]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
[v9_12] spelling, release note
authorEvan Hunt <each@isc.org>
Fri, 2 Feb 2018 18:32:35 +0000 (10:32 -0800)
committerEvan Hunt <each@isc.org>
Fri, 2 Feb 2018 18:32:35 +0000 (10:32 -0800)
(cherry picked from commit c34680cf3b01eae8debde94596ef367f2b79f4b9)

CHANGES
doc/arm/notes.xml

diff --git a/CHANGES b/CHANGES
index e5e511d1a4ccbd22a1c5c0161632901315e4d073..b82bcd1f3d2bd7746d94fbafa5ce55dd17adc553 100644 (file)
--- a/CHANGES
+++ b/CHANGES
@@ -6,11 +6,12 @@
 4881.  [bug]           Only include dst_openssl.h when OpenSSL is required.
                        [RT #47068]
 
-4880.  [bug]           Named wasn't returning the target of a cross zone
-                       CNAME between to served zones when recursion was
-                       desired and available (RD=1, RA=1). Don't return
-                       the CNAME target otherwise to prevent accidental
-                       cache poisoning. [RT #47078]
+4880.  [bug]           Named wasn't returning the target of a cross-zone
+                       CNAME between two served zones when recursion was
+                       desired and available (RD=1, RA=1). (When this is
+                       not the case, the CNAME target is deliberately
+                       withheld to prevent accidental cache poisoning.)
+                       [RT #47078]
 
 4879.  [bug]           dns_rdata_caa:value_len field was too small.
                        [RT #47086]
index 2fec705210718ef96e946dbf85ebd5d9936ea660..65eb7d196c93bd551e24909d26713226e87dc3d9 100644 (file)
 
   <section xml:id="relnotes_bugs"><info><title>Bug Fixes</title></info>
     <itemizedlist>
+      <listitem>
+       <para>
+         When answering authoritative queries, <command>named</command>
+         does not return the target of a cross-zone CNAME between two
+         locally served zones; this prevents accidental cache poisoning.
+         This same restriction was incorrectly applied to recursive
+         queries as well; this has been fixed. [RT #47078]
+       </para>
+      </listitem>
       <listitem>
        <para>
          Attempting to validate improperly unsigned CNAME responses