]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
regen v9_9_10_patch
authorTinderbox User <tbox@isc.org>
Tue, 30 May 2017 22:01:40 +0000 (22:01 +0000)
committerTinderbox User <tbox@isc.org>
Tue, 30 May 2017 22:01:40 +0000 (22:01 +0000)
42 files changed:
doc/arm/Bv9ARM.ch01.html
doc/arm/Bv9ARM.ch02.html
doc/arm/Bv9ARM.ch03.html
doc/arm/Bv9ARM.ch04.html
doc/arm/Bv9ARM.ch05.html
doc/arm/Bv9ARM.ch06.html
doc/arm/Bv9ARM.ch07.html
doc/arm/Bv9ARM.ch08.html
doc/arm/Bv9ARM.ch09.html
doc/arm/Bv9ARM.ch10.html
doc/arm/Bv9ARM.ch11.html
doc/arm/Bv9ARM.ch12.html
doc/arm/Bv9ARM.ch13.html
doc/arm/Bv9ARM.html
doc/arm/man.arpaname.html
doc/arm/man.ddns-confgen.html
doc/arm/man.dig.html
doc/arm/man.dnssec-checkds.html
doc/arm/man.dnssec-coverage.html
doc/arm/man.dnssec-dsfromkey.html
doc/arm/man.dnssec-importkey.html
doc/arm/man.dnssec-keyfromlabel.html
doc/arm/man.dnssec-keygen.html
doc/arm/man.dnssec-revoke.html
doc/arm/man.dnssec-settime.html
doc/arm/man.dnssec-signzone.html
doc/arm/man.dnssec-verify.html
doc/arm/man.genrandom.html
doc/arm/man.host.html
doc/arm/man.isc-hmac-fixup.html
doc/arm/man.lwresd.html
doc/arm/man.named-checkconf.html
doc/arm/man.named-checkzone.html
doc/arm/man.named-journalprint.html
doc/arm/man.named.conf.html
doc/arm/man.named.html
doc/arm/man.nsec3hash.html
doc/arm/man.nsupdate.html
doc/arm/man.rndc-confgen.html
doc/arm/man.rndc.conf.html
doc/arm/man.rndc.html
doc/arm/notes.html

index 6bb47fce18573dd57403a62abc6ea3292e99df48..ea08934c2d67a5864b7d03fc05df96d72b2e27e1 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 60c36a9730f33db5927f1f2a334fe19c880cda0f..ae4cb37813f44b4d122266027920375982020a6e 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index ec5947c49e8082c44359c98af2719df843979349..5984e2978c267090d3189f8cc9dc9438fb92c925 100644 (file)
@@ -762,6 +762,6 @@ controls {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index c3d63e86f153282b56fc84669c53b7390f6f0c23..954a1f2c01086b8a8f42a59076387c6b7368cbf3 100644 (file)
@@ -2131,6 +2131,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 5f60edaace6827cc2cda2ec2a585669bf8d2ae77..f690551ca2eb8d3c0ee54e6e9fb107f55bdc9545 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 99db69042e31edc119d78b2ed391ab7e6c65e7cd..1ea61e0cb0dd49338a974cb9eb894e9cd92e4254 100644 (file)
@@ -13199,6 +13199,6 @@ HOST-127.EXAMPLE. MX 0 .
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 908e178ee63b8d40a5f8a7ddca39f9c94ce7c6b7..d8f3daef0a68ece32310f070cb650747ee2989bd 100644 (file)
@@ -262,6 +262,6 @@ zone "example.com" {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index fdbce6afff47e11bfa15be7f7a001a24117957a8..8ca4d42a392b671c24a3a9bf5b6332262bacfd46 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 89daee7463d1379c1b0e3bc552b4ce2f5f31a78b..18bcbfaaf97488b4a0b2e26f3a30c49ce86774c9 100644 (file)
 <div class="toc">
 <p><b>Table of Contents</b></p>
 <dl class="toc">
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.9.10</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.9.10-P1</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#root_key">New DNSSEC Root Key</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_maint">Maintenance</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_thanks">Thank You</a></span></dt>
 </dl></dd>
 </div>
       <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.10.2"></a>Release Notes for BIND Version 9.9.10</h2></div></div></div>
+<a name="id-1.10.2"></a>Release Notes for BIND Version 9.9.10-P1</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
     <p>
-      This document summarizes significant changes since the last
-      production release of BIND on the corresponding major release
-      branch.
-      Please see the CHANGES file for a further list of bug fixes and
-      other changes.
+      This document summarizes changes since BIND 9.9.10:
+    </p>
+    <p>
+      BIND 9.9.10-P1 addresses the security issues described in
+      CVE-2017-3140 and CVE-2017-3141.
     </p>
 
   </div>
 
+
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_download"></a>Download</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
 <li class="listitem">
        <p>
-         <span class="command"><strong>rndc ""</strong></span> could trigger an assertion failure
-         in <span class="command"><strong>named</strong></span>. This flaw is disclosed in
-         (CVE-2017-3138). [RT #44924]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Some chaining (i.e., type CNAME or DNAME) responses to upstream
-         queries could trigger assertion failures. This flaw is disclosed
-         in CVE-2017-3137. [RT #44734]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>dns64</strong></span> with <span class="command"><strong>break-dnssec yes;</strong></span>
-         can result in an assertion failure. This flaw is disclosed in
-         CVE-2017-3136. [RT #44653]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         If a server is configured with a response policy zone (RPZ)
-         that rewrites an answer with local data, and is also configured
-         for DNS64 address mapping, a NULL pointer can be read
-         triggering a server crash.  This flaw is disclosed in
-         CVE-2017-3135. [RT #44434]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could mishandle authority sections
-         with missing RRSIGs, triggering an assertion failure. This
-         flaw is disclosed in CVE-2016-9444. [RT #43632]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> mishandled some responses where
-         covering RRSIG records were returned without the requested
-         data, resulting in an assertion failure. This flaw is
-         disclosed in CVE-2016-9147. [RT #43548]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> incorrectly tried to cache TKEY
-         records which could trigger an assertion failure when there was
-         a class mismatch. This flaw is disclosed in CVE-2016-9131.
-         [RT #43522]
-        </p>
-      </li>
-<li class="listitem">
-       <p>
-         It was possible to trigger assertions when processing
-         responses containing answers of type DNAME. This flaw is
-         disclosed in CVE-2016-8864. [RT #43465]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Added the ability to specify the maximum number of records
-         permitted in a zone (<code class="option">max-records #;</code>).
-         This provides a mechanism to block overly large zone
-         transfers, which is a potential risk with slave zones from
-         other parties, as described in CVE-2016-6170.
-         [RT #42143]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         It was possible to trigger an assertion when rendering a
-         message using a specially crafted request. This flaw is
-         disclosed in CVE-2016-2776. [RT #43139]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Calling <span class="command"><strong>getrrsetbyname()</strong></span> with a non-
-         absolute name could trigger an infinite recursion bug in
-         <span class="command"><strong>lwresd</strong></span> or <span class="command"><strong>named</strong></span> with
-         <span class="command"><strong>lwres</strong></span> configured if, when combined with
-         a search list entry from <code class="filename">resolv.conf</code>,
-         the resulting name is too long.  This flaw is disclosed in
-         CVE-2016-2775. [RT #42694]
-       </p>
-      </li>
-</ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         The ISC DNSSEC Lookaside Validation (DLV) service is scheduled
-         to be disabled in 2017.  A warning is now logged when
-         <span class="command"><strong>named</strong></span> is configured to use this service,
-         either explicitly or via <code class="option">dnssec-lookaside auto;</code>.
-         [RT #42207]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         If an ACL is specified with an address prefix in which the
-         prefix length is longer than the address portion (for example,
-         192.0.2.1/8), <span class="command"><strong>named</strong></span> will now log a warning.
-         In future releases this will be a fatal configuration error.
-         [RT #43367]
-       </p>
-      </li>
-</ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         A synthesized CNAME record appearing in a response before the
-         associated DNAME could be cached, when it should not have been.
-         This was a regression introduced while addressing CVE-2016-8864.
-         [RT #44318]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could deadlock if multiple changes
-         to NSEC/NSEC3 parameters for the same zone were being processed
-         at the same time. [RT #42770]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could trigger an assertion when
-         sending NOTIFY messages. [RT #44019]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Windows installs were failing due to triggering UAC without
-         the installation binary being signed.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         A change in the internal binary representation of the RBT database
-         node structure enabled a race condition to occur (especially when
-         BIND was built with certain compilers or optimizer settings),
-         leading to inconsistent database state which caused random
-         assertion failures. [RT #42380]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Referencing a nonexistent zone in a <span class="command"><strong>response-policy</strong></span>
-         statement could cause an assertion failure during configuration.
-         [RT #43787]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>rndc addzone</strong></span> could cause a crash
-         when attempting to add a zone with a type other than
-         <span class="command"><strong>master</strong></span> or <span class="command"><strong>slave</strong></span>.
-         Such zones are now rejected. [RT #43665]
+         The BIND installer on Windows used an unquoted service path,
+         which can enable privilege escalation. This flaw is disclosed
+         in CVE-2017-3141. [RT #45229]
        </p>
       </li>
 <li class="listitem">
        <p>
-         <span class="command"><strong>named</strong></span> could hang when encountering log
-         file names with large apparent gaps in version number (for
-         example, when files exist called "logfile.0", "logfile.1",
-         and "logfile.1482954169").  This is now handled correctly.
-         [RT #38688]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         If a zone was updated while <span class="command"><strong>named</strong></span> was
-         processing a query for nonexistent data, it could return
-         out-of-sync NSEC3 records causing potential DNSSEC validation
-         failure. [RT #43247]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could crash when loading a zone
-         which had RRISG records whose expiry fields were far enough
-         apart to cause an integer overflow when comparing them.
-         [RT #40571]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The <span class="command"><strong>arpaname</strong></span> command was not installed into
-         the correct <span class="command"><strong>prefix</strong></span><code class="filename">/bin</code>
-         directory. [RT #42910]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         When receiving a response from an authoritative server with
-         a TTL value of zero, <span class="command"><strong>named&gt;</strong></span> will now only use
-         that response once, to answer the currently active clients that
-         were waiting for it. Previously, such response could be cached
-         and reused for up to one second. [RT #42142]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Corrected a bug in the <span class="command"><strong>rndc</strong></span> control channel
-         that could allow a read past the end of a buffer, crashing
-         <span class="command"><strong>named</strong></span>. Thanks to Lian Yihan for reporting
-         this error.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Reverted a change to the query logging format that was
-         inadvertently backported from the 9.11 branch. [RT #43238]
+         With certain RPZ configurations, a response with TTL 0
+         could cause <span class="command"><strong>named</strong></span> to go into an infinite
+         query loop. This flaw is disclosed in CVE-2017-3140.
+         [RT #45181]
        </p>
       </li>
 </ul></div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_maint"></a>Maintenance</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
-       <p>
-         The built-in root hints have been updated to include
-         IPv6 addresses for B.ROOT-SERVERS.NET (2001:500:84::b),
-         E.ROOT-SERVERS.NET (2001:500:a8::e) and
-         G.ROOT-SERVERS.NET (2001:500:12::d0d).
-       </p>
-      </li></ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
 <a name="end_of_life"></a>End of Life</h3></div></div></div>
     <p>
       BIND 9.9 (Extended Support Version) will be supported until
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index c681860a0796ecffd9e6cd9c135eec20cef1e966..8905dd311ba91d44b04897a68e50207e13028fc6 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 0c06287d568ae799302414a1a3dbdf7dd7066b75..9f97413bb221c40b89950aa4b543ef1eed5bf8d3 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index c3a56c049518aae28d06f8dd1dc7dad6451e654a..386b4c76662f0f2ba37aa70fe22c6b957b66c27b 100644 (file)
@@ -580,6 +580,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 77a01cfcc5be2650e7bd8388d17645ffcc404225..4c496c56aae04cd9ad48d550e7ee4c9f0ec48729 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 1515614e7110e62e65aca067b4d60f34d6e93c72..6acfc723edfc2494aa1aadba490844ea5bbae541 100644 (file)
@@ -41,7 +41,7 @@
 <div>
 <div><h1 class="title">
 <a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
-<div><p class="releaseinfo">BIND Version 9.9.10</p></div>
+<div><p class="releaseinfo">BIND Version 9.9.10-P1</p></div>
 <div><p class="copyright">Copyright Â© 2004-2016 Internet Systems Consortium, Inc. ("ISC")</p></div>
 <div><p class="copyright">Copyright Â© 2000-2003 Internet Software Consortium.</p></div>
 </div>
 </dl></dd>
 <dt><span class="appendix"><a href="Bv9ARM.ch09.html">A. Release Notes</a></span></dt>
 <dd><dl>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.9.10</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.9.10-P1</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#root_key">New DNSSEC Root Key</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_maint">Maintenance</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_thanks">Thank You</a></span></dt>
 </dl></dd>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index f560d759f8b13fc64a6e8a0697496dec8cf48a47..e2cc68c80802ea0e32bc4ebf628de297d38936fc 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 07a5116baf3da99b251a21fea6d5e6f8f58b281e..4d19494e4b0d28a99773d7354e25d19ae03d1912 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 3256dd311067e2414dde2f506f59799cee77129e..711082d5893302cd8200ba76328cc76386045fd0 100644 (file)
@@ -950,6 +950,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 04f5bc010e5b55ea147eabac94a2240d079f82d4..3278cf10937f8fbb8662587ce7e725e9d771dbab 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index c4285f6ee34a9fa2c181f1859929fdb36def3242..b4095f107a504eab1a34ffbfa30a159eef00ee20 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index e63aabd7a8f8e01518c94e96fd66a458e08f8912..3be5c31b960dd9cc6a9b8a30ee6caac7c5541eab 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 0482aad06889b9219efc47c44753ed08b4f6d72c..54585251dbe3f40e0363b00a2e4faaa29cbfeeaf 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index d1c45bc85782ada52c1a3ed1619aef658f23f892..fcfb13760b1f83384737ed9eec3590954f2d71f8 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 4383f0a41daf7497576c7e051edee18f9c36cbc9..0b1493b2b01099c62bc13d90f70639febec918da 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 2d2a92482a25d8ecaf0ec47ae0353d17c30f6061..17d9821ff61a7655b7919efc2be11f0a6ece1ea7 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 466cb1d65ad855cd27591f9afa076b3cfc1d52d2..c795972505a7eb47838ddc47e2f135d89adf45d7 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 69b72dabec52f15609a7a8c36debaedcf90dd8e2..596c1e52870b1b7fc610c7ac4b489b4a4ab97ade 100644 (file)
@@ -684,6 +684,6 @@ db.example.com.signed
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 372dc34bd78bbfe4e61f5bfee8cd87f480f7657c..e6ceba69e1c865955a751fa3e82e704273a0fc04 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 79b8c84c57b40e343f3d11b22d32a1f3ebac9012..d18e2b2257e5125f804122a625c6936e603f7ec3 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 23709514efb83cead4e6fd7f8015141855f167cc..4fe6037d5670c029bddd7d12228b8dcbd1425631 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index e0e8b53005cddcb2c03aab46b6b9a931c8df2d9a..d08db18b4f8c65e995df31db3c9a588c57476f4c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 87ea0ffc311dd526da24d0fa746c54176c0abd01..c57dd4b95d315e0ef5960823d5f0b36750619736 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index c4695ee37d9a479f31ec8809f5985bcdd9383c2f..caae347370325753583e41af8acb7162fcba67a2 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 1b48ed8b1f4b32a02bc5277556d85045f6b73f14..cab1bf4ebe7695158c6febff7573120f5ba1807c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index f8d8f73840534f53cd028c9917f2dfdcca35dc63..c4ac6ef374d25ed3a925099a8dce49dca8d97775 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 99a48478ff51a84b26f6b5951f1a9966ec4b5f63..e0cc5b26f1953df8ce5263ff4563a97e49310844 100644 (file)
@@ -731,6 +731,6 @@ zone
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 322ff476d912b2bbf26c351d987df54d55cac9ef..3ec85d0d0aa798883522a8a78274b66134bd7f4b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index c9e2e891c3c9ff6b681b58fe3cf3facabc0db4ba..557a98794afd3e020d0dd3f0a99e632a1b9945e7 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index bc2373a3113f2cfc84ed769d9d9f200ec22708a4..ac058a28ffcf16d4715199eb469994de7612d17f 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index a9457390a95f7094039d1efd60ba68497bb0c1b8..09c207fbc0d1e3b2e8eb92a6b791607a43ad84cb 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index e2df80250757a2911943b5601d026751ce956db1..c0d1ce81f5192f50ec0659ef33404e2523fa0d57 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 1b9152971e50b34489a979bb62c355fc64365426..622bed567dfd65263db7694f6f76be7c6c228e2b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.9.10-P1 (Extended Support Version)</p>
 </body>
 </html>
index 5e0ef9dc989a1fadb57168aa89bd86a4ffc148e1..0430d159ca8ef6b5c7684701237991b920ead506 100644 (file)
 
   <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.2"></a>Release Notes for BIND Version 9.9.10</h2></div></div></div>
+<a name="id-1.2"></a>Release Notes for BIND Version 9.9.10-P1</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
     <p>
-      This document summarizes significant changes since the last
-      production release of BIND on the corresponding major release
-      branch.
-      Please see the CHANGES file for a further list of bug fixes and
-      other changes.
+      This document summarizes changes since BIND 9.9.10:
+    </p>
+    <p>
+      BIND 9.9.10-P1 addresses the security issues described in
+      CVE-2017-3140 and CVE-2017-3141.
     </p>
 
   </div>
 
+
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_download"></a>Download</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
 <li class="listitem">
        <p>
-         <span class="command"><strong>rndc ""</strong></span> could trigger an assertion failure
-         in <span class="command"><strong>named</strong></span>. This flaw is disclosed in
-         (CVE-2017-3138). [RT #44924]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Some chaining (i.e., type CNAME or DNAME) responses to upstream
-         queries could trigger assertion failures. This flaw is disclosed
-         in CVE-2017-3137. [RT #44734]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>dns64</strong></span> with <span class="command"><strong>break-dnssec yes;</strong></span>
-         can result in an assertion failure. This flaw is disclosed in
-         CVE-2017-3136. [RT #44653]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         If a server is configured with a response policy zone (RPZ)
-         that rewrites an answer with local data, and is also configured
-         for DNS64 address mapping, a NULL pointer can be read
-         triggering a server crash.  This flaw is disclosed in
-         CVE-2017-3135. [RT #44434]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could mishandle authority sections
-         with missing RRSIGs, triggering an assertion failure. This
-         flaw is disclosed in CVE-2016-9444. [RT #43632]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> mishandled some responses where
-         covering RRSIG records were returned without the requested
-         data, resulting in an assertion failure. This flaw is
-         disclosed in CVE-2016-9147. [RT #43548]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> incorrectly tried to cache TKEY
-         records which could trigger an assertion failure when there was
-         a class mismatch. This flaw is disclosed in CVE-2016-9131.
-         [RT #43522]
-        </p>
-      </li>
-<li class="listitem">
-       <p>
-         It was possible to trigger assertions when processing
-         responses containing answers of type DNAME. This flaw is
-         disclosed in CVE-2016-8864. [RT #43465]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Added the ability to specify the maximum number of records
-         permitted in a zone (<code class="option">max-records #;</code>).
-         This provides a mechanism to block overly large zone
-         transfers, which is a potential risk with slave zones from
-         other parties, as described in CVE-2016-6170.
-         [RT #42143]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         It was possible to trigger an assertion when rendering a
-         message using a specially crafted request. This flaw is
-         disclosed in CVE-2016-2776. [RT #43139]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Calling <span class="command"><strong>getrrsetbyname()</strong></span> with a non-
-         absolute name could trigger an infinite recursion bug in
-         <span class="command"><strong>lwresd</strong></span> or <span class="command"><strong>named</strong></span> with
-         <span class="command"><strong>lwres</strong></span> configured if, when combined with
-         a search list entry from <code class="filename">resolv.conf</code>,
-         the resulting name is too long.  This flaw is disclosed in
-         CVE-2016-2775. [RT #42694]
-       </p>
-      </li>
-</ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         The ISC DNSSEC Lookaside Validation (DLV) service is scheduled
-         to be disabled in 2017.  A warning is now logged when
-         <span class="command"><strong>named</strong></span> is configured to use this service,
-         either explicitly or via <code class="option">dnssec-lookaside auto;</code>.
-         [RT #42207]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         If an ACL is specified with an address prefix in which the
-         prefix length is longer than the address portion (for example,
-         192.0.2.1/8), <span class="command"><strong>named</strong></span> will now log a warning.
-         In future releases this will be a fatal configuration error.
-         [RT #43367]
-       </p>
-      </li>
-</ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         A synthesized CNAME record appearing in a response before the
-         associated DNAME could be cached, when it should not have been.
-         This was a regression introduced while addressing CVE-2016-8864.
-         [RT #44318]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could deadlock if multiple changes
-         to NSEC/NSEC3 parameters for the same zone were being processed
-         at the same time. [RT #42770]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could trigger an assertion when
-         sending NOTIFY messages. [RT #44019]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Windows installs were failing due to triggering UAC without
-         the installation binary being signed.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         A change in the internal binary representation of the RBT database
-         node structure enabled a race condition to occur (especially when
-         BIND was built with certain compilers or optimizer settings),
-         leading to inconsistent database state which caused random
-         assertion failures. [RT #42380]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Referencing a nonexistent zone in a <span class="command"><strong>response-policy</strong></span>
-         statement could cause an assertion failure during configuration.
-         [RT #43787]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>rndc addzone</strong></span> could cause a crash
-         when attempting to add a zone with a type other than
-         <span class="command"><strong>master</strong></span> or <span class="command"><strong>slave</strong></span>.
-         Such zones are now rejected. [RT #43665]
+         The BIND installer on Windows used an unquoted service path,
+         which can enable privilege escalation. This flaw is disclosed
+         in CVE-2017-3141. [RT #45229]
        </p>
       </li>
 <li class="listitem">
        <p>
-         <span class="command"><strong>named</strong></span> could hang when encountering log
-         file names with large apparent gaps in version number (for
-         example, when files exist called "logfile.0", "logfile.1",
-         and "logfile.1482954169").  This is now handled correctly.
-         [RT #38688]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         If a zone was updated while <span class="command"><strong>named</strong></span> was
-         processing a query for nonexistent data, it could return
-         out-of-sync NSEC3 records causing potential DNSSEC validation
-         failure. [RT #43247]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could crash when loading a zone
-         which had RRISG records whose expiry fields were far enough
-         apart to cause an integer overflow when comparing them.
-         [RT #40571]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The <span class="command"><strong>arpaname</strong></span> command was not installed into
-         the correct <span class="command"><strong>prefix</strong></span><code class="filename">/bin</code>
-         directory. [RT #42910]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         When receiving a response from an authoritative server with
-         a TTL value of zero, <span class="command"><strong>named&gt;</strong></span> will now only use
-         that response once, to answer the currently active clients that
-         were waiting for it. Previously, such response could be cached
-         and reused for up to one second. [RT #42142]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Corrected a bug in the <span class="command"><strong>rndc</strong></span> control channel
-         that could allow a read past the end of a buffer, crashing
-         <span class="command"><strong>named</strong></span>. Thanks to Lian Yihan for reporting
-         this error.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Reverted a change to the query logging format that was
-         inadvertently backported from the 9.11 branch. [RT #43238]
+         With certain RPZ configurations, a response with TTL 0
+         could cause <span class="command"><strong>named</strong></span> to go into an infinite
+         query loop. This flaw is disclosed in CVE-2017-3140.
+         [RT #45181]
        </p>
       </li>
 </ul></div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_maint"></a>Maintenance</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
-       <p>
-         The built-in root hints have been updated to include
-         IPv6 addresses for B.ROOT-SERVERS.NET (2001:500:84::b),
-         E.ROOT-SERVERS.NET (2001:500:a8::e) and
-         G.ROOT-SERVERS.NET (2001:500:12::d0d).
-       </p>
-      </li></ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
 <a name="end_of_life"></a>End of Life</h3></div></div></div>
     <p>
       BIND 9.9 (Extended Support Version) will be supported until