lp:~davewalker/ubuntu/lucid/bind9/lp_651875

Created by Dave Walker and last modified
Get this branch:
bzr branch lp:~davewalker/ubuntu/lucid/bind9/lp_651875
Only Dave Walker can upload to this branch. If you are Dave Walker please log in for upload directions.

Branch merges

Related bugs

Related blueprints

Branch information

Owner:
Dave Walker
Status:
Development

Recent revisions

22. By Dave Walker

lib/dns/validator.c: Correctly check that DNSSEC/DLV auth status before
declaring the chain broken. Mainly resolving DNSSEC validation errors
when a new DS record is inserted into a trusted DNSSEC validation tree.
Causing a return of SERVFAIL to queries under the newly inserted DS.
Patch courtesy of upstream [RT #21131]. (LP: #651875)

21. By Marc Deslauriers

* SECURITY UPDATE: denial of service via ncache entry and a rrsig for the
  same type
  - lib/dns/rbtdb.c: properly mark existing RRSIG records as stale.
  - bin/tests/system/resolver/*: added tests.
  - CVE-2010-3613
* SECURITY UPDATE: answers incorrectly marked as insecure during key
  algorithm rollover
  - lib/dns/include/dns/types.h, lib/dns/validator.c: improve logic.
  - bin/tests/system/dnssec/*: added tests.
  - CVE-2010-3614

20. By LaMont Jones

[Internet Software Consortium, Inc]

* 9.7.0-P1
  - 2852. [bug] Handle broken DNSSEC trust chains better. [RT #15619]

19. By LaMont Jones

[Niko Tyni]

* fix mips/mipsel startup. Closes: #516616

[LaMont Jones]

* ignore failures due to a lack of /etc/bind/named.conf*. LP: #422968
* ldap API changed regarding % sign. LP: #227344
* Drop more rfc and draft files. Closes: #572606
* update config.guess, config.sub. Closes: #572528

18. By LaMont Jones

[Aurelien Jarno]

* kfreebsd has linux threads. Closes: #470500

[LaMont Jones]

* do not error out on initial install. Closes: #572443

17. By LaMont Jones

New upstream release

16. By LaMont Jones

New upstream release. CVE-2010-0097

15. By LaMont Jones

[Internet Software Consortium, Inc]

* 9.6.1-P2
  - When validating, track whether pending data was from the
    additional section or not and only return it if validates
    as secure. [RT #20438] CVE-2009-4022

[LaMont Jones]

* prerm: do not stop named on upgrade. Closes: #542888
* Drop some RFCs that crept into the diff.
* meta: add ${misc:Depends}
* lintian: update config.guess, config.sub in idnkit-1.0 tree
* dnsutils: remove pre-sarge dpkg-divert calls in postinst
* meta: soname changes
* l10n: missing newline in pofile.

14. By LaMont Jones

Build-Depend on the fixed libgeoip-dev. Closes: #540973

13. By LaMont Jones

[Internet Software Consortium, Inc]

* A specially crafted update packet will cause named to exit.
  CVE-2009-0696, CERT VU#725188. Closes: #538975

[InterNIC]

* Update db.root hints file.

[LaMont Jones]

* Move default zone definitions from named.conf to named.conf.default-zones.
   Closes: #492308
* use start-stop-daemon if rndc stop fails. Closes: #536487
* lwresd: pidfile name was wrong in init script. Closes: #527137

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp:ubuntu/natty/bind9
This branch contains Public information 
Everyone can see this information.

Subscribers