head	1.30;
access;
symbols
	RELENG_8_4:1.29.0.2
	RELENG_9_1_0_RELEASE:1.21.2.5.2.2
	RELENG_9_1:1.21.2.5.0.2
	RELENG_9_1_BP:1.21.2.5
	RELENG_8_3_0_RELEASE:1.9.2.11
	RELENG_8_3:1.9.2.11.0.2
	RELENG_8_3_BP:1.9.2.11
	RELENG_9_0_0_RELEASE:1.21.4.1
	RELENG_9_0:1.21.0.4
	RELENG_9_0_BP:1.21
	RELENG_9:1.21.0.2
	RELENG_9_BP:1.21
	RELENG_7_4_0_RELEASE:1.1.1.10.2.12
	RELENG_8_2_0_RELEASE:1.9.2.6
	RELENG_7_4:1.1.1.10.2.12.0.2
	RELENG_7_4_BP:1.1.1.10.2.12
	RELENG_8_2:1.9.2.6.0.2
	RELENG_8_2_BP:1.9.2.6
	RELENG_8_1_0_RELEASE:1.9.2.4
	RELENG_8_1:1.9.2.4.0.2
	RELENG_8_1_BP:1.9.2.4
	RELENG_7_3_0_RELEASE:1.1.1.10.2.7.2.1
	RELENG_7_3:1.1.1.10.2.7.0.2
	RELENG_7_3_BP:1.1.1.10.2.7
	RELENG_8_0_0_RELEASE:1.9
	RELENG_8_0:1.9.0.4
	RELENG_8_0_BP:1.9
	RELENG_8:1.9.0.2
	RELENG_8_BP:1.9
	RELENG_7_2_0_RELEASE:1.1.1.10.2.5
	RELENG_7_2:1.1.1.10.2.5.0.2
	RELENG_7_2_BP:1.1.1.10.2.5
	RELENG_7_1_0_RELEASE:1.1.1.10.2.3
	RELENG_6_4_0_RELEASE:1.1.1.3.2.9
	RELENG_7_1:1.1.1.10.2.3.0.2
	RELENG_7_1_BP:1.1.1.10.2.3
	RELENG_6_4:1.1.1.3.2.9.0.2
	RELENG_6_4_BP:1.1.1.3.2.9
	RELENG_7_0_0_RELEASE:1.1.1.10.2.1
	RELENG_6_3_0_RELEASE:1.1.1.3.2.6
	RELENG_7_0:1.1.1.10.2.1.0.2
	RELENG_7_0_BP:1.1.1.10.2.1
	BIND_9_4_2:1.1.1.11
	RELENG_6_3:1.1.1.3.2.6.0.2
	RELENG_6_3_BP:1.1.1.3.2.6
	RELENG_7:1.1.1.10.0.2
	RELENG_7_BP:1.1.1.10
	BIND_9_4_1_P1:1.1.1.10
	BIND_9_4_1:1.1.1.9
	BIND_9_3_4:1.1.1.8
	RELENG_6_2_0_RELEASE:1.1.1.3.2.3.2.1
	BIND_9_3_3:1.1.1.7
	RELENG_6_2:1.1.1.3.2.3.0.2
	RELENG_6_2_BP:1.1.1.3.2.3
	BIND_9_3_2_P2:1.1.1.6
	BIND_9_3_2_P1:1.1.1.5
	RELENG_5_5_0_RELEASE:1.1.1.2.2.3
	RELENG_5_5:1.1.1.2.2.3.0.2
	RELENG_5_5_BP:1.1.1.2.2.3
	RELENG_6_1_0_RELEASE:1.1.1.3.2.1
	RELENG_6_1:1.1.1.3.2.1.0.2
	RELENG_6_1_BP:1.1.1.3.2.1
	BIND_9_3_2:1.1.1.4
	RELENG_6_0_0_RELEASE:1.1.1.3
	RELENG_6_0:1.1.1.3.0.4
	RELENG_6_0_BP:1.1.1.3
	RELENG_6:1.1.1.3.0.2
	RELENG_6_BP:1.1.1.3
	RELENG_5_4_0_RELEASE:1.1.1.2.2.2
	RELENG_5_4:1.1.1.2.2.2.0.2
	RELENG_5_4_BP:1.1.1.2.2.2
	BIND_9_3_1:1.1.1.3
	RELENG_5_3_0_RELEASE:1.1.1.2.2.1
	RELENG_5_3:1.1.1.2.2.1.0.2
	RELENG_5_3_BP:1.1.1.2.2.1
	RELENG_5:1.1.1.2.0.2
	BIND_9_3_0:1.1.1.2
	BIND_9_3_0_RC4:1.1.1.1
	ISC:1.1.1;
locks; strict;
comment	@# @;


1.30
date	2013.03.28.17.04.59;	author svnexp;	state Exp;
branches;
next	1.29;

1.29
date	2012.12.07.12.43.13;	author svnexp;	state Exp;
branches
	1.29.2.1;
next	1.28;

1.28
date	2012.10.10.19.47.52;	author delphij;	state Exp;
branches;
next	1.27;

1.27
date	2012.09.20.04.12.09;	author dougb;	state Exp;
branches;
next	1.26;

1.26
date	2012.07.24.18.53.28;	author dougb;	state Exp;
branches;
next	1.25;

1.25
date	2012.06.04.22.11.20;	author dougb;	state Exp;
branches;
next	1.24;

1.24
date	2012.05.28.19.47.56;	author dougb;	state Exp;
branches;
next	1.23;

1.23
date	2012.04.05.04.29.35;	author dougb;	state Exp;
branches;
next	1.22;

1.22
date	2011.11.17.00.25.35;	author dougb;	state Exp;
branches;
next	1.21;

1.21
date	2011.09.03.07.13.45;	author dougb;	state Exp;
branches
	1.21.2.1
	1.21.4.1;
next	1.20;

1.20
date	2011.07.16.11.12.09;	author dougb;	state Exp;
branches;
next	1.19;

1.19
date	2011.07.06.00.48.31;	author dougb;	state Exp;
branches;
next	1.18;

1.18
date	2011.05.28.00.21.28;	author dougb;	state Exp;
branches;
next	1.17;

1.17
date	2011.02.06.22.46.07;	author dougb;	state Exp;
branches;
next	1.16;

1.16
date	2010.12.04.05.58.56;	author dougb;	state Exp;
branches;
next	1.15;

1.15
date	2010.10.31.04.45.53;	author dougb;	state Exp;
branches;
next	1.14;

1.14
date	2010.05.20.08.15.06;	author dougb;	state Exp;
branches;
next	1.13;

1.13
date	2010.03.18.19.00.35;	author dougb;	state Exp;
branches;
next	1.12;

1.12
date	2010.03.03.05.45.24;	author dougb;	state Exp;
branches;
next	1.11;

1.11
date	2010.01.25.06.18.31;	author dougb;	state Exp;
branches;
next	1.10;

1.10
date	2009.11.30.03.38.34;	author dougb;	state Exp;
branches;
next	1.9;

1.9
date	2009.07.29.00.15.39;	author dougb;	state Exp;
branches
	1.9.2.1;
next	1.8;

1.8
date	2009.06.25.19.16.29;	author dougb;	state Exp;
branches;
next	1.7;

1.7
date	2009.05.31.05.42.58;	author dougb;	state Exp;
branches;
next	1.6;

1.6
date	2009.03.21.23.00.40;	author dougb;	state Exp;
branches;
next	1.5;

1.5
date	2009.01.09.11.45.45;	author dougb;	state Exp;
branches;
next	1.4;

1.4
date	2008.12.23.22.47.56;	author dougb;	state Exp;
branches;
next	1.3;

1.3
date	2008.09.01.22.54.49;	author dougb;	state Exp;
branches;
next	1.2;

1.2
date	2008.07.12.09.38.35;	author dougb;	state Exp;
branches;
next	1.1;

1.1
date	2004.09.19.01.30.03;	author trhodes;	state Exp;
branches
	1.1.1.1;
next	;

1.29.2.1
date	2012.12.07.12.43.13;	author svnexp;	state dead;
branches;
next	1.29.2.2;

1.29.2.2
date	2013.03.28.13.00.18;	author svnexp;	state Exp;
branches;
next	;

1.21.2.1
date	2011.12.01.21.13.41;	author dougb;	state Exp;
branches;
next	1.21.2.2;

1.21.2.2
date	2012.04.08.01.43.41;	author dougb;	state Exp;
branches;
next	1.21.2.3;

1.21.2.3
date	2012.06.01.03.46.28;	author dougb;	state Exp;
branches;
next	1.21.2.4;

1.21.2.4
date	2012.06.04.22.14.33;	author dougb;	state Exp;
branches;
next	1.21.2.5;

1.21.2.5
date	2012.07.24.22.32.03;	author dougb;	state Exp;
branches
	1.21.2.5.2.1;
next	1.21.2.6;

1.21.2.6
date	2012.09.22.08.47.29;	author delphij;	state Exp;
branches;
next	1.21.2.7;

1.21.2.7
date	2012.10.10.19.50.15;	author delphij;	state Exp;
branches;
next	1.21.2.8;

1.21.2.8
date	2013.01.08.10.02.28;	author svnexp;	state Exp;
branches;
next	1.21.2.9;

1.21.2.9
date	2013.03.28.14.27.39;	author svnexp;	state Exp;
branches;
next	1.21.2.10;

1.21.2.10
date	2013.08.16.08.01.49;	author svnexp;	state Exp;
branches;
next	1.21.2.11;

1.21.2.11
date	2013.08.26.08.01.48;	author svnexp;	state Exp;
branches;
next	1.21.2.12;

1.21.2.12
date	2014.03.03.10.08.04;	author svnexp;	state Exp;
branches;
next	;

1.21.2.5.2.1
date	2012.09.22.08.48.26;	author delphij;	state Exp;
branches;
next	1.21.2.5.2.2;

1.21.2.5.2.2
date	2012.10.10.20.37.57;	author delphij;	state Exp;
branches;
next	;

1.21.4.1
date	2011.12.01.21.17.59;	author dougb;	state Exp;
branches;
next	;

1.9.2.1
date	2009.12.11.01.23.58;	author dougb;	state Exp;
branches;
next	1.9.2.2;

1.9.2.2
date	2010.02.07.20.28.24;	author dougb;	state Exp;
branches;
next	1.9.2.3;

1.9.2.3
date	2010.03.29.06.31.58;	author dougb;	state Exp;
branches;
next	1.9.2.4;

1.9.2.4
date	2010.05.23.21.15.36;	author dougb;	state Exp;
branches;
next	1.9.2.5;

1.9.2.5
date	2010.11.04.21.48.39;	author dougb;	state Exp;
branches;
next	1.9.2.6;

1.9.2.6
date	2010.12.08.19.59.53;	author dougb;	state Exp;
branches;
next	1.9.2.7;

1.9.2.7
date	2011.02.05.19.13.34;	author dougb;	state Exp;
branches;
next	1.9.2.8;

1.9.2.8
date	2011.05.28.00.33.06;	author dougb;	state Exp;
branches;
next	1.9.2.9;

1.9.2.9
date	2011.07.06.00.50.54;	author dougb;	state Exp;
branches;
next	1.9.2.10;

1.9.2.10
date	2011.08.02.08.07.59;	author dougb;	state Exp;
branches;
next	1.9.2.11;

1.9.2.11
date	2011.11.17.00.36.10;	author dougb;	state Exp;
branches;
next	1.9.2.12;

1.9.2.12
date	2012.04.05.04.31.17;	author dougb;	state Exp;
branches;
next	1.9.2.13;

1.9.2.13
date	2012.05.28.19.48.37;	author dougb;	state Exp;
branches;
next	1.9.2.14;

1.9.2.14
date	2012.06.04.22.21.55;	author dougb;	state Exp;
branches;
next	1.9.2.15;

1.9.2.15
date	2012.07.24.19.04.35;	author dougb;	state Exp;
branches;
next	1.9.2.16;

1.9.2.16
date	2012.09.20.04.35.20;	author dougb;	state Exp;
branches;
next	1.9.2.17;

1.9.2.17
date	2012.10.11.13.25.09;	author erwin;	state Exp;
branches;
next	1.9.2.18;

1.9.2.18
date	2013.01.04.14.22.19;	author svnexp;	state Exp;
branches;
next	1.9.2.19;

1.9.2.19
date	2013.02.11.12.33.24;	author svnexp;	state Exp;
branches;
next	1.9.2.20;

1.9.2.20
date	2013.03.28.13.59.36;	author svnexp;	state Exp;
branches;
next	1.9.2.21;

1.9.2.21
date	2014.03.03.10.23.38;	author svnexp;	state Exp;
branches;
next	;

1.1.1.1
date	2004.09.19.01.30.03;	author trhodes;	state Exp;
branches;
next	1.1.1.2;

1.1.1.2
date	2004.09.23.07.18.48;	author des;	state Exp;
branches
	1.1.1.2.2.1;
next	1.1.1.3;

1.1.1.3
date	2005.03.17.08.02.17;	author dougb;	state Exp;
branches
	1.1.1.3.2.1;
next	1.1.1.4;

1.1.1.4
date	2005.12.29.04.21.49;	author dougb;	state Exp;
branches;
next	1.1.1.5;

1.1.1.5
date	2006.09.06.21.27.08;	author dougb;	state Exp;
branches;
next	1.1.1.6;

1.1.1.6
date	2006.11.04.07.53.25;	author dougb;	state Exp;
branches;
next	1.1.1.7;

1.1.1.7
date	2006.12.10.07.06.09;	author dougb;	state Exp;
branches;
next	1.1.1.8;

1.1.1.8
date	2007.01.29.18.31.21;	author dougb;	state Exp;
branches;
next	1.1.1.9;

1.1.1.9
date	2007.06.02.23.20.55;	author dougb;	state Exp;
branches;
next	1.1.1.10;

1.1.1.10
date	2007.07.25.08.11.47;	author dougb;	state Exp;
branches
	1.1.1.10.2.1;
next	1.1.1.11;

1.1.1.11
date	2007.12.02.19.09.41;	author dougb;	state Exp;
branches;
next	;

1.1.1.2.2.1
date	2004.09.26.03.09.31;	author des;	state Exp;
branches;
next	1.1.1.2.2.2;

1.1.1.2.2.2
date	2005.03.23.18.16.23;	author dougb;	state Exp;
branches;
next	1.1.1.2.2.3;

1.1.1.2.2.3
date	2006.01.14.10.41.57;	author dougb;	state Exp;
branches;
next	1.1.1.2.2.4;

1.1.1.2.2.4
date	2006.09.06.22.27.09;	author simon;	state Exp;
branches;
next	1.1.1.2.2.5;

1.1.1.2.2.5
date	2006.11.08.23.55.41;	author dougb;	state Exp;
branches;
next	1.1.1.2.2.6;

1.1.1.2.2.6
date	2006.12.13.09.57.01;	author dougb;	state Exp;
branches;
next	1.1.1.2.2.7;

1.1.1.2.2.7
date	2007.02.07.00.46.33;	author dougb;	state Exp;
branches;
next	1.1.1.2.2.8;

1.1.1.2.2.8
date	2007.07.25.08.24.39;	author dougb;	state Exp;
branches;
next	;

1.1.1.3.2.1
date	2006.01.14.10.13.33;	author dougb;	state Exp;
branches;
next	1.1.1.3.2.2;

1.1.1.3.2.2
date	2006.09.06.22.23.08;	author simon;	state Exp;
branches;
next	1.1.1.3.2.3;

1.1.1.3.2.3
date	2006.11.08.01.32.16;	author dougb;	state Exp;
branches
	1.1.1.3.2.3.2.1;
next	1.1.1.3.2.4;

1.1.1.3.2.4
date	2006.12.13.09.46.47;	author dougb;	state Exp;
branches;
next	1.1.1.3.2.5;

1.1.1.3.2.5
date	2007.02.07.00.42.07;	author dougb;	state Exp;
branches;
next	1.1.1.3.2.6;

1.1.1.3.2.6
date	2007.07.25.08.23.07;	author dougb;	state Exp;
branches;
next	1.1.1.3.2.7;

1.1.1.3.2.7
date	2008.06.03.05.38.10;	author dougb;	state Exp;
branches;
next	1.1.1.3.2.8;

1.1.1.3.2.8
date	2008.07.12.10.07.33;	author dougb;	state Exp;
branches;
next	1.1.1.3.2.9;

1.1.1.3.2.9
date	2008.09.01.22.56.10;	author dougb;	state Exp;
branches;
next	1.1.1.3.2.10;

1.1.1.3.2.10
date	2009.01.10.04.30.27;	author dougb;	state Exp;
branches;
next	;

1.1.1.3.2.3.2.1
date	2006.12.13.09.52.15;	author dougb;	state Exp;
branches;
next	;

1.1.1.10.2.1
date	2007.12.07.08.31.04;	author dougb;	state Exp;
branches;
next	1.1.1.10.2.2;

1.1.1.10.2.2
date	2008.07.13.18.42.38;	author cperciva;	state Exp;
branches;
next	1.1.1.10.2.3;

1.1.1.10.2.3
date	2008.11.14.11.00.34;	author dougb;	state Exp;
branches;
next	1.1.1.10.2.4;

1.1.1.10.2.4
date	2009.01.10.03.00.21;	author dougb;	state Exp;
branches;
next	1.1.1.10.2.5;

1.1.1.10.2.5
date	2009.03.21.23.03.56;	author dougb;	state Exp;
branches;
next	1.1.1.10.2.6;

1.1.1.10.2.6
date	2009.07.28.23.59.22;	author dougb;	state Exp;
branches;
next	1.1.1.10.2.7;

1.1.1.10.2.7
date	2009.12.11.02.23.04;	author dougb;	state Exp;
branches
	1.1.1.10.2.7.2.1;
next	1.1.1.10.2.8;

1.1.1.10.2.8
date	2010.02.16.05.14.51;	author dougb;	state Exp;
branches;
next	1.1.1.10.2.9;

1.1.1.10.2.9
date	2010.03.29.23.00.45;	author dougb;	state Exp;
branches;
next	1.1.1.10.2.10;

1.1.1.10.2.10
date	2010.05.24.06.41.57;	author dougb;	state Exp;
branches;
next	1.1.1.10.2.11;

1.1.1.10.2.11
date	2010.11.04.21.50.19;	author dougb;	state Exp;
branches;
next	1.1.1.10.2.12;

1.1.1.10.2.12
date	2010.12.09.21.11.53;	author dougb;	state Exp;
branches;
next	1.1.1.10.2.13;

1.1.1.10.2.13
date	2011.05.28.00.58.19;	author dougb;	state Exp;
branches;
next	1.1.1.10.2.14;

1.1.1.10.2.14
date	2011.08.02.09.42.58;	author dougb;	state Exp;
branches;
next	1.1.1.10.2.15;

1.1.1.10.2.15
date	2011.11.17.01.10.16;	author dougb;	state Exp;
branches;
next	;

1.1.1.10.2.7.2.1
date	2010.02.16.18.10.35;	author dougb;	state Exp;
branches;
next	;


desc
@@


1.30
log
@## SVN ## Exported commit - http://svnweb.freebsd.org/changeset/base/248788
## SVN ## CVS IS DEPRECATED: http://wiki.freebsd.org/CvsIsDeprecated
@
text
@# $Id$
# 
# This file must follow /bin/sh rules.  It is imported directly via
# configure.
#
MAJORVER=9
MINORVER=8
PATCHVER=4
RELEASETYPE=-P
RELEASEVER=2
@


1.29
log
@## SVN ## Exported commit - http://svnweb.freebsd.org/changeset/base/243981
## SVN ## CVS IS DEPRECATED: http://wiki.freebsd.org/CvsIsDeprecated
@
text
@d10 1
a10 1
RELEASEVER=1
@


1.29.2.1
log
@file version was added on branch RELENG_8_4 on 2013-03-28 13:00:18 +0000
@
text
@d1 10
@


1.29.2.2
log
@## SVN ## Exported commit - http://svnweb.freebsd.org/changeset/base/248810
## SVN ## CVS IS DEPRECATED: http://wiki.freebsd.org/CvsIsDeprecated
@
text
@a0 10
# $Id$
# 
# This file must follow /bin/sh rules.  It is imported directly via
# configure.
#
MAJORVER=9
MINORVER=8
PATCHVER=4
RELEASETYPE=-P
RELEASEVER=2
@


1.28
log
@SVN rev 241414 on 2012-10-10 19:47:52Z by delphij

Upgrade to 9.8.3-P4:

Prevents a lockup when queried a deliberately constructed combination
of records. [CVE-2012-5166]

For more information: https://kb.isc.org/article/AA-00801
@
text
@d8 1
a8 1
PATCHVER=3
d10 1
a10 1
RELEASEVER=4
@


1.27
log
@SVN rev 240729 on 2012-09-20 04:12:09Z by dougb

Upgrade to 9.8.3-P3:

Prevents a crash when queried for a record whose RDATA exceeds
65535 bytes.

Prevents a crash when validating caused by using "Bad cache" data
before it has been initialized.

ISC_QUEUE handling for recursive clients was updated to address
a race condition that could cause a memory leak. This rarely
occurred with UDP clients, but could be a significant problem
for a server handling a steady rate of TCP queries.

A condition has been corrected where improper handling of
zero-length RDATA could cause undesirable behavior, including
termination of the named process.

For more information: https://kb.isc.org/article/AA-00788
@
text
@d10 1
a10 1
RELEASEVER=3
@


1.26
log
@SVN rev 238746 on 2012-07-24 18:53:28Z by dougb

Heavy DNSSEC Validation Load Can Cause a "Bad Cache" Assertion Failure
in BIND9

High numbers of queries with DNSSEC validation enabled can cause an
assertion failure in named, caused by using a "bad cache" data structure
before it has been initialized.

CVE: CVE-2012-3817
Posting date: 24 July, 2012
@
text
@d10 1
a10 1
RELEASEVER=2
@


1.25
log
@SVN rev 236586 on 2012-06-04 22:11:20Z by dougb

Upgrade to 9.8.3-P1, the latest from ISC. This version contains
a critical bugfix:

  Processing of DNS resource records where the rdata field is zero length
  may cause various issues for the servers handling them.

  Processing of these records may lead to unexpected outcomes. Recursive
  servers may crash or disclose some portion of memory to the client.
  Secondary servers may crash on restart after transferring a zone
  containing these records. Master servers may corrupt zone data if the
  zone option "auto-dnssec" is set to "maintain". Other unexpected
  problems that are not listed here may also be encountered.

All BIND users are strongly encouraged to upgrade.
@
text
@d10 1
a10 1
RELEASEVER=1
@


1.24
log
@SVN rev 236196 on 2012-05-28 19:47:56Z by dougb

Upgrade to BIND version 9.8.3, the latest from ISC.

Feature Change

*  BIND now recognizes the TLSA resource record type, created to
   support IETF DANE (DNS-based Authentication of Named Entities)

Bug Fix

*  The locking strategy around the handling of iterative queries
   has been tuned to reduce unnecessary contention in a multi-
   threaded environment.

Other critical bug fixes are included.

All BIND users are encouraged to upgrade.
@
text
@d9 2
a10 2
RELEASETYPE=
RELEASEVER=
@


1.23
log
@SVN rev 233914 on 2012-04-05 04:29:35Z by dougb

Update to version 9.8.2, the latest from ISC, which contains numerous bug fixes.
@
text
@d8 1
a8 1
PATCHVER=2
@


1.22
log
@SVN rev 227596 on 2011-11-17 00:25:35Z by dougb

Upgrade to BIND 9.8.1-P1 to address the following DDOS bug:

Recursive name servers are failing with an assertion:
INSIST(! dns_rdataset_isassociated(sigrdataset))

At this time it is not thought that authoritative-only servers
are affected, but information about this bug is evolving rapidly.

Because it may be possible to trigger this bug even on networks
that do not allow untrusted users to access the recursive name
servers (perhaps via specially crafted e-mail messages, and/or
malicious web sites) it is recommended that ALL operators of
recursive name servers upgrade immediately.

For more information see:
https://www.isc.org/software/bind/advisories/cve-2011-tbd
which will be updated as more information becomes available.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4313
@
text
@d1 1
a1 1
# $Id: version,v 1.53.8.9.6.1 2011-11-16 09:32:07 marka Exp $
d8 3
a10 3
PATCHVER=1
RELEASETYPE=-P
RELEASEVER=1
@


1.21
log
@SVN rev 225361 on 2011-09-03 07:13:45Z by dougb

Upgrade to BIND version 9.8.1. Release notes at:

https://deepthought.isc.org/article/AA-00446/81/
or
/usr/src/contrib/bind9/

Approved by:	re (kib)
@
text
@d1 1
a1 1
# $Id: version,v 1.53.8.9 2011-08-24 02:08:26 marka Exp $
d9 2
a10 2
RELEASETYPE=
RELEASEVER=
@


1.21.4.1
log
@SVN rev 228190 on 2011-12-01 21:17:59Z by dougb

Upgrade to BIND 9.8.1-P1 to address the following DDOS bug:

Recursive name servers are failing with an assertion:
INSIST(! dns_rdataset_isassociated(sigrdataset))

At this time it is not thought that authoritative-only servers
are affected, but information about this bug is evolving rapidly.

Because it may be possible to trigger this bug even on networks
that do not allow untrusted users to access the recursive name
servers (perhaps via specially crafted e-mail messages, and/or
malicious web sites) it is recommended that ALL operators of
recursive name servers upgrade immediately.

For more information see:
https://www.isc.org/software/bind/advisories/cve-2011-4313
which will be updated as more information becomes available.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4313

Approved by:	re (kib)
@
text
@d1 1
a1 1
# $Id: version,v 1.53.8.9.6.1 2011-11-16 09:32:07 marka Exp $
d9 2
a10 2
RELEASETYPE=-P
RELEASEVER=1
@


1.21.2.1
log
@SVN rev 228189 on 2011-12-01 21:13:41Z by dougb

Upgrade to BIND 9.8.1-P1 to address the following DDOS bug:

Recursive name servers are failing with an assertion:
INSIST(! dns_rdataset_isassociated(sigrdataset))

At this time it is not thought that authoritative-only servers
are affected, but information about this bug is evolving rapidly.

Because it may be possible to trigger this bug even on networks
that do not allow untrusted users to access the recursive name
servers (perhaps via specially crafted e-mail messages, and/or
malicious web sites) it is recommended that ALL operators of
recursive name servers upgrade immediately.

For more information see:
https://www.isc.org/software/bind/advisories/cve-2011-4313
which will be updated as more information becomes available.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4313

Approved by:	re (kib)
@
text
@d1 1
a1 1
# $Id: version,v 1.53.8.9.6.1 2011-11-16 09:32:07 marka Exp $
d9 2
a10 2
RELEASETYPE=-P
RELEASEVER=1
@


1.21.2.2
log
@SVN rev 234010 on 2012-04-08 01:43:41Z by dougb

MFC r233909:

Add Bv9ARM.pdf to the list of docs to install.

MFV/MFC r233914:

Update to version 9.8.2, the latest from ISC, which contains numerous bug fixes.
@
text
@d1 1
a1 1
# $Id$
d8 3
a10 3
PATCHVER=2
RELEASETYPE=
RELEASEVER=
@


1.21.2.3
log
@SVN rev 236374 on 2012-06-01 03:46:28Z by dougb

MFV r236171, MFC r236196:

Upgrade to BIND version 9.8.3, the latest from ISC.

Feature Change

*  BIND now recognizes the TLSA resource record type, created to
   support IETF DANE (DNS-based Authentication of Named Entities)

Bug Fix

*  The locking strategy around the handling of iterative queries
   has been tuned to reduce unnecessary contention in a multi-
   threaded environment.

Other critical bug fixes are included.

All BIND users are encouraged to upgrade.
@
text
@d8 1
a8 1
PATCHVER=3
@


1.21.2.4
log
@SVN rev 236587 on 2012-06-04 22:14:33Z by dougb

Upgrade to 9.8.3-P1, the latest from ISC. This version contains
a critical bugfix:

    Processing of DNS resource records where the rdata field is zero length
    may cause various issues for the servers handling them.

    Processing of these records may lead to unexpected outcomes. Recursive
    servers may crash or disclose some portion of memory to the client.
    Secondary servers may crash on restart after transferring a zone
    containing these records. Master servers may corrupt zone data if the
    zone option "auto-dnssec" is set to "maintain". Other unexpected
    problems that are not listed here may also be encountered.

All BIND users are strongly encouraged to upgrade.
@
text
@d9 2
a10 2
RELEASETYPE=-P
RELEASEVER=1
@


1.21.2.5
log
@SVN rev 238756 on 2012-07-24 22:32:03Z by dougb

MFV r238744:

Heavy DNSSEC Validation Load Can Cause a "Bad Cache" Assertion Failure
in BIND9

High numbers of queries with DNSSEC validation enabled can cause an
assertion failure in named, caused by using a "bad cache" data structure
before it has been initialized.

CVE: CVE-2012-3817
Posting date: 24 July, 2012

Approved by:	re (kib)
@
text
@d10 1
a10 1
RELEASEVER=2
@


1.21.2.5.2.1
log
@SVN rev 240808 on 2012-09-22 08:48:26Z by delphij

MFC 240729 (dougb):

Upgrade to 9.8.3-P3:

Prevents a crash when queried for a record whose RDATA exceeds
65535 bytes.

Prevents a crash when validating caused by using "Bad cache" data
before it has been initialized.

ISC_QUEUE handling for recursive clients was updated to address
a race condition that could cause a memory leak. This rarely
occurred with UDP clients, but could be a significant problem
for a server handling a steady rate of TCP queries.

A condition has been corrected where improper handling of
zero-length RDATA could cause undesirable behavior, including
termination of the named process.

For more information: https://kb.isc.org/article/AA-00788

Approved by:	re (kib)
@
text
@d10 1
a10 1
RELEASEVER=3
@


1.21.2.5.2.2
log
@SVN rev 241417 on 2012-10-10 20:37:57Z by delphij

MFC r241414:

Upgrade to 9.8.3-P4:

Prevents a lockup when queried a deliberately constructed combination
of records. [CVE-2012-5166]

For more information: https://kb.isc.org/article/AA-00801

Approved by:	re (kib)
@
text
@d10 1
a10 1
RELEASEVER=4
@


1.21.2.6
log
@SVN rev 240807 on 2012-09-22 08:47:29Z by delphij

MFC 240729 (dougb):

Upgrade to 9.8.3-P3:

Prevents a crash when queried for a record whose RDATA exceeds
65535 bytes.

Prevents a crash when validating caused by using "Bad cache" data
before it has been initialized.

ISC_QUEUE handling for recursive clients was updated to address
a race condition that could cause a memory leak. This rarely
occurred with UDP clients, but could be a significant problem
for a server handling a steady rate of TCP queries.

A condition has been corrected where improper handling of
zero-length RDATA could cause undesirable behavior, including
termination of the named process.

For more information: https://kb.isc.org/article/AA-00788
@
text
@d10 1
a10 1
RELEASEVER=3
@


1.21.2.7
log
@SVN rev 241415 on 2012-10-10 19:50:15Z by delphij

MFC r241414:

Upgrade to 9.8.3-P4:

Prevents a lockup when queried a deliberately constructed combination
of records. [CVE-2012-5166]

For more information: https://kb.isc.org/article/AA-00801
@
text
@d10 1
a10 1
RELEASEVER=4
@


1.21.2.8
log
@## SVN ## Exported commit - http://svnweb.freebsd.org/changeset/base/245163
## SVN ## CVS IS DEPRECATED: http://wiki.freebsd.org/CvsIsDeprecated
## SVN ##
## SVN ## ------------------------------------------------------------------------
## SVN ## r245163 | erwin | 2013-01-08 09:05:09 +0000 (Tue, 08 Jan 2013) | 21 lines
## SVN ##
## SVN ## MFC r243981,243987:
## SVN ##
## SVN ##   Update to 9.8.4-P1.
## SVN ##
## SVN ##   New Features
## SVN ##
## SVN ##   *  Elliptic Curve Digital Signature Algorithm keys and signatures in
## SVN ##      DNSSEC are now supported per RFC 6605. [RT #21918]
## SVN ##
## SVN ##   Feature Changes
## SVN ##
## SVN ##   *  Improves OpenSSL error logging [RT #29932]
## SVN ##
## SVN ##   *  nslookup now returns a nonzero exit code when it is unable to get
## SVN ##      an answer.  [RT #29492]
## SVN ##
## SVN ##   Other critical bug fixes are included.
## SVN ##
## SVN ##   Approved by:  delphij (mentor)
## SVN ##   Sponsored by: DK Hostmaster A/S
## SVN ##
## SVN ## ------------------------------------------------------------------------
## SVN ##
@
text
@d8 1
a8 1
PATCHVER=4
d10 1
a10 1
RELEASEVER=1
@


1.21.2.9
log
@## SVN ## Exported commit - http://svnweb.freebsd.org/changeset/base/248808
## SVN ## CVS IS DEPRECATED: http://wiki.freebsd.org/CvsIsDeprecated
@
text
@d10 1
a10 1
RELEASEVER=2
@


1.21.2.10
log
@## SVN ## Exported commit - http://svnweb.freebsd.org/changeset/base/254402
## SVN ## CVS IS DEPRECATED: http://wiki.freebsd.org/CvsIsDeprecated
@
text
@a5 2
PRODUCT=BIND
DESCRIPTION=
d8 1
a8 1
PATCHVER=5
@


1.21.2.11
log
@## SVN ## Exported commit - http://svnweb.freebsd.org/changeset/base/254897
## SVN ## CVS IS DEPRECATED: http://wiki.freebsd.org/CvsIsDeprecated
@
text
@d7 1
a7 1
DESCRIPTION="(Extended Support Version)"
d9 2
a10 2
MINORVER=9
PATCHVER=3
@


1.21.2.12
log
@## SVN ## Exported commit - http://svnweb.freebsd.org/changeset/base/262706
## SVN ## CVS IS DEPRECATED: http://wiki.freebsd.org/CvsIsDeprecated
@
text
@d10 3
a12 4
PATCHVER=5
RELEASETYPE=
RELEASEVER=
EXTENSIONS=
@


1.20
log
@SVN rev 224092 on 2011-07-16 11:12:09Z by dougb

Upgrade to version 9.8.0-P4

This version has many new features, see /usr/share/doc/bind9/README
for details.
@
text
@d1 1
a1 1
# $Id: version,v 1.53.8.2.2.4 2011-06-21 20:44:01 each Exp $
d8 3
a10 3
PATCHVER=0
RELEASETYPE=-P
RELEASEVER=4
@


1.19
log
@SVN rev 223812 on 2011-07-06 00:48:31Z by dougb

Update to version 9.6-ESV-R4-P3

ALL BIND USERS ARE ENCOURAGED TO UPGRADE IMMEDIATELY

This update addresses the following vulnerability:

CVE-2011-2464
=============
Severity:	High
Exploitable:	Remotely

Description:

A defect in the affected BIND 9 versions allows an attacker to remotely
cause the "named" process to exit using a specially crafted packet. This
defect affects both recursive and authoritative servers. The code location
of the defect makes it impossible to protect BIND using ACLs configured
within named.conf or by disabling any features at compile-time or run-time.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2464
https://www.isc.org/software/bind/advisories/cve-2011-2464
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.11.2.2.2.3 2011-06-21 20:35:59 each Exp $
d7 4
a10 4
MINORVER=6
PATCHVER=
RELEASETYPE=-ESV
RELEASEVER=-R4-P3
@


1.18
log
@SVN rev 222395 on 2011-05-28 00:21:28Z by dougb

Upgrade to 9.6-ESV-R4-P1, which address the following issues:

1. Very large RRSIG RRsets included in a negative cache can trigger
an assertion failure that will crash named (BIND 9 DNS) due to an
off-by-one error in a buffer size check.

This bug affects all resolving name servers, whether DNSSEC validation
is enabled or not, on all BIND versions prior to today. There is a
possibility of malicious exploitation of this bug by remote users.

2. Named could fail to validate zones listed in a DLV that validated
insecure without using DLV and had DS records in the parent zone.

Add a patch provided by ru@@ and confirmed by ISC to fix a crash at
shutdown time when a SIG(0) key is being used.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.11.2.2.2.1 2011-05-27 00:19:16 each Exp $
d10 1
a10 1
RELEASEVER=-R4-P1
@


1.17
log
@SVN rev 218384 on 2011-02-06 22:46:07Z by dougb

Update to BIND 9.6.3, the latest from ISC on the 9.6 branch.

All 9.6 users with DNSSEC validation enabled should upgrade to this
version, or the latest version in the 9.7 branch, prior to 2011-03-31
in order to avoid validation failures for names in .COM as described
here:

https://www.isc.org/announcement/bind-9-dnssec-validation-fails-new-ds-record

In addition the fixes for this and other bugs, there are also the
following:

  * Various fixes to kerberos support, including GSS-TSIG
  * Various fixes to avoid leaking memory, and to problems that could
    prevent a clean shutdown of named
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.11 2011-01-30 06:38:13 marka Exp $
d8 3
a10 3
PATCHVER=3
RELEASETYPE=
RELEASEVER=
@


1.16
log
@SVN rev 216175 on 2010-12-04 05:58:56Z by dougb

Update to version 9.6-ESV-R3, the latest from ISC, which addresses
the following security vulnerabilities.

For more information regarding these issues please see:
http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisories

1. Cache incorrectly allows ncache and rrsig for the same type

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3613

   Affects resolver operators whose servers are open to potential
   attackers. Triggering the bug will cause the server to crash.

   This bug applies even if you do not have DNSSEC enabled.

2. Key algorithm rollover

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3614

   Affects resolver operators who are validating with DNSSEC, and
   querying zones which are in a key rollover period. The bug will
   cause answers to incorrectly be marked as insecure.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.8.4.4 2010/11/18 23:37:13 marka Exp $
d8 3
a10 3
PATCHVER=
RELEASETYPE=-ESV
RELEASEVER=-R3
@


1.15
log
@SVN rev 214586 on 2010-10-31 04:45:53Z by dougb

Update to 9.6-ESV-R2, the latest from ISC.

This version contains bug fixes that are relevant to any
caching/resolving name server; as well as DNSSEC-related
fixes.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.8.4.3 2010/09/03 02:57:11 marka Exp $
d10 1
a10 1
RELEASEVER=-R2
@


1.14
log
@SVN rev 208337 on 2010-05-20 08:15:06Z by dougb

Upgrade to 9.6.2-P2, which addresses the following;

   Named could return SERVFAIL for negative responses
   from unsigned zones.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.8.2.4 2010/05/10 02:07:03 marka Exp $
d8 3
a10 3
PATCHVER=2
RELEASETYPE=-P
RELEASEVER=2
@


1.13
log
@SVN rev 205292 on 2010-03-18 19:00:35Z by dougb

Update to 9.6.2-P1, the latest patchfix release which deals with
the problems related to the handling of broken DNSSEC trust chains.

This fix is only relevant for those who have DNSSEC validation
enabled and configure trust anchors from third parties, either
manually, or through a system like DLV.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.8.2.3 2010/03/04 00:08:28 marka Exp $
d10 1
a10 1
RELEASEVER=1
@


1.12
log
@SVN rev 204619 on 2010-03-03 05:45:24Z by dougb

Upgrade to version 9.6.2. This version includes all previously released
security patches to the 9.6.1 version, as well as many other bug fixes.

This version also incorporates a different fix for the problem we had
patched in contrib/bind9/bin/dig/dighost.c, so that file is now back
to being the same as the vendor version.

Due to the fact that the DNSSEC algorithm that will be used to sign the
root zone is only included in this version and in 9.7.x those who wish
to do validation MUST upgrade to one of these prior to July 2010.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.8 2010/02/18 03:34:50 marka Exp $
d9 2
a10 2
RELEASETYPE= 
RELEASEVER=
@


1.11
log
@SVN rev 202961 on 2010-01-25 06:18:31Z by dougb

Upgrade to BIND 9.6.1-P3.

This version address the following vulnerabilities:

BIND 9 Cache Update from Additional Section
https://www.isc.org/advisories/CVE-2009-4022v6
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022
A nameserver with DNSSEC validation enabled may incorrectly add
unauthenticated records to its cache that are received during the
resolution of a recursive client query

BIND 9 DNSSEC validation code could cause bogus NXDOMAIN responses
https://www.isc.org/advisories/CVE-2010-0097
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097
There was an error in the DNSSEC NSEC/NSEC3 validation code that could
cause bogus NXDOMAIN responses (that is, NXDOMAIN responses for records
proven by NSEC or NSEC3 to exist) to be cached as if they had validated
correctly

These issues only affect systems with DNSSEC validation enabled.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.5.8.3 2009/12/31 20:29:20 each Exp $
d8 3
a10 3
PATCHVER=1
RELEASETYPE=-P
RELEASEVER=3
@


1.10
log
@SVN rev 199958 on 2009-11-30 03:38:34Z by dougb

Update to BIND 9.6.1-P2. The vulnerability this is designed to fix is
related to DNSSEC validation on a resolving name server that allows
access to untrusted users. If your system does not fall into all 3 of
these categories you do not need to update immediately.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.5.8.2 2009/11/18 23:58:04 marka Exp $
d10 1
a10 1
RELEASEVER=2
@


1.9
log
@SVN rev 195936 on 2009-07-29 00:15:39Z by dougb

Update to version 9.6.1-P1 which addresses a remote DoS vulnerability:

	Receipt of a specially-crafted dynamic update message may
	cause BIND 9 servers to exit. This vulnerability affects all
	servers -- it is not limited to those that are configured to
	allow dynamic updates. Access controls will not provide an
	effective workaround.

More details can be found here: https://www.isc.org/node/474

All BIND users are encouraged to update to a patched version ASAP.

Approved by:	re (re -> SO -> dougb)
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.5.8.1 2009/07/28 14:18:08 marka Exp $
d10 1
a10 1
RELEASEVER=1
@


1.9.2.1
log
@SVN rev 200383 on 2009-12-11 01:23:58Z by dougb

MFC r199958:

Update to BIND 9.6.1-P2. The vulnerability this is designed to fix is
related to DNSSEC validation on a resolving name server that allows
access to untrusted users. If your system does not fall into all 3 of
these categories you do not need to update immediately.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.5.8.2 2009/11/18 23:58:04 marka Exp $
d10 1
a10 1
RELEASEVER=2
@


1.9.2.2
log
@SVN rev 203635 on 2010-02-07 20:28:24Z by dougb

MFC 202961:

Upgrade to BIND 9.6.1-P3.

This version address the following vulnerabilities:

BIND 9 Cache Update from Additional Section
https://www.isc.org/advisories/CVE-2009-4022v6
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022
A nameserver with DNSSEC validation enabled may incorrectly add
unauthenticated records to its cache that are received during the
resolution of a recursive client query

BIND 9 DNSSEC validation code could cause bogus NXDOMAIN responses
https://www.isc.org/advisories/CVE-2010-0097
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097
There was an error in the DNSSEC NSEC/NSEC3 validation code that could
cause bogus NXDOMAIN responses (that is, NXDOMAIN responses for records
proven by NSEC or NSEC3 to exist) to be cached as if they had validated
correctly

These issues only affect systems with DNSSEC validation enabled.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.5.8.3 2009/12/31 20:29:20 each Exp $
d10 1
a10 1
RELEASEVER=3
@


1.9.2.3
log
@SVN rev 205820 on 2010-03-29 06:31:58Z by dougb

Update to 9.6.2-P1, the latest patchfix release which deals with
the problems related to the handling of broken DNSSEC trust chains.

This fix is only relevant for those who have DNSSEC validation
enabled and configure trust anchors from third parties, either
manually, or through a system like DLV.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.8.2.3 2010/03/04 00:08:28 marka Exp $
d8 1
a8 1
PATCHVER=2
d10 1
a10 1
RELEASEVER=1
@


1.9.2.4
log
@SVN rev 208473 on 2010-05-23 21:15:36Z by dougb

Upgrade to 9.6.2-P2, which addresses the following;

	Named could return SERVFAIL for negative responses
	from unsigned zones.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.8.2.4 2010/05/10 02:07:03 marka Exp $
d10 1
a10 1
RELEASEVER=2
@


1.9.2.5
log
@SVN rev 214811 on 2010-11-04 21:48:39Z by dougb

Update to 9.6-ESV-R2, the latest from ISC.

This version contains bug fixes that are relevant to any
caching/resolving name server; as well as DNSSEC-related
fixes.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.8.4.3 2010/09/03 02:57:11 marka Exp $
d8 3
a10 3
PATCHVER=
RELEASETYPE=-ESV
RELEASEVER=-R2
@


1.9.2.6
log
@SVN rev 216307 on 2010-12-08 19:59:53Z by dougb

Update to version 9.6-ESV-R4, the latest from ISC, which addresses
the following security vulnerabilities.

For more information regarding these issues please see:
http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisories

1. Cache incorrectly allows ncache and rrsig for the same type

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3613

   Affects resolver operators whose servers are open to potential
   attackers. Triggering the bug will cause the server to crash.

   This bug applies even if you do not have DNSSEC enabled.

2. Key algorithm rollover

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3614

   Affects resolver operators who are validating with DNSSEC, and
   querying zones which are in a key rollover period. The bug will
   cause answers to incorrectly be marked as insecure.

Approved by:	re (kensmith)
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.8.4.4 2010/11/18 23:37:13 marka Exp $
d10 1
a10 1
RELEASEVER=-R3
@


1.9.2.7
log
@SVN rev 218334 on 2011-02-05 19:13:34Z by dougb

Update to BIND 9.6.3, the latest from ISC on the 9.6 branch.

All 9.6 users with DNSSEC validation enabled should upgrade to this
version, or the latest version in the 9.7 branch, prior to 2011-03-31
in order to avoid validation failures for names in .COM as described
here:

https://www.isc.org/announcement/bind-9-dnssec-validation-fails-new-ds-record

In addition the fixes for this and other bugs, there are also the
following:

  * Various fixes to kerberos support, including GSS-TSIG
  * Various fixes to avoid leaking memory, and to problems that could
    prevent a clean shutdown of named
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.11 2011-01-30 06:38:13 marka Exp $
d8 3
a10 3
PATCHVER=3
RELEASETYPE=
RELEASEVER=
@


1.9.2.8
log
@SVN rev 222396 on 2011-05-28 00:33:06Z by dougb

Upgrade to 9.6-ESV-R4-P1, which address the following issues:

1. Very large RRSIG RRsets included in a negative cache can trigger
an assertion failure that will crash named (BIND 9 DNS) due to an
off-by-one error in a buffer size check.

This bug affects all resolving name servers, whether DNSSEC validation
is enabled or not, on all BIND versions prior to today. There is a
possibility of malicious exploitation of this bug by remote users.

2. Named could fail to validate zones listed in a DLV that validated
insecure without using DLV and had DS records in the parent zone.

Add a patch provided by ru@@ and confirmed by ISC to fix a crash at
shutdown time when a SIG(0) key is being used.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.11.2.2.2.1 2011-05-27 00:19:16 each Exp $
d8 3
a10 3
PATCHVER=
RELEASETYPE=-ESV
RELEASEVER=-R4-P1
@


1.9.2.9
log
@SVN rev 223815 on 2011-07-06 00:50:54Z by dougb

Update to version 9.6-ESV-R4-P3

ALL BIND USERS ARE ENCOURAGED TO UPGRADE IMMEDIATELY

This update addresses the following vulnerability:

CVE-2011-2464
=============
Severity:	High
Exploitable:	Remotely

Description:

A defect in the affected BIND 9 versions allows an attacker to remotely
cause the "named" process to exit using a specially crafted packet. This
defect affects both recursive and authoritative servers. The code location
of the defect makes it impossible to protect BIND using ACLs configured
within named.conf or by disabling any features at compile-time or run-time.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2464
https://www.isc.org/software/bind/advisories/cve-2011-2464
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.11.2.2.2.3 2011-06-21 20:35:59 each Exp $
d10 1
a10 1
RELEASEVER=-R4-P3
@


1.9.2.10
log
@SVN rev 224596 on 2011-08-02 08:07:59Z by dougb

Update to version 9.6-ESV-R5 which contains various bug fixes
and improvements:

ftp://ftp.isc.org/isc/bind9/9.6-ESV-R5/RELEASE-NOTES-BIND-9.6-ESV.html
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.14 2011-07-21 02:48:13 marka Exp $
d10 1
a10 1
RELEASEVER=-R5
@


1.9.2.11
log
@SVN rev 227599 on 2011-11-17 00:36:10Z by dougb

Upgrade to BIND 9.6-ESV-R5-P1 to address the following DDOS bug:

Recursive name servers are failing with an assertion:
INSIST(! dns_rdataset_isassociated(sigrdataset))

At this time it is not thought that authoritative-only servers
are affected, but information about this bug is evolving rapidly.

Because it may be possible to trigger this bug even on networks
that do not allow untrusted users to access the recursive name
servers (perhaps via specially crafted e-mail messages, and/or
malicious web sites) it is recommended that ALL operators of
recursive name servers upgrade immediately.

For more information see:
https://www.isc.org/software/bind/advisories/cve-2011-tbd
which will be updated as more information becomes available.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4313
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.14.10.1 2011-11-16 09:18:28 marka Exp $
d10 1
a10 1
RELEASEVER=-R5-P1
@


1.9.2.12
log
@SVN rev 233915 on 2012-04-05 04:31:17Z by dougb

Update to version 9.6-ESV-R6, the latest from ISC, which contains numerous
bug fixes.
@
text
@d1 1
a1 1
# $Id$
d10 1
a10 1
RELEASEVER=-R6
@


1.9.2.13
log
@SVN rev 236197 on 2012-05-28 19:48:37Z by dougb

Upgrade to BIND version 9.6-ESV-R7, the latest from ISC.

Feature Change

*  BIND now recognizes the TLSA resource record type, created to
   support IETF DANE (DNS-based Authentication of Named Entities)

Bug Fix

*  The locking strategy around the handling of iterative queries
   has been tuned to reduce unnecessary contention in a multi-
   threaded environment.

Other critical bug fixes are included.

All BIND users are encouraged to upgrade.
@
text
@d10 1
a10 1
RELEASEVER=-R7
@


1.9.2.14
log
@SVN rev 236590 on 2012-06-04 22:21:55Z by dougb

Upgrade to 9.6-ESV-R7-P1, the latest from ISC. This version contains
a critical bugfix:

  Processing of DNS resource records where the rdata field is zero length
  may cause various issues for the servers handling them.

  Processing of these records may lead to unexpected outcomes. Recursive
  servers may crash or disclose some portion of memory to the client.
  Secondary servers may crash on restart after transferring a zone
  containing these records. Master servers may corrupt zone data if the
  zone option "auto-dnssec" is set to "maintain". Other unexpected
  problems that are not listed here may also be encountered.

All BIND users are strongly encouraged to upgrade.
@
text
@d10 1
a10 1
RELEASEVER=-R7-P1
@


1.9.2.15
log
@SVN rev 238749 on 2012-07-24 19:04:35Z by dougb

Heavy DNSSEC Validation Load Can Cause a "Bad Cache" Assertion Failure
in BIND9

High numbers of queries with DNSSEC validation enabled can cause an
assertion failure in named, caused by using a "bad cache" data structure
before it has been initialized.

CVE: CVE-2012-3817
Posting date: 24 July, 2012
@
text
@d10 1
a10 1
RELEASEVER=-R7-P2
@


1.9.2.16
log
@SVN rev 240732 on 2012-09-20 04:35:20Z by dougb

Upgrade to 9.6-ESV-R7-P3:

Prevents a crash when queried for a record whose RDATA exceeds
65535 bytes.

Prevents a crash when validating caused by using "Bad cache" data
before it has been initialized.

ISC_QUEUE handling for recursive clients was updated to address
a race condition that could cause a memory leak. This rarely
occurred with UDP clients, but could be a significant problem
for a server handling a steady rate of TCP queries.

A condition has been corrected where improper handling of
zero-length RDATA could cause undesirable behavior, including
termination of the named process.

For more information: https://kb.isc.org/article/AA-00788
@
text
@d10 1
a10 1
RELEASEVER=-R7-P3
@


1.9.2.17
log
@SVN rev 241443 on 2012-10-11 13:25:09Z by erwin

Update to 9.6-ESV-R7-P4

Prevents a lockup when queried a deliberately constructed combination
of records. [CVE-2012-5166]

For more information: https://kb.isc.org/article/AA-00801

Approved by:	bz
@
text
@d10 1
a10 1
RELEASEVER=-R7-P4
@


1.9.2.18
log
@## SVN ## Exported commit - http://svnweb.freebsd.org/changeset/base/245039
## SVN ## CVS IS DEPRECATED: http://wiki.freebsd.org/CvsIsDeprecated
## SVN ##
## SVN ## ------------------------------------------------------------------------
## SVN ## r245039 | erwin | 2013-01-04 13:36:31 +0000 (Fri, 04 Jan 2013) | 7 lines
## SVN ##
## SVN ## Update to 9.6-ESV-R8.
## SVN ##
## SVN ## All security fixes were previously merged.
## SVN ## Release notes: https://kb.isc.org/article/AA-00795
## SVN ##
## SVN ## Approved by:	delphij (mentor)
## SVN ##
## SVN ## ------------------------------------------------------------------------
## SVN ##
@
text
@d10 1
a10 1
RELEASEVER=-R8
@


1.9.2.19
log
@## SVN ## Exported commit - http://svnweb.freebsd.org/changeset/base/246656
## SVN ## CVS IS DEPRECATED: http://wiki.freebsd.org/CvsIsDeprecated
@
text
@d7 4
a10 4
MINORVER=8
PATCHVER=4
RELEASETYPE=-P
RELEASEVER=1
@


1.9.2.20
log
@## SVN ## Exported commit - http://svnweb.freebsd.org/changeset/base/248807
## SVN ## CVS IS DEPRECATED: http://wiki.freebsd.org/CvsIsDeprecated
@
text
@d10 1
a10 1
RELEASEVER=2
@


1.9.2.21
log
@## SVN ## Exported commit - http://svnweb.freebsd.org/changeset/base/262707
## SVN ## CVS IS DEPRECATED: http://wiki.freebsd.org/CvsIsDeprecated
@
text
@a5 2
PRODUCT=BIND
DESCRIPTION=
d8 3
a10 4
PATCHVER=7
RELEASETYPE=
RELEASEVER=
EXTENSIONS=
@


1.8
log
@SVN rev 194995 on 2009-06-25 19:16:29Z by dougb

Update to the final release version of BIND 9.6.1. It has the following
changes from the 9.6.1rc1 version. The first 2 only affect DNSSEC.

          named could incorrectly delete NSEC3 records for
          empty nodes when processing a update request.

          Accept DS responses from delegation only zones.

          "delegation-only" was not being accepted in
          delegation-only type zones.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.5 2009/06/04 04:02:41 marka Exp $
d9 2
a10 2
RELEASETYPE=
RELEASEVER=
@


1.7
log
@SVN rev 193149 on 2009-05-31 05:42:58Z by dougb

Update BIND to version 9.6.1rc1. This version has better performance and
lots of new features compared to 9.4.x, including:

	Full NSEC3 support
	Automatic zone re-signing
	New update-policy methods tcp-self and 6to4-self
	DHCID support.
	More detailed statistics counters including those supported in BIND 8.
	Faster ACL processing.
	Efficient LRU cache-cleaning mechanism.
	NSID support.
@
text
@d1 1
a1 1
# $Id: version,v 1.43.12.4 2009/04/08 06:55:37 marka Exp $
d9 2
a10 2
RELEASETYPE=rc
RELEASEVER=1
@


1.6
log
@SVN rev 190227 on 2009-03-21 23:00:40Z by dougb

Merge from vendor/bind9/dist as of the 9.4.3-P2 import
@
text
@d1 2
a2 2
# $Id: version,v 1.29.134.23.2.2 2009/03/17 02:23:49 marka Exp $
#
d7 4
a10 4
MINORVER=4
PATCHVER=3
RELEASETYPE=-P
RELEASEVER=2
@


1.5
log
@SVN rev 186942 on 2009-01-09 11:45:45Z by dougb

Merge from vendor/bind9/dist as of the 9.4.3-P1 import
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.23.2.1 2008/12/24 00:21:22 marka Exp $
d10 1
a10 1
RELEASEVER=1
@


1.4
log
@SVN rev 186462 on 2008-12-23 22:47:56Z by dougb

Merge from vendor/bind9/dist as of the 9.4.3 import
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.23 2008/11/12 04:17:12 marka Exp $
d9 2
a10 2
RELEASETYPE=
RELEASEVER=
@


1.3
log
@SVN rev 182645 on 2008-09-01 22:54:49Z by dougb

Merge from vendor/bind9/dist as of the 9.4.2-P2 import
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.18.8.2 2008/07/29 05:03:28 each Exp $
d8 3
a10 3
PATCHVER=2
RELEASETYPE=-P
RELEASEVER=2
@


1.2
log
@SVN rev 180477 on 2008-07-12 09:38:35Z by dougb

Merge from vendor/bind9/dist as of the 9.4.2-P1 import, including
the patch from ISC for lib/bind9/check.c and deletion of unused
files in lib/bind.

This version will by default randomize the UDP query source port
(and sequence number of course) for every query.

In order to take advantage of this randomization users MUST have an
appropriate firewall configuration to allow UDP queries to be sent and
answers to be received on random ports; and users MUST NOT specify a
port number using the query-source[-v6] options.

The avoid-v[46]-udp-ports options exist for users who wish to eliminate
certain port numbers from being chosen by named for this purpose. See
the ARM Chatper 6 for more information.

Also please note, this issue applies only to UDP query ports. A random
ephemeral port is always chosen for TCP queries.

This issue applies primarily to name servers whose main purpose is to
resolve random queries (sometimes referred to as "caching" servers, or
more properly as "resolving" servers), although even an "authoritative"
name server will make some queries, primarily at startup time.

All users of BIND are strongly encouraged to upgrade to the latest
version, and to utilize the source port randomization feature.

This update addresses issues raised in:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447
http://www.kb.cert.org/vuls/id/800113
http://tools.ietf.org/html/draft-ietf-dnsext-forgery-resilience
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.18.8.1 2008/05/22 21:28:03 each Exp $
d10 1
a10 1
RELEASEVER=1
@


1.1
log
@Initial revision
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.10 2004/09/01 07:29:40 marka Exp $
d7 4
a10 4
MINORVER=3
PATCHVER=0
RELEASETYPE=rc
RELEASEVER=4
@


1.1.1.1
log
@Vender import of BIND 9.3.0rc4.
@
text
@@


1.1.1.2
log
@Vendor import of BIND 9.3.0.
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.10.4.1 2004/09/20 01:01:01 marka Exp $
d9 2
a10 2
RELEASETYPE=
RELEASEVER=
@


1.1.1.3
log
@Vendor import of BIND 9.3.1
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.17 2005/03/03 04:51:08 marka Exp $
d8 1
a8 1
PATCHVER=1
@


1.1.1.3.2.1
log
@MFC import of BIND 9.3.2
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.21 2005/12/14 00:43:14 marka Exp $
d8 1
a8 1
PATCHVER=2
@


1.1.1.3.2.2
log
@MFC remaining changes between BIND 9.3.2 and 9.3.2-P1.  The "functional"
changes were part of the FreeBSD-SA-06:20.bind commit.

Requested by:	dougb
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.21.4.1 2006/08/17 07:12:31 marka Exp $
d9 2
a10 2
RELEASETYPE=-P
RELEASEVER=1
@


1.1.1.3.2.3
log
@MFC the upgrade to BIND 9.3.2-P2. This is mostly a noop in the base,
since if you're compiling the base with this upgraded, you've already
got your openssl upgraded, but it's a good idea to include this for
completeness sake.

Approved by:	re (hrs)
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.21.4.2 2006/10/04 07:00:13 marka Exp $
d10 1
a10 1
RELEASEVER=2
@


1.1.1.3.2.3.2.1
log
@MFC upgrade to version 9.3.3

Approved by:    re (kensmith)
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.26 2006/11/28 00:52:38 marka Exp $
d8 3
a10 3
PATCHVER=3
RELEASETYPE=
RELEASEVER=
@


1.1.1.3.2.4
log
@MFC upgrade to version 9.3.3

Approved by:	re (kensmith)
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.26 2006/11/28 00:52:38 marka Exp $
d8 3
a10 3
PATCHVER=3
RELEASETYPE=
RELEASEVER=
@


1.1.1.3.2.5
log
@MFC the upgrade to BIND 9.3.4
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.26.4.1 2007/01/11 05:06:25 marka Exp $
d8 1
a8 1
PATCHVER=4
@


1.1.1.3.2.6
log
@Update to 9.3.4-P1, which fixes the following:

The DNS query id generation is vulnerable to cryptographic
analysis which provides a 1 in 8 chance of guessing the next
query id for 50% of the query ids. This can be used to perform
cache poisoning by an attacker.

This bug only affects outgoing queries, generated by BIND 9 to
answer questions as a resolver, or when it is looking up data
for internal uses, such as when sending NOTIFYs to slave name
servers.

All users are encouraged to upgrade.

See also:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2926
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.26.4.2 2007/06/27 02:07:20 marka Exp $
d9 2
a10 2
RELEASETYPE=-P
RELEASEVER=1
@


1.1.1.3.2.7
log
@SVN rev 179502 on 2008-06-03 05:38:10Z by dougb

Update to version 9.3.5. It contains the latest bug fixes, updates
to root server addresses, and a fix for the vulnerability mentioned
here: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0122

Users of BIND 9.3.x are strongly encouraged to upgrade to this
version. Also, the 9.3.x branch is now in maintenance-only mode.
Users are encouraged to investigate BIND 9.4.x or perhaps 9.5.x.

http://www.isc.org/index.pl?/sw/bind/versions_and_support.php

This udpate is being done by updating the files directly in this
branch rather than an import + MFC because BIND in HEAD is 9.4.x.
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.31 2008/04/03 00:22:17 each Exp $
d8 3
a10 3
PATCHVER=5
RELEASETYPE=
RELEASEVER=
@


1.1.1.3.2.8
log
@SVN rev 180479 on 2008-07-12 10:07:33Z by dougb

Merge from vendor/bind9/dist-9.3 as of the 9.3.5-P1 import.

This version will by default randomize the UDP query source port
(and sequence number of course) for every query.

In order to take advantage of this randomization users MUST have an
appropriate firewall configuration to allow UDP queries to be sent and
answers to be received on random ports; and users MUST NOT specify a
port number using the query-source[-v6] options.

The avoid-v[46]-udp-ports options exist for users who wish to eliminate
certain port numbers from being chosen by named for this purpose. See
the ARM Chatper 6 for more information.

Also please note, this issue applies only to UDP query ports. A random
ephemeral port is always chosen for TCP queries.

This issue applies primarily to name servers whose main purpose is to
resolve random queries (sometimes referred to as "caching" servers, or
more properly as "resolving" servers), although even an "authoritative"
name server will make some queries, primarily at startup time.

All users of BIND are strongly encouraged to upgrade to the latest
version, and to utilize the source port randomization feature.

This update addresses issues raised in:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447
http://www.kb.cert.org/vuls/id/800113
http://tools.ietf.org/html/draft-ietf-dnsext-forgery-resilience
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.31.4.1 2008/05/22 21:11:13 each Exp $
d9 2
a10 2
RELEASETYPE=-P
RELEASEVER=1
@


1.1.1.3.2.9
log
@SVN rev 182647 on 2008-09-01 22:56:10Z by dougb

Merge from vendor/bind9/dist-9.3 as of the 9.3.5-P2 import
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.31.4.2 2008/07/29 05:03:50 each Exp $
d10 1
a10 1
RELEASEVER=2
@


1.1.1.3.2.10
log
@SVN rev 186999 on 2009-01-10 04:30:27Z by dougb

Merge from vendor/bind9/dist-9.3 as of the 9.3.6-P1 import
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.35 2008/12/24 00:21:45 marka Exp $
d8 1
a8 1
PATCHVER=6
d10 1
a10 1
RELEASEVER=1
@


1.1.1.4
log
@Vendor import of BIND 9.3.2
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.21 2005/12/14 00:43:14 marka Exp $
d8 1
a8 1
PATCHVER=2
@


1.1.1.5
log
@Vendor import of BIND 9.3.2-P1, which addresses the following security
vulnerabilities:

http://www.niscc.gov.uk/niscc/docs/re-20060905-00590.pdf?lang=en
2066.  [security]      Handle SIG queries gracefully. [RT #16300]

http://www.kb.cert.org/vuls/id/697164
1941.  [bug]           ncache_adderesult() should set eresult even if no
                       rdataset is passed to it. [RT #15642]

All users of BIND 9 are encouraged to upgrade to this version.
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.21.4.1 2006/08/17 07:12:31 marka Exp $
d9 2
a10 2
RELEASETYPE=-P
RELEASEVER=1
@


1.1.1.6
log
@Update to version 9.3.2-P2, which addresses the vulnerability
announced by ISC dated 31 October (delivered via e-mail to the
bind-announce@@isc.org list on 2 November):

Description:
        Because of OpenSSL's recently announced vulnerabilities
        (CAN-2006-4339, CVE-2006-2937 and CVE-2006-2940) which affect named,
        we are announcing this workaround and releasing patches.  A proof of
        concept attack on OpenSSL has been demonstrated for CAN-2006-4339.

        OpenSSL is required to use DNSSEC with BIND.

Fix for version 9.3.2-P1 and lower:
        Upgrade to BIND 9.3.2-P2, then generate new RSASHA1 and
        RSAMD5 keys for all old keys using the old default exponent
        and perform a key rollover to these new keys.

        These versions also change the default RSA exponent to be
        65537 which is not vulnerable to the attacks described in
        CAN-2006-4339.
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.21.4.2 2006/10/04 07:00:13 marka Exp $
d10 1
a10 1
RELEASEVER=2
@


1.1.1.7
log
@Vendor import of BIND 9.3.3
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.26 2006/11/28 00:52:38 marka Exp $
d8 3
a10 3
PATCHVER=3
RELEASETYPE=
RELEASEVER=
@


1.1.1.8
log
@Vendor import of BIND 9.3.4
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.26.4.1 2007/01/11 05:06:25 marka Exp $
d8 1
a8 1
PATCHVER=4
@


1.1.1.9
log
@Vendor import of BIND 9.4.1
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.13.8.1 2007/04/30 01:11:30 marka Exp $
d7 2
a8 2
MINORVER=4
PATCHVER=1
@


1.1.1.10
log
@Vendor import of 9.4.1-P1, which has fixes for the following:

1. The default access control lists (acls) are not being
correctly set. If not set anyone can make recursive queries
and/or query the cache contents.

See also:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2925

2. The DNS query id generation is vulnerable to cryptographic
analysis which provides a 1 in 8 chance of guessing the next
query id for 50% of the query ids. This can be used to perform
cache poisoning by an attacker.

This bug only affects outgoing queries, generated by BIND 9 to
answer questions as a resolver, or when it is looking up data
for internal uses, such as when sending NOTIFYs to slave name
servers.

All users are encouraged to upgrade.

See also:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2926

Approved by:	re (kensmith, implicit)
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.13.8.2 2007/06/27 02:10:22 marka Exp $
d9 2
a10 2
RELEASETYPE=-P
RELEASEVER=1
@


1.1.1.10.2.1
log
@MFC contrib code and bmake changes for BIND version 9.4.2

Approved by:	re (kensmith)
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.18 2007/11/19 15:25:23 each Exp $
d8 3
a10 3
PATCHVER=2
RELEASETYPE=
RELEASEVER=
@


1.1.1.10.2.2
log
@SVN rev 180499 on 2008-07-13 18:42:38Z by cperciva

Improve randomization in BIND to prevent response spoofing.

Security:	FreeBSD-SA-08:06.bind
Approved by:	so (cperciva)
Thanks to:	remko, csjp
No thanks to:	bronchitis
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.18.8.1 2008/05/22 21:28:03 each Exp $
d9 2
a10 2
RELEASETYPE=-P
RELEASEVER=1
@


1.1.1.10.2.3
log
@SVN rev 184967 on 2008-11-14 11:00:34Z by dougb

MFC the BIND 9.4.2-P2 update

Approved by:	re (kib)
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.18.8.2 2008/07/29 05:03:28 each Exp $
d10 1
a10 1
RELEASEVER=2
@


1.1.1.10.2.4
log
@SVN rev 186996 on 2009-01-10 03:00:21Z by dougb

MFC the BIND 9.4.3 and 9.4.3-P1 updates
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.23.2.1 2008/12/24 00:21:22 marka Exp $
d8 1
a8 1
PATCHVER=3
d10 1
a10 1
RELEASEVER=1
@


1.1.1.10.2.5
log
@SVN rev 190228 on 2009-03-21 23:03:56Z by dougb

MFC the 9.4.3-P2 update
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.23.2.2 2009/03/17 02:23:49 marka Exp $
d10 1
a10 1
RELEASEVER=2
@


1.1.1.10.2.6
log
@SVN rev 195933 on 2009-07-28 23:59:22Z by dougb

Update to version 9.4.3-P3 which addresses a remote DoS vulnerability:

	Receipt of a specially-crafted dynamic update message may
	cause BIND 9 servers to exit. This vulnerability affects all
	servers -- it is not limited to those that are configured to
	allow dynamic updates. Access controls will not provide an
	effective workaround.

More details can be found here: https://www.isc.org/node/474

All BIND users are encouraged to update to a patched version ASAP.
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.23.2.3 2009/07/28 13:57:27 marka Exp $
d10 1
a10 1
RELEASEVER=3
@


1.1.1.10.2.7
log
@SVN rev 200393 on 2009-12-11 02:23:04Z by dougb

Update to version 9.4.3-P4. The vulnerability this is designed to fix is
related to DNSSEC validation on a resolving name server that allows
access to untrusted users. If your system does not fall into all 3 of
these categories you do not need to update immediately.
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.23.2.4 2009/11/19 00:25:17 marka Exp $
d10 1
a10 1
RELEASEVER=4
@


1.1.1.10.2.7.2.1
log
@SVN rev 203961 on 2010-02-16 18:10:35Z by dougb

Merge from stable/7, version 203948:

Upgrade to BIND 9.4-ESV. This version incorporates all bug and security
fixes since the release of 9.4.3, including the most recent -P5 security
fix detailed below.

From the README:
BIND 9.4-ESV will be supported until December 31, 2010, at
which time you will need to upgrade to the current release
of BIND.

This versions address the following vulnerabilities:

BIND 9 Cache Update from Additional Section
https://www.isc.org/advisories/CVE-2009-4022v6
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022
A nameserver with DNSSEC validation enabled may incorrectly add
unauthenticated records to its cache that are received during the
resolution of a recursive client query

BIND 9 DNSSEC validation code could cause bogus NXDOMAIN responses
https://www.isc.org/advisories/CVE-2010-0097
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097
There was an error in the DNSSEC NSEC/NSEC3 validation code that could
cause bogus NXDOMAIN responses (that is, NXDOMAIN responses for records
proven by NSEC or NSEC3 to exist) to be cached as if they had validated
correctly

These issues only affect systems with DNSSEC validation enabled.

Approved by:	re (kensmith)
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.28 2010/01/21 01:10:54 marka Exp $
d8 3
a10 3
PATCHVER=
RELEASETYPE=-ESV
RELEASEVER=
@


1.1.1.10.2.8
log
@SVN rev 203948 on 2010-02-16 05:14:51Z by dougb

Upgrade to BIND 9.4-ESV. This version incorporates all bug and security
fixes since the release of 9.4.3, including the most recent -P5 security
fix detailed below.

From the README:
BIND 9.4-ESV will be supported until December 31, 2010, at
which time you will need to upgrade to the current release
of BIND.

This versions address the following vulnerabilities:

BIND 9 Cache Update from Additional Section
https://www.isc.org/advisories/CVE-2009-4022v6
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022
A nameserver with DNSSEC validation enabled may incorrectly add
unauthenticated records to its cache that are received during the
resolution of a recursive client query

BIND 9 DNSSEC validation code could cause bogus NXDOMAIN responses
https://www.isc.org/advisories/CVE-2010-0097
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097
There was an error in the DNSSEC NSEC/NSEC3 validation code that could
cause bogus NXDOMAIN responses (that is, NXDOMAIN responses for records
proven by NSEC or NSEC3 to exist) to be cached as if they had validated
correctly

These issues only affect systems with DNSSEC validation enabled.

Approved by:	re (kensmith)
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.28 2010/01/21 01:10:54 marka Exp $
d8 3
a10 3
PATCHVER=
RELEASETYPE=-ESV
RELEASEVER=
@


1.1.1.10.2.9
log
@SVN rev 205868 on 2010-03-29 23:00:45Z by dougb

Update to 9.4-ESV-R1, the latest patchfix release which deals with
the problems related to the handling of broken DNSSEC trust chains.

This fix is only relevant for those who have DNSSEC validation
enabled and configure trust anchors from third parties, either
manually, or through a system like DLV.
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.29 2010/03/04 00:25:25 marka Exp $
d10 1
a10 1
RELEASEVER=-R1
@


1.1.1.10.2.10
log
@SVN rev 208485 on 2010-05-24 06:41:57Z by dougb

Upgrade to 9.4-ESV-R2, which addresses the following:

	Named could return SERVFAIL for negative responses
	from unsigned zones.
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.30 2010/05/10 01:56:40 marka Exp $
d10 1
a10 1
RELEASEVER=-R2
@


1.1.1.10.2.11
log
@SVN rev 214812 on 2010-11-04 21:50:19Z by dougb

MFV version 9.4-ESV-R3

This version contains several fixes for DNSSEC and DLV, as well as
fixes relevant to any resolving name server.
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.31 2010/09/02 07:23:32 marka Exp $
d10 1
a10 1
RELEASEVER=-R3
@


1.1.1.10.2.12
log
@SVN rev 216336 on 2010-12-09 21:11:53Z by dougb

MFV: vendor/bind9/dist-9.4

Update to version 9.4-ESV-R4, the latest from ISC, which addresses
the following security vulnerabilities.

For more information regarding these issues please see:
http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisories

1. Cache incorrectly allows ncache and rrsig for the same type

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3613

   Affects resolver operators whose servers are open to potential
   attackers. Triggering the bug will cause the server to crash.

   This bug applies even if you do not have DNSSEC enabled.

2. Key algorithm rollover

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3614

   Affects resolver operators who are validating with DNSSEC, and
   querying zones which are in a key rollover period. The bug will
   cause answers to incorrectly be marked as insecure.

Approved by:	re (kib)
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.32 2010/11/18 01:34:50 marka Exp $
d10 1
a10 1
RELEASEVER=-R4
@


1.1.1.10.2.13
log
@SVN rev 222399 on 2011-05-28 00:58:19Z by dougb

Upgrade to 9.4-ESV-R4-P1, which addresses the following issues:

1. Very large RRSIG RRsets included in a negative cache can trigger
an assertion failure that will crash named (BIND 9 DNS) due to an
off-by-one error in a buffer size check.

This bug affects all resolving name servers, whether DNSSEC validation
is enabled or not, on all BIND versions prior to today. There is a
possibility of malicious exploitation of this bug by remote users.

2. Named could fail to validate zones listed in a DLV that validated
insecure without using DLV and had DS records in the parent zone.
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.32.10.1 2011-05-26 23:56:25 each Exp $
d10 1
a10 1
RELEASEVER=-R4-P1
@


1.1.1.10.2.14
log
@SVN rev 224601 on 2011-08-02 09:42:58Z by dougb

Update to version 9.4-ESV-R5 which contains various bug fixes
and improvements

See RELEASE-NOTES-BIND-9.4-ESV.* for details

This is expected to be the final release of the BIND 9.4 branch
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.35 2011-07-21 02:11:00 marka Exp $
d10 1
a10 1
RELEASEVER=-R5
@


1.1.1.10.2.15
log
@SVN rev 227603 on 2011-11-17 01:10:16Z by dougb

Upgrade to BIND 9.4-ESV-R5-P1 to address the following DDOS bug:

Recursive name servers are failing with an assertion:
INSIST(! dns_rdataset_isassociated(sigrdataset))

At this time it is not thought that authoritative-only servers
are affected, but information about this bug is evolving rapidly.

Because it may be possible to trigger this bug even on networks
that do not allow untrusted users to access the recursive name
servers (perhaps via specially crafted e-mail messages, and/or
malicious web sites) it is recommended that ALL operators of
recursive name servers upgrade immediately.

For more information see:
https://www.isc.org/software/bind/advisories/cve-2011-tbd
which will be updated as more information becomes available.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4313
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.35.2.1 2011-11-16 09:33:40 each Exp $
d10 1
a10 1
RELEASEVER=-R5-P1
@


1.1.1.11
log
@Vendor import of BIND 9.4.2
@
text
@d1 1
a1 1
# $Id: version,v 1.29.134.18 2007/11/19 15:25:23 each Exp $
d8 3
a10 3
PATCHVER=2
RELEASETYPE=
RELEASEVER=
@


1.1.1.2.2.1
log
@MFC: BIND 9 and related bits.

Approved by:	re
@
text
@@


1.1.1.2.2.2
log
@MFC BIND 9.3.1 and related bmake updates

Approved by:	re (kensmith)
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.17 2005/03/03 04:51:08 marka Exp $
d8 1
a8 1
PATCHVER=1
@


1.1.1.2.2.3
log
@MFC import of BIND 9.3.2
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.21 2005/12/14 00:43:14 marka Exp $
d8 1
a8 1
PATCHVER=2
@


1.1.1.2.2.4
log
@MFC remaining changes between BIND 9.3.2 and 9.3.2-P1.  The
"functional" changes were part of the FreeBSD-SA-06:20.bind commit.

Requested by:	dougb
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.21.4.1 2006/08/17 07:12:31 marka Exp $
d9 2
a10 2
RELEASETYPE=-P
RELEASEVER=1
@


1.1.1.2.2.5
log
@MFC the upgrade to BIND 9.3.2-P2. This is mostly a noop in the base,
since if you're compiling the base with this upgraded, you've already
got your openssl upgraded, but it's a good idea to include this for
completeness sake.
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.21.4.2 2006/10/04 07:00:13 marka Exp $
d10 1
a10 1
RELEASEVER=2
@


1.1.1.2.2.6
log
@MFC upgrade to version 9.3.3
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.26 2006/11/28 00:52:38 marka Exp $
d8 3
a10 3
PATCHVER=3
RELEASETYPE=
RELEASEVER=
@


1.1.1.2.2.7
log
@MFC the upgrade to BIND 9.3.4
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.26.4.1 2007/01/11 05:06:25 marka Exp $
d8 1
a8 1
PATCHVER=4
@


1.1.1.2.2.8
log
@Update to 9.3.4-P1, which fixes the following:

The DNS query id generation is vulnerable to cryptographic
analysis which provides a 1 in 8 chance of guessing the next
query id for 50% of the query ids. This can be used to perform
cache poisoning by an attacker.

This bug only affects outgoing queries, generated by BIND 9 to
answer questions as a resolver, or when it is looking up data
for internal uses, such as when sending NOTIFYs to slave name
servers.

All users are encouraged to upgrade.

See also:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2926
@
text
@d1 1
a1 1
# $Id: version,v 1.26.2.17.2.26.4.2 2007/06/27 02:07:20 marka Exp $
d9 2
a10 2
RELEASETYPE=-P
RELEASEVER=1
@


