| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: bind-libs-32bit | Distribution: openSUSE 11.3 |
| Version: 9.7.4P1 | Vendor: openSUSE |
| Release: 0.2.1 | Build date: Thu Nov 17 17:43:44 2011 |
| Group: Development/Libraries/C and C++ | Build host: build15 |
| Size: 3008436 | Source RPM: bind-9.7.4P1-0.2.1.src.rpm |
| Packager: http://bugs.opensuse.org | |
| Url: http://isc.org/sw/bind/ | |
| Summary: Shared libraries of BIND | |
This package contains the shared libraries of the Berkeley Internet
Name Domain (BIND) Domain Name System implementation of the Domain Name
System (DNS) protocols.
Authors:
--------
ISC Software <bind@isc.org>
BSD3c(or similar) ; MIT License (or similar)
* Thu Nov 17 2011 ug@suse.de
- Cache lookup could return RRSIG data associated with nonexistent
records, leading to an assertion failure. (bnc#730995)
CVE-2011-4313
* Wed Jul 06 2011 ug@suse.de
- Change #2912 (see CHANGES) exposed a latent bug in the DNS message
processing code that could allow certain UPDATE requests to crash
named. This was fixed by disambiguating internal database
representation vs DNS wire format data. [RT #24777] [CVE-2011-2464]
(bnc#703907)
* Tue May 31 2011 meissner@suse.de
- updated to 9.7.3-P1 to fix RRSIG denial of service (CVE-2011-1910 / bnc#696585)
- updated named.root file
* Tue May 31 2011 meissner@suse.de
- updated named.root file
* Thu Feb 24 2011 ug@suse.de
- fixed VUL-0: bind: IXFR or DDNS update combined with
high query rate DoS vulnerability
bnc#674431, CVE-2011-0414
- version from 9.7.1-p2 to 9.7.3
see CHANGES for details
* Mon Dec 06 2010 ug@suse.de
- fixed VUL-0: bind: Key algorithm rollover bug
bnc#657102, CVE-2010-3614
- fixed VUL-0: bind: cache incorrectly allows a ncache entry and a rrsig for the same type
bnc#657129, CVE-2010-3613
- fixed return code of "rcnamed status"
* Tue Oct 12 2010 ug@suse.de
- when a recursive validating server has a trust anchor
that is configured statically or via DNSSEC Lookaside
Validation (DLV), allows remote attackers to cause a
denial of service (infinite loop) via a query for
an RRSIG record whose answer is not in the cache, which causes BIND to
repeatedly send RRSIG queries to the authoritative servers.
(bnc#644907)
VUL-0: bind: DNSSEC denial of service via a recursive validating server
- Temporarily and partially disable change 2864
because it would cause inifinite attempts of RRSIG
queries. This is an urgent care fix; we'll
revisit the issue and complete the fix later.
[RT #21710]
- Named failed to accept uncachable negative responses
from insecure zones. [RT# 21555]
* Mon Jul 26 2010 ug@suse.de
- chrooted bind failed to start (bnc#625019)
* Mon Jun 21 2010 ug@suse.de
- genrandom: add support for the generation of multiple
files.
- Update empty-zones list to match
draft-ietf-dnsop-default-local-zones-13.
- Incrementally write the master file after performing
a AXFR.
- Add AAAA address for L.ROOT-SERVERS.NET.
- around 50 bugs fixed (see CHANGELOG for details)
- version 9.7.1
* Thu May 20 2010 ug@suse.de
- Handle broken DNSSEC trust chains better. [RT #15619]
- Named could return SERVFAIL for negative responses
from unsigned zones. [RT #21131
- version 9.7.0-P2
* Sat May 01 2010 aj@suse.de
- Handle /var/run on tmpfs.
- do not use run_ldconfig.
* Wed Feb 24 2010 jengelh@medozas.de
- Enable DLZ-LDAP (supersedes sdb_ldap) and add a patch
* Wed Feb 17 2010 ug@suse.de
- Fully automatic signing of zones by "named".
- Simplified configuration of DNSSEC Lookaside Validation (DLV).
- Simplified configuration of Dynamic DNS, using the "ddns-confgen"
command line tool or the "local" update-policy option. (As a side
effect, this also makes it easier to configure automatic zone
re-signing.)
- New named option "attach-cache" that allows multiple views to
share a single cache.
- DNS rebinding attack prevention.
- New default values for dnssec-keygen parameters.
- Support for RFC 5011 automated trust anchor maintenance
- Smart signing: simplified tools for zone signing and key
maintenance.
- The "statistics-channels" option is now available on Windows.
- A new DNSSEC-aware libdns API for use by non-BIND9 applications
- On some platforms, named and other binaries can now print out
a stack backtrace on assertion failure, to aid in debugging.
- A "tools only" installation mode on Windows, which only installs
dig, host, nslookup and nsupdate.
- Improved PKCS#11 support, including Keyper support and explicit
OpenSSL engine selection.
- version 9.7.0
* Wed Jan 20 2010 ug@suse.de
- [security] Do not attempt to validate or cache
out-of-bailiwick data returned with a secure
answer; it must be re-fetched from its original
source and validated in that context. [RT #20819]
- [security] Cached CNAME or DNAME RR could be returned to clients
without DNSSEC validation. [RT #20737]
- [security] Bogus NXDOMAIN could be cached as if valid. [RT #20712]
- version 9.6.1-P3
* Mon Jan 04 2010 ug@suse.de
- removed the syntax check for include files (bnc#567593)
* Tue Dec 15 2009 jengelh@medozas.de
- add baselibs.conf as a source
- enable parallel building
- add baselibs for SPARC
- package documentation as noarch
* Wed Nov 25 2009 ug@suse.de
- Security fix
When validating, track whether pending data was from
the additional section or not and only return it if
validates as secure. [RT #20438]
CVE-2009-4022
bnc#558260
- update from P1 to P2
* Fri Nov 20 2009 ug@suse.de
- added localhost for ipv6 to default config (bnc#539529)
* Wed Nov 18 2009 ug@suse.de
- fixed apparmor profile (bnc#544181)
* Tue Nov 03 2009 coolo@novell.com
- updated patches to apply with fuzz=0
* Wed Sep 30 2009 ug@suse.de
- using start_daemon instead of startproc (bnc#539532)
* Mon Aug 10 2009 ug@suse.de
- version update to 9.6.1-P1
(security fix CVE-2009-0696)
bnc#526185
* Tue Jun 30 2009 ug@suse.de
- enabled MySQL DLZ (Dynamically Loadable Zones)
* Tue Jun 16 2009 ug@suse.de
- around 50 bugfixes against 9.6.0p1
See changelog for details
- version 9.6.1
* Thu Apr 09 2009 ug@suse.de
- not all include files were copied into chroot (bnc#466800)
* Tue Mar 03 2009 ug@suse.de
- /etc/named.conf does not include /etc/named.d/forwarders.conf
by default (bnc#480334)
/usr/lib/libbind9.so.60 /usr/lib/libbind9.so.60.0.6 /usr/lib/libdns.so.69 /usr/lib/libdns.so.69.3.1 /usr/lib/libidnkit.so.1 /usr/lib/libidnkit.so.1.0.2 /usr/lib/libidnkitlite.so.1 /usr/lib/libidnkitlite.so.1.0.2 /usr/lib/libidnkitres.so.1 /usr/lib/libidnkitres.so.1.0.1 /usr/lib/libisc.so.62 /usr/lib/libisc.so.62.2.1 /usr/lib/libisccc.so.60 /usr/lib/libisccc.so.60.0.0 /usr/lib/libisccfg.so.62 /usr/lib/libisccfg.so.62.0.2 /usr/lib/liblwres.so.60 /usr/lib/liblwres.so.60.0.2
Generated by rpm2html 1.8.1
Fabrice Bellet, Mon May 20 05:14:52 2013