From: Tinderbox User Date: Sat, 3 Feb 2018 01:11:31 +0000 (+0000) Subject: regen master X-Git-Tag: v9.13.0~192 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=31d0b7e909a4b2a7f6a0e08fe25b76e05a184ed3;p=thirdparty%2Fbind9.git regen master --- diff --git a/doc/arm/Bv9ARM.ch08.html b/doc/arm/Bv9ARM.ch08.html index a3793be3774..f18fcc5728e 100644 --- a/doc/arm/Bv9ARM.ch08.html +++ b/doc/arm/Bv9ARM.ch08.html @@ -131,7 +131,17 @@

Bug Fixes

-
  • +
      +
    • +

      + When answering authoritative queries, named + does not return the target of a cross-zone CNAME between two + locally served zones; this prevents accidental cache poisoning. + This same restriction was incorrectly applied to recursive + queries as well; this has been fixed. [RT #47078] +

      +
    • +
    • Attempting to validate improperly unsigned CNAME responses from secure zones could cause a validator loop. This caused @@ -139,7 +149,8 @@ of encountering the crash bug described in CVE-2017-3145. [RT #46839]

      -
    +
  • +
diff --git a/doc/arm/notes.html b/doc/arm/notes.html index 3dfe655e9ba..4a1c80f3f37 100644 --- a/doc/arm/notes.html +++ b/doc/arm/notes.html @@ -93,7 +93,17 @@

Bug Fixes

-
  • +
      +
    • +

      + When answering authoritative queries, named + does not return the target of a cross-zone CNAME between two + locally served zones; this prevents accidental cache poisoning. + This same restriction was incorrectly applied to recursive + queries as well; this has been fixed. [RT #47078] +

      +
    • +
    • Attempting to validate improperly unsigned CNAME responses from secure zones could cause a validator loop. This caused @@ -101,7 +111,8 @@ of encountering the crash bug described in CVE-2017-3145. [RT #46839]

      -
    +
  • +