]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
regen v9_12
authorTinderbox User <tbox@isc.org>
Thu, 8 Feb 2018 22:22:04 +0000 (22:22 +0000)
committerTinderbox User <tbox@isc.org>
Thu, 8 Feb 2018 22:22:04 +0000 (22:22 +0000)
doc/arm/Bv9ARM.ch08.html
doc/arm/Bv9ARM.pdf
doc/arm/notes.html
doc/arm/notes.pdf

index d75ffaf633eb9f5429e66eed47acedfef82c1b81..94a6f4fbb5bb0b2968d2d94f46e85b5c672b3d58 100644 (file)
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         Addresses could be referenced after being freed during resolver
-         processing, causing an assertion failure. The chances of this
-         happening were remote, but the introduction of a delay in
-         resolution increased them. This bug is disclosed in
-         CVE-2017-3145. [RT #46839]
-       </p>
-      </li>
-<li class="listitem">
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
          update-policy rules that otherwise ignore the name field now
          require that it be set to "." to ensure that any type list
-         present is properly interpreted.  If the name field was omitted
-         from the rule declaration and a type list was present it wouldn't
-         be interpreted as expected.
+         present is properly interpreted.  Previously, if the name field
+         was omitted from the rule declaration but a type list was
+         present, it wouldn't be interpreted as expected.
        </p>
-      </li>
-</ul></div>
+      </li></ul></div>
   </div>
 
   <div class="section">
       </li>
 <li class="listitem">
        <p>
-         Attempting to validate improperly unsigned CNAME responses
-         from secure zones could cause a validator loop. This caused
-         a delay in returning SERVFAIL and also increased the chances
-         of encountering the crash bug described in CVE-2017-3145.
-         [RT #46839]
+         <span class="command"><strong>named</strong></span> could crash when acting as a slave for a
+         catalog zone if zone contained a master definition without an IP
+         address. [RT #45999]
        </p>
       </li>
 </ul></div>
index a95b9e4a1e7e1fd57f283835c5a0d1c98b1e2891..aad67ba52fe84b92348de1d5d666c0749aa7e177 100644 (file)
Binary files a/doc/arm/Bv9ARM.pdf and b/doc/arm/Bv9ARM.pdf differ
index c2e893a57cb31e9730a42a366d6bb2d6315616a5..69ff4e6663757b8f751022628d0156cd94ede56d 100644 (file)
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         Addresses could be referenced after being freed during resolver
-         processing, causing an assertion failure. The chances of this
-         happening were remote, but the introduction of a delay in
-         resolution increased them. This bug is disclosed in
-         CVE-2017-3145. [RT #46839]
-       </p>
-      </li>
-<li class="listitem">
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
          update-policy rules that otherwise ignore the name field now
          require that it be set to "." to ensure that any type list
-         present is properly interpreted.  If the name field was omitted
-         from the rule declaration and a type list was present it wouldn't
-         be interpreted as expected.
+         present is properly interpreted.  Previously, if the name field
+         was omitted from the rule declaration but a type list was
+         present, it wouldn't be interpreted as expected.
        </p>
-      </li>
-</ul></div>
+      </li></ul></div>
   </div>
 
   <div class="section">
       </li>
 <li class="listitem">
        <p>
-         Attempting to validate improperly unsigned CNAME responses
-         from secure zones could cause a validator loop. This caused
-         a delay in returning SERVFAIL and also increased the chances
-         of encountering the crash bug described in CVE-2017-3145.
-         [RT #46839]
+         <span class="command"><strong>named</strong></span> could crash when acting as a slave for a
+         catalog zone if zone contained a master definition without an IP
+         address. [RT #45999]
        </p>
       </li>
 </ul></div>
index 8335e9b7a8135cfa9f10515869c9d3d126078d6d..e0fad26ddf5ded3fdfc2fd4082a2fb66a31f5247 100644 (file)
Binary files a/doc/arm/notes.pdf and b/doc/arm/notes.pdf differ