- LaMont Jones <email address hidden>  Wed, 25 Jan 2012 03:55:21 -0700
Superseded in precise-release
bind9 (1:9.8.1.dfsg.P1-1) unstable; urgency=low


  [Internet Software Consortium, Inc]

  * 9.8.1-P1
    -  Cache lookup could return RRSIG data associated with nonexistent
       records, leading to an assertion failure.

  [LaMont Jones]

  * add a readme entry for DNSSEC-by-default
  * Failed to install due to chgrp on non-existant directory.  Closes: #647598
  * ack NMU: l10n issues

 -- LaMont Jones <email address hidden>  Wed, 18 Jan 2012 10:44:14 -0700
Superseded in precise-release
bind9 (1:9.8.1.dfsg.P1-1~build1) precise; urgency=low

  * precise upload

Superseded in precise-release
bind9 (1:9.7.3.dfsg-1ubuntu5) precise; urgency=low

  * SECURITY UPDATE: denial of service via specially crafted packet
    - bin/named/query.c,lib/dns/rbtdb.c: correctly handle cache lookups
      that return RRSIG data associated with nonexistent records.
    - Patch backported from 9.7.4-P1.
    - CVE-2011-4313
 -- Marc Deslauriers <email address hidden>   Wed, 16 Nov 2011 14:22:11 -0500
Obsolete in maverick-updates
Obsolete in maverick-security
bind9 (1:9.7.1.dfsg.P2-2ubuntu0.5) maverick-security; urgency=low

  * SECURITY UPDATE: denial of service via specially crafted packet
    - debian/patches/CVE-2011-4313.patch: correctly handle cache lookups
      that return RRSIG data associated with nonexistent records in
      bin/named/query.c,lib/dns/rbtdb.c.
    - CVE-2011-4313
 -- Marc Deslauriers <email address hidden>   Wed, 16 Nov 2011 14:27:21 -0500
Superseded in lucid-updates
Superseded in lucid-security
bind9 (1:9.7.0.dfsg.P1-1ubuntu0.4) lucid-security; urgency=low

  * SECURITY UPDATE: denial of service via specially crafted packet
    - bin/named/query.c,lib/dns/rbtdb.c: correctly handle cache lookups
      that return RRSIG data associated with nonexistent records.
    - Patch backported from 9.7.4-P1.
    - CVE-2011-4313
 -- Marc Deslauriers <email address hidden>   Wed, 16 Nov 2011 14:29:38 -0500
Superseded in hardy-updates
Superseded in hardy-security
bind9 (1:9.4.2.dfsg.P2-2ubuntu0.9) hardy-security; urgency=low

  * SECURITY UPDATE: denial of service via specially crafted packet
    - bin/named/query.c,lib/dns/rbtdb.c: correctly handle cache lookups
      that return RRSIG data associated with nonexistent records.
    - Patch backported from 9.4-ESV-R5-P1.
    - CVE-2011-4313
 -- Marc Deslauriers <email address hidden>   Wed, 16 Nov 2011 14:30:39 -0500
Superseded in natty-updates
Superseded in natty-security
bind9 (1:9.7.3.dfsg-1ubuntu2.3) natty-security; urgency=low

  * SECURITY UPDATE: denial of service via specially crafted packet
    - bin/named/query.c,lib/dns/rbtdb.c: correctly handle cache lookups
      that return RRSIG data associated with nonexistent records.
    - Patch backported from 9.7.4-P1.
    - CVE-2011-4313
 -- Marc Deslauriers <email address hidden>   Wed, 16 Nov 2011 14:25:20 -0500
Superseded in oneiric-updates
Superseded in oneiric-security
bind9 (1:9.7.3.dfsg-1ubuntu4.1) oneiric-security; urgency=low

  * SECURITY UPDATE: denial of service via specially crafted packet
    - bin/named/query.c,lib/dns/rbtdb.c: correctly handle cache lookups
      that return RRSIG data associated with nonexistent records.
    - Patch backported from 9.7.4-P1.
    - CVE-2011-4313
 -- Marc Deslauriers <email address hidden>   Wed, 16 Nov 2011 14:22:11 -0500
Superseded in precise-release
Obsolete in oneiric-release
bind9 (1:9.7.3.dfsg-1ubuntu4) oneiric; urgency=low

  * debian/apparmor-profile: Allow /var/run and /run. (LP: #810270)
 -- Martin Pitt <email address hidden>   Thu, 14 Jul 2011 15:15:45 +0200
Superseded in oneiric-release
bind9 (1:9.7.3.dfsg-1ubuntu3) oneiric; urgency=low

  * SECURITY UPDATE: denial of service via specially crafted packet
    - lib/dns/include/dns/rdataset.h, lib/dns/{masterdump,message,ncache,
      nsec3,rbtdb,rdataset,resolver,validator}.c: Use an rdataset attribute
      flag to indicate negative-cache records rather than using rrtype 0.
    - Patch backported from 9.7.3-P3.
    - CVE-2011-2464
 -- Marc Deslauriers <email address hidden>   Tue, 05 Jul 2011 08:33:30 -0400
Superseded in lucid-updates
Superseded in lucid-security
bind9 (1:9.7.0.dfsg.P1-1ubuntu0.3) lucid-security; urgency=low

  * SECURITY UPDATE: denial of service via specially crafted packet
    - lib/dns/include/dns/rdataset.h, lib/dns/{masterdump,message,ncache,
      nsec3,rbtdb,rdataset,resolver,validator}.c: Use an rdataset attribute
      flag to indicate negative-cache records rather than using rrtype 0.
    - Patch backported from 9.7.3-P3.
    - CVE-2011-2464
 -- Marc Deslauriers <email address hidden>   Tue, 05 Jul 2011 09:15:54 -0400
Superseded in hardy-updates
Superseded in hardy-security
bind9 (1:9.4.2.dfsg.P2-2ubuntu0.8) hardy-security; urgency=low

  * SECURITY UPDATE: denial of service via specially crafted packet
    - lib/dns/include/dns/rdataset.h, lib/dns/{masterdump,message,ncache,
      nsec3,rbtdb,rdataset,resolver,validator}.c: Use an rdataset attribute
      flag to indicate negative-cache records rather than using rrtype 0.
    - Patch backported from 9.6-ESV-R4-P3.
    - CVE-2011-2464
 -- Marc Deslauriers <email address hidden>   Tue, 05 Jul 2011 09:30:37 -0400
Superseded in maverick-updates
Superseded in maverick-security
bind9 (1:9.7.1.dfsg.P2-2ubuntu0.4) maverick-security; urgency=low

  * SECURITY UPDATE: denial of service via specially crafted packet
    - debian/patches/CVE-2011-2464.patch: Use an rdataset attribute flag to
      indicate negative-cache records rather than using rrtype 0 in
      lib/dns/include/dns/rdataset.h, lib/dns/{masterdump,message,ncache,
      nsec3,rbtdb,rdataset,resolver,validator}.c.
    - CVE-2011-2464
 -- Marc Deslauriers <email address hidden>   Tue, 05 Jul 2011 09:07:19 -0400
Superseded in natty-updates
Superseded in natty-security
bind9 (1:9.7.3.dfsg-1ubuntu2.2) natty-security; urgency=low

  * SECURITY UPDATE: denial of service via specially crafted packet
    - lib/dns/include/dns/rdataset.h, lib/dns/{masterdump,message,ncache,
      nsec3,rbtdb,rdataset,resolver,validator}.c: Use an rdataset attribute
      flag to indicate negative-cache records rather than using rrtype 0.
    - Patch backported from 9.7.3-P3.
    - CVE-2011-2464
 -- Marc Deslauriers <email address hidden>   Tue, 05 Jul 2011 08:33:30 -0400
Superseded in maverick-updates
Superseded in maverick-security
bind9 (1:9.7.1.dfsg.P2-2ubuntu0.3) maverick-security; urgency=low

  * SECURITY UPDATE: denial of service via off-by-one
    - debian/patches/CVE-2011-1910.patch: correctly validate length in
      lib/dns/ncache.c.
    - CVE-2011-1910
 -- Marc Deslauriers <email address hidden>   Fri, 27 May 2011 15:23:52 -0400
Superseded in hardy-updates
Superseded in hardy-security
bind9 (1:9.4.2.dfsg.P2-2ubuntu0.7) hardy-security; urgency=low

  * SECURITY UPDATE: denial of service via multiple trust anchors for a
    single zone
    - lib/dns/validator.c: fix arguments to dns_keytable_findnextkeynode().
    - Upstream change 2869.
    - CVE-2010-3762
  * SECURITY UPDATE: denial of service via off-by-one
    - lib/dns/ncache.c: correctly validate length.
    - Patch backported from 9.4-ESV-R4-P1.
    - CVE-2011-1910
  * Added tests for previous security update to test suite and backport
    DNS_DBFIND_ADDITIONALOK so they work.
 -- Marc Deslauriers <email address hidden>   Fri, 27 May 2011 13:26:22 -0400
Superseded in lucid-updates
Superseded in lucid-security
bind9 (1:9.7.0.dfsg.P1-1ubuntu0.2) lucid-security; urgency=low

  * SECURITY UPDATE: denial of service via multiple trust anchors for a
    single zone
    - lib/dns/validator.c: fix arguments to dns_keytable_findnextkeynode().
    - Upstream change 2869.
    - CVE-2010-3762
  * SECURITY UPDATE: denial of service via off-by-one
    - lib/dns/ncache.c: correctly validate length.
    - Patch backported from 9.7.3-P1.
    - CVE-2011-1910
 -- Marc Deslauriers <email address hidden>   Fri, 27 May 2011 13:03:07 -0400
Superseded in oneiric-release
Superseded in natty-updates
Superseded in natty-security
bind9 (1:9.7.3.dfsg-1ubuntu2.1) natty-security; urgency=low

  * SECURITY UPDATE: denial of service via off-by-one
    - lib/dns/ncache.c: correctly validate length.
    - Patch backported from 9.7.3-P1.
    - CVE-2011-1910
 -- Marc Deslauriers <email address hidden>   Fri, 27 May 2011 12:50:40 -0400
Superseded in oneiric-release
Obsolete in natty-release
bind9 (1:9.7.3.dfsg-1ubuntu2) natty; urgency=low

  * debian/rules, configure, contrib/dlz/config.dlz.in: use
    DEB_HOST_MULTIARCH so we can find multiarch libraries and fix FTBFS.
    (LP: #745642)
 -- Marc Deslauriers <email address hidden>   Wed, 30 Mar 2011 10:19:37 -0400
Superseded in natty-release
bind9 (1:9.7.3.dfsg-1ubuntu1) natty; urgency=low

  * debian/bind9-default.md5sum:
    - updated to reflect the default md5sum in maverick and natty, this
      avoids a bogus /etc/default/bind9.dpkg-dist file
      (LP: #556332)
 -- Michael Vogt <email address hidden>   Tue, 29 Mar 2011 10:13:11 +0200
Superseded in natty-release
bind9 (1:9.7.3.dfsg-1) unstable; urgency=low

  [Peter Palfrader]

  * Add db-4.6 to bdb_libnames in dlz/config.dlz.in so that it finds the right
    db.

  [Internet Systems Consortium, Inc]

  * 9.7.3 - Closes: #612287

  [Mahyuddin Susanto]

  * Updated Indonesian debconf templates.  Closes: #608559

  [LaMont Jones]

  * soname changes
 -- LaMont Jones <email address hidden>   Thu,  24 Feb 2011 11:40:45 +0000
Superseded in natty-release
bind9 (1:9.7.3.dfsg-1~build1) natty; urgency=low

  * Natty version, no source changes

Superseded in maverick-updates
Superseded in maverick-security
bind9 (1:9.7.1.dfsg.P2-2ubuntu0.2) maverick-security; urgency=low

  * SECURITY UPDATE: denial of service via IXFR or DDNS update
    - debian/patches/CVE-2011-0414.patch: Use correct lock in
      lib/dns/rbtdb.c.
    - CVE-2011-0414
 -- Marc Deslauriers <email address hidden>   Wed, 23 Feb 2011 08:30:32 -0500
Superseded in natty-release
bind9 (1:9.7.2.dfsg.P3-1.1) unstable; urgency=low

  * Non-maintainer upload.
  * Fix encoding of Danish debconf translation
 -- Dave Walker <email address hidden>   Thu,  10 Feb 2011 08:54:28 +0000
Superseded in natty-release
bind9 (1:9.7.2.dfsg.P3-1) unstable; urgency=high

  [ISC]
  * Fix denial of service via ncache entry and a rrsig for the
    same type (CVE-2010-3613)
  * answers were incorrectly marked as insecure during key algorithm
    rollover (CVE-2010-3614)
  * Using "allow-query" in the "options" or "view" statements to
    restrict access to authoritative zones had no effect.
    (CVE-2010-3615)

  [LaMont Jones]

  * Adjust indentation for dpkg change.  Closes: #597171
 -- Ubuntu Archive Auto-Sync <email address hidden>   Mon,  06 Dec 2010 12:52:54 +0000
Superseded in natty-release
bind9 (1:9.7.2.dfsg.P3-1~build1) natty; urgency=low

  * build for upload
 -- LaMont Jones <email address hidden>   Sun, 05 Dec 2010 10:28:06 -0700
Obsolete in dapper-updates
Obsolete in dapper-security
bind9 (1:9.3.2-2ubuntu1.12) dapper-security; urgency=low

  * SECURITY UPDATE: denial of service via ncache entry and a rrsig for the
    same type
    - lib/dns/rbtdb.c: properly mark existing RRSIG records as stale. Also
      required backport of change #1997.
    - CVE-2010-3613
  * SECURITY UPDATE: answers incorrectly marked as insecure during key
    algorithm rollover
    - lib/dns/include/dns/types.h, lib/dns/validator.c: improve logic.
    - CVE-2010-3614
 -- Marc Deslauriers <email address hidden>   Fri, 26 Nov 2010 12:54:23 -0500
Superseded in hardy-updates
Superseded in hardy-security
bind9 (1:9.4.2.dfsg.P2-2ubuntu0.6) hardy-security; urgency=low

  * SECURITY UPDATE: denial of service via ncache entry and a rrsig for the
    same type
    - lib/dns/rbtdb.c: properly mark existing RRSIG records as stale.
    - CVE-2010-3613
  * SECURITY UPDATE: answers incorrectly marked as insecure during key
    algorithm rollover
    - lib/dns/include/dns/types.h, lib/dns/validator.c: improve logic.
    - CVE-2010-3614
 -- Marc Deslauriers <email address hidden>   Fri, 26 Nov 2010 09:41:20 -0500
Obsolete in karmic-updates
Obsolete in karmic-security
bind9 (1:9.6.1.dfsg.P1-3ubuntu0.4) karmic-security; urgency=low

  * SECURITY UPDATE: denial of service via ncache entry and a rrsig for the
    same type
    - lib/dns/rbtdb.c: properly mark existing RRSIG records as stale.
    - bin/tests/system/resolver/*: added tests.
    - CVE-2010-3613
  * SECURITY UPDATE: answers incorrectly marked as insecure during key
    algorithm rollover
    - lib/dns/include/dns/types.h, lib/dns/validator.c: improve logic.
    - bin/tests/system/dnssec/*: added tests.
    - CVE-2010-3614
 -- Marc Deslauriers <email address hidden>   Fri, 26 Nov 2010 17:04:49 -0500
Superseded in lucid-updates
Superseded in lucid-security
bind9 (1:9.7.0.dfsg.P1-1ubuntu0.1) lucid-security; urgency=low

  * SECURITY UPDATE: denial of service via ncache entry and a rrsig for the
    same type
    - lib/dns/rbtdb.c: properly mark existing RRSIG records as stale.
    - bin/tests/system/resolver/*: added tests.
    - CVE-2010-3613
  * SECURITY UPDATE: answers incorrectly marked as insecure during key
    algorithm rollover
    - lib/dns/include/dns/types.h, lib/dns/validator.c: improve logic.
    - bin/tests/system/dnssec/*: added tests.
    - CVE-2010-3614
 -- Marc Deslauriers <email address hidden>   Fri, 26 Nov 2010 15:53:25 -0500
Superseded in maverick-updates
Superseded in maverick-security
bind9 (1:9.7.1.dfsg.P2-2ubuntu0.1) maverick-security; urgency=low

  * SECURITY UPDATE: denial of service via ncache entry and a rrsig for the
    same type
    - debian/patches/CVE-2010-3613-3614.patch: properly mark existing RRSIG
      records as stale in lib/dns/rbtdb.c. Added tests to
      bin/tests/system/resolver/*.
    - CVE-2010-3613
  * SECURITY UPDATE: answers incorrectly marked as insecure during key
    algorithm rollover
    - debian/patches/CVE-2010-3613-3614.patch: improve logic in
      lib/dns/validator.c. Added tests to bin/tests/system/dnssec/*.
    - CVE-2010-3614
 -- Marc Deslauriers <email address hidden>   Tue, 30 Nov 2010 08:39:45 -0500
Superseded in natty-release
bind9 (1:9.7.2.dfsg.P2-3~build1) natty; urgency=low

  * upload to natty
 -- LaMont Jones <email address hidden>   Fri, 26 Nov 2010 05:23:22 -0700
Superseded in natty-release
bind9 (1:9.7.2.dfsg.P2-2ubuntu1) natty; urgency=low

  [ Andres Rodriguez ]
  * Add apport hook (LP: #533601):
    - debian/bind9.apport: Added.

  [ Martin Pitt ]
  * debian/rules: Install Apport hook when building on Ubuntu.
 -- Martin Pitt <email address hidden>   Fri, 26 Nov 2010 10:50:17 +0100
Superseded in natty-release
bind9 (1:9.7.2.dfsg.P2-2) unstable; urgency=low

  [Roy Jamison]

  * lib/isc/unix/resource.c was missing inttypes.h include.  LP: #674199
 -- Ubuntu Archive Auto-Sync <email address hidden>   Sat,  13 Nov 2010 13:44:32 +0000
Superseded in natty-release
bind9 (1:9.7.2.dfsg.P2-2~build1) natty; urgency=low

  * backport to natty
 -- LaMont Jones <email address hidden>   Fri, 12 Nov 2010 11:19:29 -0700
Superseded in natty-release
bind9 (1:9.7.2.dfsg.P2-1) unstable; urgency=low

  [Joe Dalton]

  * Add Danish translation of debconf templates.  Closes: #599431

  [Internet Software Consortium, Inc]

  * v9.7.2-P2

  [José Figueiredo]

  * Add Brazilian Portuguese debconf templates translation.  Closes: #597616

  [LaMont Jones]

  * drop this v3 (quilt) source format idea.  Closes: #589916
 -- Ubuntu Archive Auto-Sync <email address hidden>   Mon,  08 Nov 2010 09:46:16 +0000
Superseded in natty-release
Obsolete in maverick-release
bind9 (1:9.7.1.dfsg.P2-2) unstable; urgency=low

  * Correct conflicts for bind9-host
 -- LaMont Jones <email address hidden>   Wed,  04 Aug 2010 21:19:10 +0100
Superseded in maverick-release
bind9 (1:9.7.1.dfsg.P2-2~build1) maverick; urgency=low

  * direct maverick upload.

Superseded in maverick-release
bind9 (1:9.7.1.dfsg.P2-1~build1) maverick; urgency=low

  * ubuntu upload to speed things along
 -- LaMont Jones <email address hidden>   Thu, 15 Jul 2010 17:11:12 -0600
Superseded in maverick-release
bind9 (1:9.7.1.dfsg-2) unstable; urgency=low

  [Regid Ichira]

  * explicitly add nsupdate to dynamic updates in README.Debian. 
    Closes: #577398

  [LaMont Jones]

  * Cleanup bind9-host description.  Closes: #579421
  * switch to 3.0 (quilt) source format, but not to quilt.  Closes: #578210

  [Stephen Gran]

  * updated geoip patch for ipv6, based on work by John 'Warthog9' Hawley
    <email address hidden>.  Closes: #584603

Superseded in maverick-release
Obsolete in lucid-release
bind9 (1:9.7.0.dfsg.P1-1) unstable; urgency=low

  [Internet Software Consortium, Inc]

  * 9.7.0-P1
    - 2852. [bug] Handle broken DNSSEC trust chains better. [RT #15619]
 -- LaMont Jones <email address hidden>   Mon,  22 Mar 2010 18:18:27 +0000
Superseded in lucid-release
bind9 (1:9.7.0.dfsg.P1-1~build1) lucid; urgency=low

  * build for upload
 -- LaMont Jones <email address hidden>   Wed, 17 Mar 2010 09:09:35 -0600
Superseded in lucid-release
bind9 (1:9.7.0.dfsg.1-1~build1) lucid; urgency=low

  * lucid port
 -- LaMont Jones <email address hidden>   Fri, 12 Mar 2010 15:16:53 -0700
Superseded in lucid-release
bind9 (1:9.7.0.dfsg-2~build1) lucid; urgency=low

  * no-change lucid-port.
 -- LaMont Jones <email address hidden>   Thu, 04 Mar 2010 10:46:42 -0700
Superseded in lucid-release
bind9 (1:9.7.0.dfsg-1~build1) lucid; urgency=low

  * upload of -1 to lucid, LP#530107
 -- LaMont Jones <email address hidden>   Mon, 01 Mar 2010 20:51:23 -0700
Superseded in lucid-release
bind9 (1:9.6.1.dfsg.P3-1) unstable; urgency=low

  * New upstream release.  CVE-2010-0097
 -- Ubuntu Archive Auto-Sync <email address hidden>   Mon,  01 Feb 2010 23:57:18 +0000
Superseded in dapper-updates
Superseded in dapper-security
bind9 (1:9.3.2-2ubuntu1.11) dapper-security; urgency=low

  * SECURITY UPDATE: incorrect cache update from additional section
    - bin/named/query.c, lib/dns/include/dns/types.h,
      lib/dns/{resolver.c,validator.c}: further fixes backported from
      9.4.3-P5
    - CVE-2009-4022
  * SECURITY UPDATE: incorrect caching of bogus NXDOMAIN responses
    - bin/named/query.c, lib/dns/include/dns/types.h,
      lib/dns/{resolver.c,validator.c}: fixes backported from 9.4.3-P5
    - CVE-2010-0097
 -- Marc Deslauriers <email address hidden>   Tue, 19 Jan 2010 19:19:45 -0500
Superseded in hardy-updates
Superseded in hardy-security
bind9 (1:9.4.2.dfsg.P2-2ubuntu0.5) hardy-security; urgency=low

  * SECURITY UPDATE: incorrect cache update from additional section
    - bin/named/query.c, lib/dns/include/dns/types.h,
      lib/dns/{resolver.c,validator.c}: further fixes backported from
      9.4.3-P5
    - CVE-2009-4022
  * SECURITY UPDATE: incorrect caching of bogus NXDOMAIN responses
    - bin/named/query.c, lib/dns/include/dns/types.h,
      lib/dns/{resolver.c,validator.c}: fixes backported from 9.4.3-P5
    - CVE-2010-0097
 -- Marc Deslauriers <email address hidden>   Tue, 19 Jan 2010 13:15:01 -0500
Obsolete in intrepid-updates
Obsolete in intrepid-security
bind9 (1:9.5.0.dfsg.P2-1ubuntu3.5) intrepid-security; urgency=low

  * SECURITY UPDATE: incorrect cache update from additional section
    - bin/named/query.c, lib/dns/include/dns/{db.h,types.h},
      lib/dns/{rbtdb.c,resolver.c,validator.c}: further fixes backported
      from 9.5.2-P2
    - CVE-2009-4022
  * SECURITY UPDATE: incorrect caching of bogus NXDOMAIN responses
    - bin/named/query.c, lib/dns/include/dns/{db.h,types.h},
      lib/dns/{rbtdb.c,resolver.c,validator.c}: fixes backported from
      9.5.2-P2
    - CVE-2010-0097
 -- Marc Deslauriers <email address hidden>   Tue, 19 Jan 2010 13:11:22 -0500
Obsolete in jaunty-updates
Obsolete in jaunty-security
bind9 (1:9.5.1.dfsg.P2-1ubuntu0.4) jaunty-security; urgency=low

  * SECURITY UPDATE: incorrect cache update from additional section
    - bin/named/query.c, lib/dns/include/dns/{db.h,types.h},
      lib/dns/{rbtdb.c,resolver.c,validator.c}: further fixes backported
      from 9.5.2-P2
    - CVE-2009-4022
  * SECURITY UPDATE: incorrect caching of bogus NXDOMAIN responses
    - bin/named/query.c, lib/dns/include/dns/{db.h,types.h},
      lib/dns/{rbtdb.c,resolver.c,validator.c}: fixes backported from
      9.5.2-P2
    - CVE-2010-0097
 -- Marc Deslauriers <email address hidden>   Tue, 19 Jan 2010 13:07:12 -0500
Superseded in karmic-updates
Superseded in karmic-security
bind9 (1:9.6.1.dfsg.P1-3ubuntu0.3) karmic-security; urgency=low

  * SECURITY UPDATE: incorrect cache update from additional section
    - bin/named/query.c, lib/dns/include/dns/{db.h,types.h},
      lib/dns/{rbtdb.c,resolver.c,validator.c}: further fixes backported
      from 9.6.1-P3
    - CVE-2009-4022
  * SECURITY UPDATE: incorrect caching of bogus NXDOMAIN responses
    - bin/named/query.c, lib/dns/include/dns/{db.h,types.h},
      lib/dns/{rbtdb.c,resolver.c,validator.c}: fixes backported from
      9.6.1-P3
    - CVE-2010-0097
 -- Marc Deslauriers <email address hidden>   Tue, 19 Jan 2010 12:59:27 -0500
Superseded in lucid-release
bind9 (1:9.6.1.dfsg.P3-1~build1) lucid; urgency=low

  * Ubuntu upload for early access to 9.6.1.dfsg.P3-1.
    9.6.1.dfsg.P3-1 should sync over: no source changes present.
 -- LaMont Jones <email address hidden>   Tue, 19 Jan 2010 11:45:55 -0700
Superseded in lucid-release
bind9 (1:9.6.1.dfsg.P2-1) unstable; urgency=low

  [Internet Software Consortium, Inc]

  * 9.6.1-P2
    - When validating, track whether pending data was from the
      additional section or not and only return it if validates
      as secure. [RT #20438] CVE-2009-4022

  [LaMont Jones]

  * prerm: do not stop named on upgrade.  Closes: #542888
  * Drop some RFCs that crept into the diff.
  * meta: add ${misc:Depends}
  * lintian: update config.guess, config.sub in idnkit-1.0 tree
  * dnsutils: remove pre-sarge dpkg-divert calls in postinst
  * meta: soname changes
  * l10n: missing newline in pofile.
 -- Ubuntu Archive Auto-Sync <email address hidden>   Mon,  14 Dec 2009 18:46:02 +0000
Superseded in dapper-updates
Superseded in dapper-security
bind9 (1:9.3.2-2ubuntu1.9) dapper-security; urgency=low

  * SECURITY UPDATE: incorrect cache update from additional section
    - bin/named/query.c, lib/dns/{include/dns/types.h,masterdump.c,
      rbtdb.c,resolver.c,validator.c}: handle the additional section
      properly. lib/dns/api, version: increment versions.
    - debian/*: increment to libdns23, add libdns21 metapackage so
      upgrade-manager won't hold the bind9 upgrade back.
    - CVE-2009-4022
 -- Marc Deslauriers <email address hidden>   Fri, 04 Dec 2009 09:28:29 -0500
Superseded in hardy-updates
Superseded in hardy-security
bind9 (1:9.4.2.dfsg.P2-2ubuntu0.4) hardy-security; urgency=low

  * SECURITY UPDATE: incorrect cache update from additional section
    - bin/named/query.c, lib/dns/{include/dns/types.h,masterdump.c,
      rbtdb.c,resolver.c,validator.c}: handle the additional section
      properly. lib/dns/api, version: increment versions.
    - debian/*: increment to libdns36, add libdns35 metapackage so
      upgrade-manager won't hold the bind9 upgrade back.
    - CVE-2009-4022
 -- Marc Deslauriers <email address hidden>   Fri, 04 Dec 2009 09:13:41 -0500
Superseded in intrepid-updates
Superseded in intrepid-security
bind9 (1:9.5.0.dfsg.P2-1ubuntu3.4) intrepid-security; urgency=low

  * SECURITY UPDATE: incorrect cache update from additional section
    - bin/named/query.c, lib/dns/{include/dns/types.h,masterdump.c,
      rbtdb.c,resolver.c,validator.c}: handle the additional section
      properly. lib/dns/api, version: increment versions.
    - debian/*: increment to libdns44, add libdns43 metapackage so
      upgrade-manager won't hold the bind9 upgrade back.
    - CVE-2009-4022
 -- Marc Deslauriers <email address hidden>   Fri, 04 Dec 2009 08:47:05 -0500
Superseded in jaunty-updates
Superseded in jaunty-security
bind9 (1:9.5.1.dfsg.P2-1ubuntu0.3) jaunty-security; urgency=low

  * SECURITY UPDATE: incorrect cache update from additional section
    - bin/named/query.c, lib/dns/{include/dns/types.h,masterdump.c,
      rbtdb.c,resolver.c,validator.c}: handle the additional section
      properly. lib/dns/api, version: increment versions.
    - debian/*: increment to libdns46, add libdns45 metapackage so
      upgrade-manager won't hold the bind9 upgrade back.
    - CVE-2009-4022
 -- Marc Deslauriers <email address hidden>   Fri, 04 Dec 2009 08:30:45 -0500
Superseded in karmic-updates
Superseded in karmic-security
bind9 (1:9.6.1.dfsg.P1-3ubuntu0.2) karmic-security; urgency=low

  * SECURITY UPDATE: incorrect cache update from additional section
    - CHANGES, bin/named/query.c, lib/dns/{include/dns/types.h,
      masterdump.c,rbtdb.c,resolver.c,validator.c}: handle the additional
      section properly. lib/dns/api, version: increment versions.
    - debian/*: increment to libdns53, add libdns50 metapackage so
      upgrade-manager won't hold the bind9 upgrade back.
    - CVE-2009-4022
 -- Marc Deslauriers <email address hidden>   Fri, 04 Dec 2009 08:13:05 -0500
Superseded in lucid-release
bind9 (1:9.6.1.dfsg.P2-1~1build1) lucid; urgency=low

  * upload to lucid

Superseded in lucid-release
Obsolete in karmic-release
bind9 (1:9.6.1.dfsg.P1-3) unstable; urgency=low

  * Build-Depend on the fixed libgeoip-dev.  Closes: #540973

301375 of 445 results