~nacc/ubuntu/+source/bind9:debian/lenny

Last commit made on 2012-03-10
Get this branch:
git clone -b debian/lenny https://git.launchpad.net/~nacc/ubuntu/+source/bind9
Only Nish Aravamudan can upload to this branch. If you are Nish Aravamudan please log in for upload directions.

Branch merges

Branch information

Name:
debian/lenny
Repository:
lp:~nacc/ubuntu/+source/bind9

Recent commits

54bfb43... by Florian Weimer

Import patches-unapplied version 1:9.6.ESV.R4+dfsg-0+lenny4 to debian/lenny

Imported using usd-importer.

Publish parent: d64a8daf5dece8433a0a97119ccf3a1b0b2725fc

New changelog entries:
  * Apply patch from ISC to fix query.c crash (CVE-2011-4313)

d64a8da... by Florian Weimer

Import patches-unapplied version 1:9.6.ESV.R4+dfsg-0+lenny3 to debian/lenny

Imported using usd-importer.

Publish parent: ef1dbe61fe6a146b787e3d9929801908bb94471b

New changelog entries:
  * Apply patch from ISC BIND 9.6-ESV-R4-P3 to address CVE-2011-2464.
  * Apply patches from 9.6-ESV-R4-P1 to address crasher in negative
    caching (CVE-2011-1910) and resolution failures in DLV mode.
  * New upstream version. Prepare for a signed COM TLD, as per:
    <http://www.isc.org/announcement/operational-advisory-bind-96-esv-r3-and-previous>

ef1dbe6... by LaMont Jones

Import patches-unapplied version 1:9.6.ESV.R3+dfsg-0+lenny1 to debian/lenny

Imported using usd-importer.

Publish parent: 3c705369f23561e545aba88fcd0dbdad3820c0b3

New changelog entries:
  * v9.6-ESV-R3. Addresses CVE-2010-3613, CVE-2010-3614
    - Fix denial of service via ncache entry and a rrsig for the
      same type (CVE-2010-3613)
    - answers were incorrectly marked as insecure during key algorithm
      rollover (CVE-2010-3614)
  [Internet Software Consortium, Inc]
  * v9.6-ESV-R2. Addresses CVE-2010-3762
    - Check that named successfully skips NSEC3 records that fail to match
      the NSEC3PARAM record currently in use. [RT# 21868]
    - Worked around an apparent race condition in over memory conditions.
      Without this fix a DNS cache DB or ADB could incorrectly stay in an
      over memory state, effectively refusing further caching, which
      subsequently made a BIND 9 caching server unworkable. This fix
      prevents this problem from happening by polling the state of the
      memory context, rather than making a copy of the state, which
      appeared to cause a race. This is a "workaround" in that it doesn't
      solve the possible race per se, but several experiments proved this
      change solves the symptom. Also, the polling overhead hasn't been
      reported to be an issue. This bug should only affect a caching
      server that specifies a finite max-cache-size. It's also quite
      likely that the bug happens only when enabling threads, but it's not
      confirmed yet. [RT #21818]
    - Named failed to accept uncachable negative responses from insecure
      zones. [RT# 21555]
    - The resolver could attempt to destroy a fetch context too soon.
      [RT #19878]
    - The placeholder negative caching element was not properly constructed
      triggering a INSIST in dns_ncache_towire(). [RT #21346]
    - Handle the introduction of new trusted-keys and DS, DLV RRsets better.
      [RT #21097]
    - Fix arguments to dns_keytable_findnextkeynode() call. [RT #20877]
    - Named could return SERVFAIL for negative responses from unsigned
      zones. [RT #21131]
    - Handle broken DNSSEC trust chains better. [RT #15619]
  [LaMont Jones]
  * meta: drop verisoned depends from library packages, for less upgrade pain
  * cleanup libisc version number. It should be libisc50, not libisc52 or
    libisc53

3c70536... by Florian Weimer

Import patches-unapplied version 1:9.6.ESV.R1+dfsg-0+lenny2 to debian/lenny

Imported using usd-importer.

Publish parent: 8c2dc4ceb5f2b0ecd11d761dd4bea75b5ae1c47a

New changelog entries:
  * Use old location of the PID files. Closes: #585004.
  * Log warning if openssl.cnf is not readable.

8c2dc4c... by Florian Weimer

Import patches-unapplied version 1:9.6.ESV.R1+dfsg-0+lenny1 to debian/lenny

Imported using usd-importer.

Publish parent: 98bc80f9e31258f2e38e6abcccd3ef940aa70729

New changelog entries:
  * New upstream version: BIND 9.6-ESV-R1.
  * Restore Debian-specific feature patches.
  * New upstream version: BIND 9.6-ESV.

98bc80f... by Florian Weimer

Import patches-unapplied version 1:9.5.1.dfsg.P3-1+lenny1 to debian/lenny

Imported using usd-importer.

Publish parent: d3b0162aad5055d5f6e8f0e5bcff05d62416a7fe

New changelog entries:
  * Fix cache poisoning through additional section for secure delegations
    (CVE-2009-4022). Backport of ISC changes between 9.5.2 and 9.5.2-P1.

d3b0162... by LaMont Jones

Import patches-unapplied version 1:9.5.1.dfsg.P3-1 to debian/lenny

Imported using usd-importer.

Publish parent: 1f74d92dd8e06fd60e5906b5eb521ae1a7ec17ef

New changelog entries:
  [Internet Software Consortium, Inc]
  * A specially crafted update packet will cause named to exit.
    CVE-2009-0696, CERT VU#725188. Closes: #538975

1f74d92... by Florian Weimer

Import patches-unapplied version 1:9.5.1.dfsg.P2-1+lenny1 to debian/lenny

Imported using usd-importer.

Publish parent: 8e5fcbf570f80a32a6a1402bbc9388e8ae8d4d3c
Changelog parent: 68c481b91b6b7ee6be0be7b4e9bdfd6bdc509e1d

New changelog entries:
  * Non-maintainer upload with permission from maintainer
  * Upload "DNSSEC lookaside validation failed to handle unknown
    algorithms. [RT #19479]" fix to stable

8e5fcbf... by LaMont Jones

Import patches-unapplied version 1:9.5.1.dfsg.P1-2 to debian/lenny

Imported using usd-importer.

Publish parent: 2904648cd71bd9b84590f2a5014b770552ba4d48

New changelog entries:
  [Juhana Helovuo]
  * fix atomic operations on alpha. Closes: #512285
  [Dann Frazier]
  * fix atomic operations on ia64. Closes: #520179
  [LaMont Jones]
  * build-conflict: libdb4.2-dev. Closes: #515074, #507013
  [localization folks]
  * l10n: Basque debconf template. Closes: #516549 (Piarres Beobide)

68c481b... by LaMont Jones

Import patches-unapplied version 1:9.5.1.dfsg.P2-1 to debian/sid

Imported using usd-importer.

Publish parent: 50c7ef90043c4cce99967134f22e80f30c349d98

New changelog entries:
  [Internet Software Consortium, Inc]
  * 9.5.1-P2
    - DNSSEC lookaside validation failed to handle unknown algorithms. [RT #19479]
  [LaMont Jones]
  * meta: fix override disparity
  [Sven Joachim]
  * meta: pass host and build into configure for hybrid build machines.
    Closes: #515110