ubuntu/+source/bind9:ubuntu/impish

Last commit made on 2021-07-12
Get this branch:
git clone -b ubuntu/impish https://git.launchpad.net/ubuntu/+source/bind9
Members of git-ubuntu import can upload to this branch. Log in for directions.

Branch merges

Branch information

Name:
ubuntu/impish
Repository:
lp:ubuntu/+source/bind9

Recent commits

5440bba... by Athos Ribeiro

Update changelog for 1:9.16.15-1ubuntu1 release

0304629... by Athos Ribeiro

update-maintainer

b70e8d3... by Athos Ribeiro

reconstruct-changelog

75d7d5b... by Athos Ribeiro

merge-changelogs

99ddfdb... by Athos Ribeiro

- d/bind9.named.service: use systemd Type=forking to signal daemon init. This
  fixes a regression of #900788 where services whose startup depend on name
  resolutions may fail due to bind9 not being ready (LP: #1899902).

5764509... by Athos Ribeiro

* Dropped change
  - SECURITY UPDATE: overflow in BIND's GSSAPI security policy negotiation
    + debian/rules: build with --disable-isc-spnego to disable internal
      SPNEGO and use the one from the kerberos libraries.
    + CVE-2021-25216
    [Fixed in 1:9.16.15-1]

f0d9eb7... by Athos Ribeiro

* Dropped change
  - SECURITY UPDATE: assert via answering certain queries for DNAME records
    + debian/patches/CVE-2021-25215.patch: fix assert checks in
      lib/ns/query.c.
    + CVE-2021-25215
    [Fixed in 1:9.16.15-1]

c7c7e87... by Athos Ribeiro

* Dropped change
  - SECURITY UPDATE: DoS via broken inbound incremental zone update (IXFR)
    + debian/patches/CVE-2021-25214.patch: immediately reject the entire
      transfer for certain RR in lib/dns/xfrin.c.
    + CVE-2021-25214
    [Fixed in 1:9.16.15-1]

eb9895d... by Athos Ribeiro

* Dropped change
  - SECURITY UPDATE: off-by-one bug in ISC SPNEGO implementation
    + debian/patches/CVE-2020-8625.patch: properly calculate length in
      lib/dns/spnego.c.
    + CVE-2020-8625
    [Fixed in 1:9.16.12-1]

b6073b4... by Andreas Hasenack

    - d/NEWS: mention some of the bigger changes in 9.16.0 packaging