]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
regen v9_10_5_patch
authorTinderbox User <tbox@isc.org>
Tue, 30 May 2017 21:54:25 +0000 (21:54 +0000)
committerTinderbox User <tbox@isc.org>
Tue, 30 May 2017 21:54:25 +0000 (21:54 +0000)
44 files changed:
doc/arm/Bv9ARM.ch01.html
doc/arm/Bv9ARM.ch02.html
doc/arm/Bv9ARM.ch03.html
doc/arm/Bv9ARM.ch04.html
doc/arm/Bv9ARM.ch05.html
doc/arm/Bv9ARM.ch06.html
doc/arm/Bv9ARM.ch07.html
doc/arm/Bv9ARM.ch08.html
doc/arm/Bv9ARM.ch09.html
doc/arm/Bv9ARM.ch10.html
doc/arm/Bv9ARM.ch11.html
doc/arm/Bv9ARM.ch12.html
doc/arm/Bv9ARM.ch13.html
doc/arm/Bv9ARM.html
doc/arm/man.arpaname.html
doc/arm/man.ddns-confgen.html
doc/arm/man.delv.html
doc/arm/man.dig.html
doc/arm/man.dnssec-checkds.html
doc/arm/man.dnssec-coverage.html
doc/arm/man.dnssec-dsfromkey.html
doc/arm/man.dnssec-importkey.html
doc/arm/man.dnssec-keyfromlabel.html
doc/arm/man.dnssec-keygen.html
doc/arm/man.dnssec-revoke.html
doc/arm/man.dnssec-settime.html
doc/arm/man.dnssec-signzone.html
doc/arm/man.dnssec-verify.html
doc/arm/man.genrandom.html
doc/arm/man.host.html
doc/arm/man.isc-hmac-fixup.html
doc/arm/man.lwresd.html
doc/arm/man.named-checkconf.html
doc/arm/man.named-checkzone.html
doc/arm/man.named-journalprint.html
doc/arm/man.named-rrchecker.html
doc/arm/man.named.conf.html
doc/arm/man.named.html
doc/arm/man.nsec3hash.html
doc/arm/man.nsupdate.html
doc/arm/man.rndc-confgen.html
doc/arm/man.rndc.conf.html
doc/arm/man.rndc.html
doc/arm/notes.html

index ca212014144fd4ac3aec310dfe516d53f224208b..2fba951a67afe182c5bb93e6f5da6da21fcc1dcd 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 5549123ddac4fe0ea739ede33d3bbdf6d526c12d..0dcaad9f15bb9cb15da38bd7a5998e47ae6d101d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index e2c869f4b6416af90de21282da6f08cd1556fb30..9e6c31d4047874b1bbaf7b1fc10481189b0dd284 100644 (file)
@@ -768,6 +768,6 @@ controls {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index ec4e7ba789da094cb59d2ceb10253aeb7db4a9f7..b27a4fa5495e61cb72a7673b9d2e3ca21fba0f51 100644 (file)
@@ -2498,6 +2498,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index b4f58c0d586d149f2247f6eae80ce6ab4dddf8a9..05576be5dcf491129ebb561cc0cd2ead3aea1b8d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 979f713aba7911da05341de197f3e78f4e0ce0bd..29377ce35e83a2e3f093777f6d4116a99a110870 100644 (file)
@@ -13790,6 +13790,6 @@ HOST-127.EXAMPLE. MX 0 .
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 4cbd9fb8090654d154bf5d13b53492563bca65de..2837791511aa1023fe19842ee75ce50b5847df23 100644 (file)
@@ -262,6 +262,6 @@ zone "example.com" {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 9ce22731a0f2fcda89485995e8c3f9001ae34409..364a959a2bfc1351e1409bd88e84fffc812cb2cf 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index bc991108a65ebb32bdee9135e62d8e23e66f4835..f77bdd2ef2fb9331dae02e27b9da01a5592386e9 100644 (file)
 <div class="toc">
 <p><b>Table of Contents</b></p>
 <dl class="toc">
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.10.5</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.10.5-P1</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#root_key">New DNSSEC Root Key</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_features">New Features</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_maint">Maintenance</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_thanks">Thank You</a></span></dt>
 </dl></dd>
 </div>
       <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.10.2"></a>Release Notes for BIND Version 9.10.5</h2></div></div></div>
+<a name="id-1.10.2"></a>Release Notes for BIND Version 9.10.5-P1</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
     <p>
-      This document summarizes changes since the last production
-      release on the BIND 9.10 branch.
-      Please see the <code class="filename">CHANGES</code> file for a further
-      list of bug fixes and other changes.
+      This document summarizes changes since BIND 9.10.5:
+    </p>
+    <p>
+      BIND 9.10.5-P1 addresses the security issues described in
+      CVE-2017-3140 and CVE-2017-3141.
     </p>
   </div>
 
+
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_download"></a>Download</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
 <li class="listitem">
        <p>
-         <span class="command"><strong>rndc ""</strong></span> could trigger an assertion failure
-         in <span class="command"><strong>named</strong></span>. This flaw is disclosed in
-         (CVE-2017-3138). [RT #44924]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Some chaining (i.e., type CNAME or DNAME) responses to upstream
-         queries could trigger assertion failures. This flaw is disclosed
-         in CVE-2017-3137. [RT #44734]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>dns64</strong></span> with <span class="command"><strong>break-dnssec yes;</strong></span>
-         can result in an assertion failure. This flaw is disclosed in
-         CVE-2017-3136. [RT #44653]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         If a server is configured with a response policy zone (RPZ)
-         that rewrites an answer with local data, and is also configured
-         for DNS64 address mapping, a NULL pointer can be read
-         triggering a server crash.  This flaw is disclosed in
-         CVE-2017-3135. [RT #44434]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could mishandle authority sections
-         with missing RRSIGs, triggering an assertion failure. This
-         flaw is disclosed in CVE-2016-9444. [RT #43632]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> mishandled some responses where
-         covering RRSIG records were returned without the requested
-         data, resulting in an assertion failure. This flaw is
-         disclosed in CVE-2016-9147. [RT #43548]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> incorrectly tried to cache TKEY
-         records which could trigger an assertion failure when there was
-         a class mismatch. This flaw is disclosed in CVE-2016-9131.
-         [RT #43522]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         It was possible to trigger assertions when processing
-         responses containing answers of type DNAME. This flaw is
-         disclosed in CVE-2016-8864. [RT #43465]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Added the ability to specify the maximum number of records
-         permitted in a zone (<code class="option">max-records #;</code>).
-         This provides a mechanism to block overly large zone
-         transfers, which is a potential risk with slave zones from
-         other parties, as described in CVE-2016-6170.
-         [RT #42143]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         It was possible to trigger an assertion when rendering a
-         message using a specially crafted request. This flaw is
-         disclosed in CVE-2016-2776. [RT #43139]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Calling <span class="command"><strong>getrrsetbyname()</strong></span> with a non
-         absolute name could trigger an infinite recursion bug in
-         <span class="command"><strong>lwresd</strong></span> or <span class="command"><strong>named</strong></span> with
-         <span class="command"><strong>lwres</strong></span> configured if, when combined with
-         a search list entry from <code class="filename">resolv.conf</code>,
-         the resulting name is too long.  This flaw is disclosed in
-         CVE-2016-2775. [RT #42694]
-       </p>
-      </li>
-</ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_features"></a>New Features</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> now provides feedback to the
-         owners of zones which have trust anchors configured
-         (<span class="command"><strong>trusted-keys</strong></span>,
-         <span class="command"><strong>managed-keys</strong></span>, <span class="command"><strong>dnssec-validation
-         auto;</strong></span> and <span class="command"><strong>dnssec-lookaside auto;</strong></span>)
-         by sending a daily query which encodes the keyids of the
-         configured trust anchors for the zone.  This is controlled
-         by <span class="command"><strong>trust-anchor-telemetry</strong></span> and defaults
-         to yes.
+         The BIND installer on Windows used an unquoted service path,
+         which can enable privilege escalation. This flaw is disclosed
+         in CVE-2017-3141. [RT #45229]
        </p>
       </li>
 <li class="listitem">
        <p>
-         A new <span class="command"><strong>tcp-only</strong></span> option has been added to
-         <span class="command"><strong>server</strong></span> clauses, to indicate that UDP should
-         not be used when sending queries to a specified IP address or
-         prefix.
+         With certain RPZ configurations, a response with TTL 0
+         could cause <span class="command"><strong>named</strong></span> to go into an infinite
+         query loop. This flaw is disclosed in CVE-2017-3140.
+         [RT #45181]
        </p>
       </li>
 </ul></div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         The ISC DNSSEC Lookaside Validation (DLV) service is scheduled
-         to be disabled in 2017.  A warning is now logged when
-         <span class="command"><strong>named</strong></span> is configured to use this service,
-         either explicitly or via <code class="option">dnssec-lookaside auto;</code>.
-         [RT #42207]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         If an ACL is specified with an address prefix in which the
-         prefix length is longer than the address portion (for example,
-         192.0.2.1/8), <span class="command"><strong>named</strong></span> will now log a warning.
-         In future releases this will be a fatal configuration error.
-         [RT #43367]
-       </p>
-      </li>
-</ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         A synthesized CNAME record appearing in a response before the
-         associated DNAME could be cached, when it should not have been.
-         This was a regression introduced while addressing CVE-2016-8864.
-         [RT #44318]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could deadlock if multiple changes
-         to NSEC/NSEC3 parameters for the same zone were being processed
-         at the same time. [RT #42770]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could trigger an assertion when
-         sending NOTIFY messages. [RT #44019]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Fixed a crash when calling <span class="command"><strong>rndc stats</strong></span> on some
-         Windows builds: some Visual Studio compilers generate code that
-         crashes when the "%z" printf() format specifier is used. [RT #42380]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Windows installs were failing due to triggering UAC without
-         the installation binary being signed.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         A change in the internal binary representation of the RBT database
-         node structure enabled a race condition to occur (especially when
-         BIND was built with certain compilers or optimizer settings),
-         leading to inconsistent database state which caused random
-         assertion failures. [RT #42380]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Referencing a nonexistent zone in a <span class="command"><strong>response-policy</strong></span>
-         statement could cause an assertion failure during configuration.
-         [RT #43787]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>rndc addzone</strong></span> could cause a crash
-         when attempting to add a zone with a type other than
-         <span class="command"><strong>master</strong></span> or <span class="command"><strong>slave</strong></span>.
-         Such zones are now rejected. [RT #43665]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could hang when encountering log
-         file names with large apparent gaps in version number (for
-         example, when files exist called "logfile.0", "logfile.1",
-         and "logfile.1482954169").  This is now handled correctly.
-         [RT #38688]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         If a zone was updated while <span class="command"><strong>named</strong></span> was
-         processing a query for nonexistent data, it could return
-         out-of-sync NSEC3 records causing potential DNSSEC validation
-         failure. [RT #43247]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could crash when loading a zone
-         which had RRISG records whose expiry fields were far enough
-         apart to cause an integer overflow when comparing them.
-         [RT #40571]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The <span class="command"><strong>arpaname</strong></span> and <span class="command"><strong>named-rrchecker</strong></span>
-         commands were not installed into the correct
-         <span class="command"><strong>prefix</strong></span><code class="filename">/bin</code> directory.
-         [RT #42910]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         When receiving a response from an authoritative server with
-         a TTL value of zero, <span class="command"><strong>named&gt;</strong></span> will now only use
-         that response once, to answer the currently active clients that
-         were waiting for it. Previously, such response could be cached
-         and reused for up to one second. [RT #42142]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named-checkconf</strong></span> now checks the
-         <span class="command"><strong>rate-limit</strong></span> clause for correctness.
-         [RT #42970]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Corrected a bug in the <span class="command"><strong>rndc</strong></span> control channel
-         that could allow a read past the end of a buffer, crashing
-         <span class="command"><strong>named</strong></span>. Thanks to Lian Yihan for reporting
-         this error.
-       </p>
-      </li>
-</ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_maint"></a>Maintenance</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
-       <p>
-         The built-in root hints have been updated to include
-         IPv6 addresses for B.ROOT-SERVERS.NET (2001:500:84::b),
-         E.ROOT-SERVERS.NET (2001:500:a8::e) and
-         G.ROOT-SERVERS.NET (2001:500:12::d0d).
-       </p>
-      </li></ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
 <a name="end_of_life"></a>End of Life</h3></div></div></div>
     <p>
       The end of life for BIND 9.10 is yet to be determined but
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 1d9dfda78f216d8268a1be132141095477bb2a0f..12e143741382b13bee6a5b84da8bee8a8375ca22 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 05c04ff26c92dbdb9ff5507a4384e4d7f03d30f5..0e4b8505cb97997e7e4ccd6a3c6f735f84138efa 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 6289ec9e3d93f378fcd5cf59944245e6899ff476..28d5fdb7c26ff34df87a5b5e1bf3d51840adbedc 100644 (file)
@@ -584,6 +584,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index cbdf525c107ec36a35d448177a8529ecc671ec91..da0af8121ead1558e2e0d832e67601df49725507 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 954b49f5fa7cf734d886951c6a501fc3c35d25f3..15dd6db2e331928027a23696e7a856a947fa3969 100644 (file)
@@ -41,7 +41,7 @@
 <div>
 <div><h1 class="title">
 <a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
-<div><p class="releaseinfo">BIND Version 9.10.5</p></div>
+<div><p class="releaseinfo">BIND Version 9.10.5-P1</p></div>
 <div><p class="copyright">Copyright Â© 2004-2016 Internet Systems Consortium, Inc. ("ISC")</p></div>
 <div><p class="copyright">Copyright Â© 2000-2003 Internet Software Consortium.</p></div>
 </div>
 </dl></dd>
 <dt><span class="appendix"><a href="Bv9ARM.ch09.html">A. Release Notes</a></span></dt>
 <dd><dl>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.10.5</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.10.5-P1</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#root_key">New DNSSEC Root Key</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_features">New Features</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_maint">Maintenance</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_thanks">Thank You</a></span></dt>
 </dl></dd>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index f3c9d24820dc378c9ea9a166e01ff5e186370ade..317f46190da997b22994ce3527bd146abaecba85 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 092988e5f762d18e62dc4188dd677fb7c6f2bb35..3399ca910373c50b061562321e7c277a2ad398db 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index c8eefe0099d1ad0510d38fe76f8f0eafde14055e..3aa9949c2bfd2b06fbb742698dba05ed7b80a14d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 696bfc35e6ba2e8584d9571f3f500570bc5de00d..721d7262fb3a9b457a6ec93ed7eed7b0389d255c 100644 (file)
@@ -1035,6 +1035,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index f7141b7c08d1a5b5803fa2cc37171af5f1745c08..5d9d3cbb05533e5d0fe806e329d84f97514de971 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index c3d457c0af30a154be1677acded9e52f27f3430c..5dd7a741b2d7306b77c44fe9cb77a356eaec1c0b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 594b6503a1e547ca2ec52d0513c09fb352afacf6..6ea6eb3092c5e74813b2fd8e0c6e409e80df6b1c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index a3f4879e7aa685a86b9c5d81a760c7c6636c6b2f..a91cb3824f3364f136ff39788e83eae5ab7c8346 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 7d2b1e550f50efde50a295dbc4a563b5ef3776ac..3bdc2c1ae1756614f3141c56dcf296e6363f0af7 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 2677b7c9baa662025d456dfc2ba9b6bf0a45ac1b..daf6f1e837309265df373e28756d6322d20783c2 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 772624c1196eb6fb81f93c70eff220a1410e2203..fc10a245c7c255db103cc69c4ae7fcff504d6617 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 6553a31f44efd334bd8f8341c146cc9e4700d50f..a43172bfecc1aef72b7c8575447f307f396b0e31 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index ca8471ff94f10fad80ae855bed7d67e3135c13a0..ccb17bcc113e2bf8b630e13125c80a3163ad0ae3 100644 (file)
@@ -711,6 +711,6 @@ db.example.com.signed
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 77306812804dbdf03d172ff63f4d992a5384226e..248ecb31ffe30092b2969a2c5205a81f12edad61 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 536588e2d446a2fc1e2a3b0fa5cdfb897a6fabb7..2bd50484e1b4438686f9960940ae17b3c6bfc415 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index e7c95dff7cd058550d1b752eee77a622eb8b0435..dcc8756d4a3cd60ebf2a43e6d2862261bc62e0c1 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 59a55b11671c48307059f0223d4352a9e7a9ffc5..01a4f3eab9b7a941b4134de95aa3cb9c9b3178f2 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index fbb794386725299f4b6188ddf297335e2af419de..c71182d6bc4a9002375be321a3efa7f33de1e73a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 88c15ef055c6aff3923a217dcec399a0daf42d4f..b516cfb4a3c0377da54a15516ad7a6a3dc2fcbf0 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 2a4361d097782fe605dac8022327dbed24a9b934..a6a40fcd4ce9fc8bfd1a038964c97611ffb5e07c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index b0f1d320da3069b01c698be2e7c61c6714914dd2..86f3fd62f30b91c621a22793b3cb05cc78c00b1b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 8a384e3c40238573f261b1fd2457df3a8f89a937..00eac33cb5dfd622b106b78b2f414bf2ecf76a82 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index c90987f948366f583c751bb5027f703c9279bef2..11e42a76576c93ae626f0dff6cdcef4e6104007c 100644 (file)
@@ -736,6 +736,6 @@ zone
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 975f09f38eb41c733ba4265208e0dc7da2a65477..a1397802e470a033e66bcd3f3fa3d7e8bb5eafda 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 12fd637bfa0e95f81f20f26cbbeccaf2acf4a45b..e5a6266d273450dbb5a435fa1b237edcdc60e9ec 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index e94efd29ac12894a3b3e9e78216371e91b4d5594..9fff60e4ad62aa9b681337c3b2b78309283be08c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 8a6f154212485fe8e81be0e4a1835b44096893d1..f7afed2191603e9c1f0667b086ddc2cf44821afd 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index ba3d18921dab097701c8e0053ff5366692917854..347e1aea0808009ce31919bcf05f8136ec9408ba 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 6a8b50c555400d7631f3dbdbe90e56b807dffd99..8a762ffff69643c048f695553b3782dc90560eaf 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.10.5-P1</p>
 </body>
 </html>
index 54f77a0675edb0c49862418bc155fb76b30c2582..acfd124f87b2ca0d879fabbd28445dc9b22857a1 100644 (file)
 
   <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.2"></a>Release Notes for BIND Version 9.10.5</h2></div></div></div>
+<a name="id-1.2"></a>Release Notes for BIND Version 9.10.5-P1</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
     <p>
-      This document summarizes changes since the last production
-      release on the BIND 9.10 branch.
-      Please see the <code class="filename">CHANGES</code> file for a further
-      list of bug fixes and other changes.
+      This document summarizes changes since BIND 9.10.5:
+    </p>
+    <p>
+      BIND 9.10.5-P1 addresses the security issues described in
+      CVE-2017-3140 and CVE-2017-3141.
     </p>
   </div>
 
+
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_download"></a>Download</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
 <li class="listitem">
        <p>
-         <span class="command"><strong>rndc ""</strong></span> could trigger an assertion failure
-         in <span class="command"><strong>named</strong></span>. This flaw is disclosed in
-         (CVE-2017-3138). [RT #44924]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Some chaining (i.e., type CNAME or DNAME) responses to upstream
-         queries could trigger assertion failures. This flaw is disclosed
-         in CVE-2017-3137. [RT #44734]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>dns64</strong></span> with <span class="command"><strong>break-dnssec yes;</strong></span>
-         can result in an assertion failure. This flaw is disclosed in
-         CVE-2017-3136. [RT #44653]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         If a server is configured with a response policy zone (RPZ)
-         that rewrites an answer with local data, and is also configured
-         for DNS64 address mapping, a NULL pointer can be read
-         triggering a server crash.  This flaw is disclosed in
-         CVE-2017-3135. [RT #44434]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could mishandle authority sections
-         with missing RRSIGs, triggering an assertion failure. This
-         flaw is disclosed in CVE-2016-9444. [RT #43632]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> mishandled some responses where
-         covering RRSIG records were returned without the requested
-         data, resulting in an assertion failure. This flaw is
-         disclosed in CVE-2016-9147. [RT #43548]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> incorrectly tried to cache TKEY
-         records which could trigger an assertion failure when there was
-         a class mismatch. This flaw is disclosed in CVE-2016-9131.
-         [RT #43522]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         It was possible to trigger assertions when processing
-         responses containing answers of type DNAME. This flaw is
-         disclosed in CVE-2016-8864. [RT #43465]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Added the ability to specify the maximum number of records
-         permitted in a zone (<code class="option">max-records #;</code>).
-         This provides a mechanism to block overly large zone
-         transfers, which is a potential risk with slave zones from
-         other parties, as described in CVE-2016-6170.
-         [RT #42143]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         It was possible to trigger an assertion when rendering a
-         message using a specially crafted request. This flaw is
-         disclosed in CVE-2016-2776. [RT #43139]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Calling <span class="command"><strong>getrrsetbyname()</strong></span> with a non
-         absolute name could trigger an infinite recursion bug in
-         <span class="command"><strong>lwresd</strong></span> or <span class="command"><strong>named</strong></span> with
-         <span class="command"><strong>lwres</strong></span> configured if, when combined with
-         a search list entry from <code class="filename">resolv.conf</code>,
-         the resulting name is too long.  This flaw is disclosed in
-         CVE-2016-2775. [RT #42694]
-       </p>
-      </li>
-</ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_features"></a>New Features</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> now provides feedback to the
-         owners of zones which have trust anchors configured
-         (<span class="command"><strong>trusted-keys</strong></span>,
-         <span class="command"><strong>managed-keys</strong></span>, <span class="command"><strong>dnssec-validation
-         auto;</strong></span> and <span class="command"><strong>dnssec-lookaside auto;</strong></span>)
-         by sending a daily query which encodes the keyids of the
-         configured trust anchors for the zone.  This is controlled
-         by <span class="command"><strong>trust-anchor-telemetry</strong></span> and defaults
-         to yes.
+         The BIND installer on Windows used an unquoted service path,
+         which can enable privilege escalation. This flaw is disclosed
+         in CVE-2017-3141. [RT #45229]
        </p>
       </li>
 <li class="listitem">
        <p>
-         A new <span class="command"><strong>tcp-only</strong></span> option has been added to
-         <span class="command"><strong>server</strong></span> clauses, to indicate that UDP should
-         not be used when sending queries to a specified IP address or
-         prefix.
+         With certain RPZ configurations, a response with TTL 0
+         could cause <span class="command"><strong>named</strong></span> to go into an infinite
+         query loop. This flaw is disclosed in CVE-2017-3140.
+         [RT #45181]
        </p>
       </li>
 </ul></div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         The ISC DNSSEC Lookaside Validation (DLV) service is scheduled
-         to be disabled in 2017.  A warning is now logged when
-         <span class="command"><strong>named</strong></span> is configured to use this service,
-         either explicitly or via <code class="option">dnssec-lookaside auto;</code>.
-         [RT #42207]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         If an ACL is specified with an address prefix in which the
-         prefix length is longer than the address portion (for example,
-         192.0.2.1/8), <span class="command"><strong>named</strong></span> will now log a warning.
-         In future releases this will be a fatal configuration error.
-         [RT #43367]
-       </p>
-      </li>
-</ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         A synthesized CNAME record appearing in a response before the
-         associated DNAME could be cached, when it should not have been.
-         This was a regression introduced while addressing CVE-2016-8864.
-         [RT #44318]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could deadlock if multiple changes
-         to NSEC/NSEC3 parameters for the same zone were being processed
-         at the same time. [RT #42770]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could trigger an assertion when
-         sending NOTIFY messages. [RT #44019]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Fixed a crash when calling <span class="command"><strong>rndc stats</strong></span> on some
-         Windows builds: some Visual Studio compilers generate code that
-         crashes when the "%z" printf() format specifier is used. [RT #42380]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Windows installs were failing due to triggering UAC without
-         the installation binary being signed.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         A change in the internal binary representation of the RBT database
-         node structure enabled a race condition to occur (especially when
-         BIND was built with certain compilers or optimizer settings),
-         leading to inconsistent database state which caused random
-         assertion failures. [RT #42380]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Referencing a nonexistent zone in a <span class="command"><strong>response-policy</strong></span>
-         statement could cause an assertion failure during configuration.
-         [RT #43787]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>rndc addzone</strong></span> could cause a crash
-         when attempting to add a zone with a type other than
-         <span class="command"><strong>master</strong></span> or <span class="command"><strong>slave</strong></span>.
-         Such zones are now rejected. [RT #43665]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could hang when encountering log
-         file names with large apparent gaps in version number (for
-         example, when files exist called "logfile.0", "logfile.1",
-         and "logfile.1482954169").  This is now handled correctly.
-         [RT #38688]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         If a zone was updated while <span class="command"><strong>named</strong></span> was
-         processing a query for nonexistent data, it could return
-         out-of-sync NSEC3 records causing potential DNSSEC validation
-         failure. [RT #43247]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could crash when loading a zone
-         which had RRISG records whose expiry fields were far enough
-         apart to cause an integer overflow when comparing them.
-         [RT #40571]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The <span class="command"><strong>arpaname</strong></span> and <span class="command"><strong>named-rrchecker</strong></span>
-         commands were not installed into the correct
-         <span class="command"><strong>prefix</strong></span><code class="filename">/bin</code> directory.
-         [RT #42910]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         When receiving a response from an authoritative server with
-         a TTL value of zero, <span class="command"><strong>named&gt;</strong></span> will now only use
-         that response once, to answer the currently active clients that
-         were waiting for it. Previously, such response could be cached
-         and reused for up to one second. [RT #42142]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named-checkconf</strong></span> now checks the
-         <span class="command"><strong>rate-limit</strong></span> clause for correctness.
-         [RT #42970]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Corrected a bug in the <span class="command"><strong>rndc</strong></span> control channel
-         that could allow a read past the end of a buffer, crashing
-         <span class="command"><strong>named</strong></span>. Thanks to Lian Yihan for reporting
-         this error.
-       </p>
-      </li>
-</ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_maint"></a>Maintenance</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
-       <p>
-         The built-in root hints have been updated to include
-         IPv6 addresses for B.ROOT-SERVERS.NET (2001:500:84::b),
-         E.ROOT-SERVERS.NET (2001:500:a8::e) and
-         G.ROOT-SERVERS.NET (2001:500:12::d0d).
-       </p>
-      </li></ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
 <a name="end_of_life"></a>End of Life</h3></div></div></div>
     <p>
       The end of life for BIND 9.10 is yet to be determined but