]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
prep 9.11.28
authorTinderbox User <tbox@isc.org>
Thu, 4 Feb 2021 13:05:28 +0000 (13:05 +0000)
committerTinderbox User <tbox@isc.org>
Thu, 4 Feb 2021 13:05:28 +0000 (13:05 +0000)
61 files changed:
CHANGES
README
README.md
doc/arm/Bv9ARM.ch01.html
doc/arm/Bv9ARM.ch02.html
doc/arm/Bv9ARM.ch03.html
doc/arm/Bv9ARM.ch04.html
doc/arm/Bv9ARM.ch05.html
doc/arm/Bv9ARM.ch06.html
doc/arm/Bv9ARM.ch07.html
doc/arm/Bv9ARM.ch08.html
doc/arm/Bv9ARM.ch09.html
doc/arm/Bv9ARM.ch10.html
doc/arm/Bv9ARM.ch11.html
doc/arm/Bv9ARM.ch12.html
doc/arm/Bv9ARM.ch13.html
doc/arm/Bv9ARM.html
doc/arm/Bv9ARM.pdf
doc/arm/man.arpaname.html
doc/arm/man.ddns-confgen.html
doc/arm/man.delv.html
doc/arm/man.dig.html
doc/arm/man.dnssec-checkds.html
doc/arm/man.dnssec-coverage.html
doc/arm/man.dnssec-dsfromkey.html
doc/arm/man.dnssec-importkey.html
doc/arm/man.dnssec-keyfromlabel.html
doc/arm/man.dnssec-keygen.html
doc/arm/man.dnssec-keymgr.html
doc/arm/man.dnssec-revoke.html
doc/arm/man.dnssec-settime.html
doc/arm/man.dnssec-signzone.html
doc/arm/man.dnssec-verify.html
doc/arm/man.dnstap-read.html
doc/arm/man.genrandom.html
doc/arm/man.host.html
doc/arm/man.isc-hmac-fixup.html
doc/arm/man.lwresd.html
doc/arm/man.mdig.html
doc/arm/man.named-checkconf.html
doc/arm/man.named-checkzone.html
doc/arm/man.named-journalprint.html
doc/arm/man.named-nzd2nzf.html
doc/arm/man.named-rrchecker.html
doc/arm/man.named.conf.html
doc/arm/man.named.html
doc/arm/man.nsec3hash.html
doc/arm/man.nslookup.html
doc/arm/man.nsupdate.html
doc/arm/man.pkcs11-destroy.html
doc/arm/man.pkcs11-keygen.html
doc/arm/man.pkcs11-list.html
doc/arm/man.pkcs11-tokens.html
doc/arm/man.rndc-confgen.html
doc/arm/man.rndc.conf.html
doc/arm/man.rndc.html
doc/arm/notes.html
doc/arm/notes.pdf
doc/arm/notes.txt
lib/dns/api
version

diff --git a/CHANGES b/CHANGES
index 86bcfcbd68169fac0e6f47fc4a38c1e2a728f504..e5c2b5c35a8f50b2c45992616e2317736f93bf5b 100644 (file)
--- a/CHANGES
+++ b/CHANGES
@@ -1,3 +1,5 @@
+       --- 9.11.28 released ---
+
 5562.  [security]      Fix off-by-one bug in ISC SPNEGO implementation.
                        (CVE-2020-8625) [GL #2354]
 
diff --git a/README b/README
index bdd6b563c3ce7910c517d7ba23f8e7d914d2754c..f2b6ab44bcb8804a7b6e5657680da575997de536 100644 (file)
--- a/README
+++ b/README
@@ -368,6 +368,11 @@ BIND 9.11.27
 
 BIND 9.11.27 is a maintenance release.
 
+BIND 9.11.28
+
+BIND 9.11.28 is a maintenance release, and also addresses the security
+vulnerability disclosed in CVE-2020-8625.
+
 Building BIND
 
 Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
index d4fa43dffcbd8281461d9905c8909adead123bd1..94f2b1f7975c73e28ab5563f4de6a77fe6df6cec 100644 (file)
--- a/README.md
+++ b/README.md
@@ -385,6 +385,11 @@ BIND 9.11.26 is a maintenance release.
 
 BIND 9.11.27 is a maintenance release.
 
+#### BIND 9.11.28
+
+BIND 9.11.28 is a maintenance release, and also addresses the security
+vulnerability disclosed in CVE-2020-8625.
+
 ### <a name="build"/> Building BIND
 
 Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
index 1bb6296e424de058f913c26596312561107602dc..4c11710f0601316a55d39fff0c66d201d79c347a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 3ec6e6cdbfcab912097bc1309a5c1b7a80f5c4d9..e95ca49ca8b267443237bd430ad0196be41a925d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index eebcd9759a880739198552183f2faad911d399d6..820cd5648a209a6ff451b6cdb8f13cca9f50c7c7 100644 (file)
@@ -654,6 +654,6 @@ controls {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 6e9707a2daba0fe46a9d0864f7bbd8352274e374..4df9806be915e77492a8cd0ee0aaf9b8a0829c05 100644 (file)
@@ -2664,6 +2664,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index d8f3551d8fddc36e74c654c1454bb04ad571733d..18d4347cb1639870bd51738ddcc40c7d87bac718 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 384166a47d20018fd0cd4bb2a48a893731f4f5b8..1d87c7c17def9caeee17aa0009fb4d9ee927cd89 100644 (file)
@@ -12842,6 +12842,6 @@ HOST-127.EXAMPLE. MX 0 .
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 07510f763ca39a211212d79258e4b13db9770206..0ed34f9fa43e3631a278dcd299bf9fc88edf5e4d 100644 (file)
@@ -384,6 +384,6 @@ allow-query { !{ !10/8; any; }; key example; };
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 8897e0bf38488f79c17d232f5a97947922f4b8f4..5e6439b8c0462714c9f377c9f5f00d2671a3301a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index edfbd5a1c2d880becc7683aec7cc9f1d3ddf64a4..bdec569563192313ff234a6a3b9914fb68163e35 100644 (file)
 <div class="toc">
 <p><b>Table of Contents</b></p>
 <dl class="toc">
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.27</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.28</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_license">License Change</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.28">Notes for BIND 9.11.28</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.27">Notes for BIND 9.11.27</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.26">Notes for BIND 9.11.26</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.25">Notes for BIND 9.11.25</a></span></dt>
@@ -76,7 +77,7 @@
 </div>
 <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.10.2"></a>Release Notes for BIND Version 9.11.27</h2></div></div></div>
+<a name="id-1.10.2"></a>Release Notes for BIND Version 9.11.28</h2></div></div></div>
 <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
 </div>
 <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
+<a name="relnotes-9.11.28"></a>Notes for BIND 9.11.28</h3></div></div></div>
+<div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.11.28-security"></a>Security Fixes</h4></div></div></div>
+<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+<p>
+          When <span class="command"><strong>tkey-gssapi-keytab</strong></span> or
+          <span class="command"><strong>tkey-gssapi-credential</strong></span> was configured, a specially
+          crafted GSS-TSIG query could cause a buffer overflow in the ISC
+          implementation of SPNEGO (a protocol enabling negotiation of the
+          security mechanism to use for GSSAPI authentication). This flaw could
+          be exploited to crash <span class="command"><strong>named</strong></span>. Theoretically, it also
+          enabled remote code execution, but achieving the latter is very
+          difficult in real-world conditions. (CVE-2020-8625)
+        </p>
+<p>
+          This vulnerability was responsibly reported to us as ZDI-CAN-12302 by
+          Trend Micro Zero Day Initiative. [GL #2354]
+        </p>
+</li></ul></div>
+</div>
+</div>
+<div class="section">
+<div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes-9.11.27"></a>Notes for BIND 9.11.27</h3></div></div></div>
 <div class="section">
 <div class="titlepage"><div><div><h4 class="title">
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index ea130e0ec5110369f1f509a58a5d1ee37f172edc..9f04e47d62e31cb190ab166c1e9636b6be56d0e8 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 162f5cb663f2be27189867097dec813c6a843bc7..04f5f139fafdd9446649e08cadaf040624753e51 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index cab66d7424df4fbf5e66311facfd3389f220bffb..76ae6da295d4afe29186e2d2d92b015cf7133e32 100644 (file)
@@ -473,6 +473,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 9e47c6dfdc53945bd8a66138d1e8081b5b4de036..7c24d8d359378ae8b444de58370194131a105bf3 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 7994a2fdb2a8c5a152485273f28131f6a0410717..ba08bd0a782a553101577655fc0bd49b9d506c63 100644 (file)
@@ -32,7 +32,7 @@
 <div>
 <div><h1 class="title">
 <a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
-<div><p class="releaseinfo">BIND Version 9.11.27</p></div>
+<div><p class="releaseinfo">BIND Version 9.11.28</p></div>
 <div><p class="copyright">Copyright © 2000-2021 Internet Systems Consortium, Inc. ("ISC")</p></div>
 </div>
 <hr>
 </dl></dd>
 <dt><span class="appendix"><a href="Bv9ARM.ch09.html">A. Release Notes</a></span></dt>
 <dd><dl>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.27</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.28</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_license">License Change</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.28">Notes for BIND 9.11.28</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.27">Notes for BIND 9.11.27</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.26">Notes for BIND 9.11.26</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes-9.11.25">Notes for BIND 9.11.25</a></span></dt>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index f4afed30567cd29b5671eb515a0e070d77bae758..5d37e8d2cad626d9599a9302cc8065205d08cf22 100644 (file)
Binary files a/doc/arm/Bv9ARM.pdf and b/doc/arm/Bv9ARM.pdf differ
index 68b89c2c376a4346df1ad6c0571a856f5240b2a4..5cb58da3d2f2bbe2a6d411cdc30b91dd019bce5a 100644 (file)
@@ -72,6 +72,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index e984a6a6039996dcf8445706f76f34664746c495..2fd30aadc04e2faf25da051f1f9d36612ee1418e 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 8affee0569fea2a630969da90fe0733d759b4501..dd02c21dc3181b7834e6c965469f0c165349edaa 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index ec1619e86aaaee291200e6f7a45140ed68147777..86222f7cd65014dd8ea432f084755e65879a9c25 100644 (file)
@@ -919,6 +919,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index e7d869a7ba08f3ad37dc9e10a5d99e9075bb5d9b..bb6ce8ae8bd7644e89899c1985835f1e3d9aa0c0 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 590676ee636b9480aaec3866831f11429a4c6720..92e2eb673cb4fb3ba392f379eaa55450035ab3ab 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index f394f33ebb8050099763f2755e676baa1852c0ba..dc8db75f2fc1abc36bf2c4286fc89bd62be88cb8 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 362c858c33f6c7c68bdc94b6489ddabc7b2da28a..fb7fa6b5dc67779a327da3b5866e051dee134925 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index f901c754cacacb4e2a32f362591dad6e32de09df..2dbe410f7216bfe0ccb441590c384b5db0f91375 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index ae6fc389b68cc16950b5199ebb726e393549b36f..9622c358e746cfd45927b8c58b1932eb25e5bc73 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index acd7e4b24b6e3612858ff6cc0974105b54f742cb..05052cd64ec5c64a23c1463818cb1f547dbda88f 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 496be1388e0aa4cbc20c306b8eed5bbe450b40c9..5f06260c8425674d9b4b169c4be322de5898fa87 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index a712c02336d8dda1b05782beeec61012c37097ce..81995e299128fbdacf9ca0954bde706ad4574800 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 2ecc630d7a31e7b4cda832d72d401dcc1a194f6d..c6df0664475b91d8c45c74fe9184b3beb0f29b9e 100644 (file)
@@ -559,6 +559,6 @@ db.example.com.signed
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index a0b05d1d7aa8a90e1f7ef6884247a5f68d768f74..e37bd6ed74136cd8bfcd0ffc057a4ff0d486bb8f 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index d9e5c7df0c318bf90a9e0b4a334e4207ad9d342e..667ec8a4fc3b714342e71fbfd9456d04c4c95895 100644 (file)
@@ -99,6 +99,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 310a08f4661c805ffc433bd2ed4c485063610868..d856ba7647a1ecfb868eef77720f227cd6f94584 100644 (file)
@@ -93,6 +93,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 4d422951f664e684bf1fd5d67a7a0360bbaea35b..2984cea966e1fea445cdd18a640e6bf9bfef8c1d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index ca79c708533583ec41ad1ec91b7322d789280558..ad4f8fb19f57c7bed5b4d37e4b3616857033fe80 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 809653857d33eabb639832e50cbd3d822d1dd08a..da910f28e7083369991e103b027989085a9dfe8c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index be309328b2f541b1ff9517a26108ff4033800cb3..ec9881ec4d6c2a47bcce0c8b75eb0a12880505fd 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index e2f8fa9ee9a5e977d75919d7815bcd6042b1189f..4533aeaf5aeef836c8dcfd531ef955c2269f1b58 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 2a5ece056e8a59ed401376ed664b31ff80423614..6c1e9a07e5b2d5d1fa9622c628a9dd31503b4a1c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 6a24004357ab2dddc50e760c28e43927d88ca66f..a297190ed8ea27e650e8617250cb7b4b8e9dfc1a 100644 (file)
@@ -94,6 +94,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 1933ad2ebc794836f21aaa7ad35539c8cd2fbf2c..c359c79d29024f78c446e998c49c1e98143de8fd 100644 (file)
@@ -95,6 +95,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 955b7babaa5f9c978d0a27b4269f96889b57caa0..d6c0d41032df0ea0114e90dc6d842fdebb0e2e21 100644 (file)
@@ -96,6 +96,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 876930e8a061182f7a7e70caa2fdc19a230aeb47..43e2273021103a84cd0d78940e28ba6d4f68f1bf 100644 (file)
@@ -974,6 +974,6 @@ zone
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 879f7d5a4a5bc5a483adc932abc6a1ec51264b70..7b926f3237f9def612b6100d6be547a6df1a979c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 42f80bbce21accab74b95d79b8e8b7aa765b87f9..e403417a32fa5455b9a4c51995cbe3d31bbf1571 100644 (file)
@@ -98,6 +98,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index c67a7e3140e20391974e392953cb28f11b1e38e7..9151c309db1c4b0aa2fdf9e17b78b59c9584396b 100644 (file)
@@ -362,6 +362,6 @@ nslookup -query=hinfo  -timeout=10
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index f58a1457e0105d6d918c19f9af31f8a2108067ba..35b1ee3f468f3a6829830ab2910b4268d9c0714d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index e0c270305635183e0ec1fb1aae6b510bf4a3d5ee..2a18c069df9e47f402942061336396da7e4e2fb2 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 81658e8e9e215f52f8cf61a1f786d2786f27d135..45e1b0e02fc167078f74a72d2efa2afdb3f0e962 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index f5e1fa88594ae8ee2dc7bf57277421f2f0eee5e0..2c3eab441e4dffa88de837ed7b2198ca6fcddc8b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index dee5233564cd5ac13d754ada7a7c05f2764d6206..40d6fd492019af1c77d787a71e897a5430ea1706 100644 (file)
@@ -91,6 +91,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 3baa1d7832908ee0b754c11448ee80224c4c6f2f..c5cb164899b022a4b15877f2756b42e12a8529b0 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 1ce144499c681bc23af5239ee63df29d2cbf2c7d..95ab19c0b549a9592c0b8a571e375c16a3c4d900 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index d7f13a1f076b3e9009bbbfc41df49e5d326c5d0b..b516c060666e6f0236ef68b56eb14320fd43000a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.27 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.28 (Extended Support Version)</p>
 </body>
 </html>
index 91dc2ed72a6c6f21141f88c0d1a5f68b0cdb409b..1ff37b3f97b8f4ef0bf1c3cdf828b20ad7234b44 100644 (file)
@@ -13,7 +13,7 @@
 </head>
 <body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="article"><div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.2"></a>Release Notes for BIND Version 9.11.27</h2></div></div></div>
+<a name="id-1.2"></a>Release Notes for BIND Version 9.11.28</h2></div></div></div>
 <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
 </div>
 <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
+<a name="relnotes-9.11.28"></a>Notes for BIND 9.11.28</h3></div></div></div>
+<div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.11.28-security"></a>Security Fixes</h4></div></div></div>
+<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+<p>
+          When <span class="command"><strong>tkey-gssapi-keytab</strong></span> or
+          <span class="command"><strong>tkey-gssapi-credential</strong></span> was configured, a specially
+          crafted GSS-TSIG query could cause a buffer overflow in the ISC
+          implementation of SPNEGO (a protocol enabling negotiation of the
+          security mechanism to use for GSSAPI authentication). This flaw could
+          be exploited to crash <span class="command"><strong>named</strong></span>. Theoretically, it also
+          enabled remote code execution, but achieving the latter is very
+          difficult in real-world conditions. (CVE-2020-8625)
+        </p>
+<p>
+          This vulnerability was responsibly reported to us as ZDI-CAN-12302 by
+          Trend Micro Zero Day Initiative. [GL #2354]
+        </p>
+</li></ul></div>
+</div>
+</div>
+<div class="section">
+<div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes-9.11.27"></a>Notes for BIND 9.11.27</h3></div></div></div>
 <div class="section">
 <div class="titlepage"><div><div><h4 class="title">
index 06bcd97fda548cae8b322abd32b830d4ff72bf3b..c1b445030f48650c678cb38d3c04d79eb0f0e88e 100644 (file)
Binary files a/doc/arm/notes.pdf and b/doc/arm/notes.pdf differ
index 4e9131a3f5c0371faec0f54f0d6b5ef2481a16e7..eeabdeae8beb24c3ac3bfdd6a31d9d62659cdea8 100644 (file)
@@ -1,4 +1,4 @@
-Release Notes for BIND Version 9.11.27
+Release Notes for BIND Version 9.11.28
 
 Introduction
 
@@ -36,6 +36,21 @@ Those unsure whether or not the license change affects their use of BIND,
 or who wish to discuss how to comply with the license may contact ISC at
 https://www.isc.org/mission/contact/.
 
+Notes for BIND 9.11.28
+
+Security Fixes
+
+  • When tkey-gssapi-keytab or tkey-gssapi-credential was configured, a
+    specially crafted GSS-TSIG query could cause a buffer overflow in the
+    ISC implementation of SPNEGO (a protocol enabling negotiation of the
+    security mechanism to use for GSSAPI authentication). This flaw could
+    be exploited to crash named. Theoretically, it also enabled remote
+    code execution, but achieving the latter is very difficult in
+    real-world conditions. (CVE-2020-8625)
+
+    This vulnerability was responsibly reported to us as ZDI-CAN-12302 by
+    Trend Micro Zero Day Initiative. [GL #2354]
+
 Notes for BIND 9.11.27
 
 Bug Fixes
index f08df2cdb1adc46d853f96a426d1bf44f3ebded3..2ca75f55fe17b4c49270d24db685c40e9fc64fcb 100644 (file)
@@ -9,5 +9,5 @@
 # 9.11: 160-169,1100-1199
 # 9.12: 1200-1299
 LIBINTERFACE = 1113
-LIBREVISION = 0
+LIBREVISION = 1
 LIBAGE = 0
diff --git a/version b/version
index 69214d2ccd0c311304ee214ba213f779e2371448..808fc4540b96b013da65137603bc2f0ca102b598 100644 (file)
--- a/version
+++ b/version
@@ -5,7 +5,7 @@ PRODUCT=BIND
 DESCRIPTION="(Extended Support Version)"
 MAJORVER=9
 MINORVER=11
-PATCHVER=27
+PATCHVER=28
 RELEASETYPE=
 RELEASEVER=
 EXTENSIONS=