2011年5月13日

[installer 2794] BIND 9.4-ESV-R5b1, 9.6-ESV-R5b1, 9.7.4b1

BIND 9.4-ESV-R5b1, 9.6-ESV-R5b1, 9.7.4b1 出ています。

☆ BIND 9.4-ESV-R5b1
https://www.isc.org/software/bind
ftp://ftp.isc.org/isc/bind/9.4-ESV-R5b1/bind-9.4-ESV-R5b1.tar.gz

--- 9.4-ESV-R5b1 released ---

3095. [bug] Handle isolated reserved ports in the port range.
[RT #23957]

3088. [bug] Remove bin/tests/system/logfileconfig/ns1/named.conf
and add setup.sh in order to resolve changing
named.conf issue. [RT #23687]

3071. [bug] has_nsec could be used unintialised in
update.c:next_active. [RT #20256]

3067. [bug] ixfr-from-differences {master|slave}; failed to
select the master/slave zones. [RT #23580]

3065. [bug] RRSIG could have time stamps too far in the future.
[RT #23356]

3064. [bug] powerpc: add sync instructions to the end of atomic
operations. [RT #23469]

3058. [bug] Cause named to terminate at startup or rndc reconfig/
reload to fail, if a log file specified in the conf
file isn't a plain file. [RT #22771]

3051. [bug] NS records obsure DNAME records at the bottom of the
zone if both are present. [RT #23035]

3041. [bug] dnssec-signzone failed to generate new signatures on
ttl changes. [RT #23330]

3040. [bug] Named failed to validate insecure zones where a node
with a CNAME existed between the trust anchor and the
top of the zone. [RT #23338]

3037. [doc] Update COPYRIGHT to contain all the individual
copyright notices that cover various parts.

3014. [bug] Fix the zonechecks system test to match expected
behaviour for 9.4 and to fail on error. [RT #22905]

3009. [bug] clients-per-query code didn't work as expected with
particular query patterns. [RT #22972]

3007. [bug] Named failed to preserve the case of domain names in
rdata which is not compressible when writing master
files. [RT #22863]

2996. [security] Temporarily disable SO_ACCEPTFILTER support.
[RT #22589]


☆ BIND 9.6-ESV-R5b1
https://www.isc.org/software/bind
ftp://ftp.isc.org/isc/bind/9.6-ESV-R5b1/bind-9.6-ESV-R5b1.tar.gz

--- 9.6-ESV-R5b1 released ---

3095. [bug] Handle isolated reserved ports in the port range.
[RT #23957]

3088. [bug] Remove bin/tests/system/logfileconfig/ns1/named.conf
and add setup.sh in order to resolve changing
named.conf issue. [RT #23687]

3083. [bug] NOTIFY messages were not being sent when generating
a NSEC3 chain incrementally. [RT #23702]

3081. [bug] Failure of DNAME substitution did not return
YXDOMAIN. [RT #23591]

3080. [cleanup] Replaced compile time constant by STDTIME_ON_32BITS.
[RT #23587]

3079. [bug] Handle isc_event_allocate failures in t_tasks.
[RT #23572]

3074. [bug] Make the adb cache read through for zone data and
glue learn for zone named is authoritative for.
[RT #22842]

3071. [bug] has_nsec could be used unintialised in
update.c:next_active. [RT #20256]

3069. [cleanup] Silence warnings messages from clang static analysis.
[RT #20256]

3068. [bug] Named failed to build with a OpenSSL without engine
support. [RT #23473]

3067. [bug] ixfr-from-differences {master|slave}; failed to
select the master/slave zones. [RT #23580]

3065. [bug] RRSIG could have time stamps too far in the future.
[RT #23356]

3064. [bug] powerpc: add sync instructions to the end of atomic
operations. [RT #23469]

3063. [contrib] More verbose error reporting from DLZ LDAP. [RT #23402]

3059. [test] Added a regression test for change #3023.

3058. [bug] Cause named to terminate at startup or rndc reconfig/
reload to fail, if a log file specified in the conf
file isn't a plain file. [RT #22771]

3053. [bug] Under a sustained high query load with a finite
max-cache-size, it was possible for cache memory
to be exhausted and not recovered. [RT #23371]

3051. [bug] NS records obsure DNAME records at the bottom of the
zone if both are present. [RT #23035]

3046. [bug] Use RRSIG original TTL to compute validated RRset
and RRSIG TTL. [RT #23332]

3044. [bug] Hold the socket manager lock while freeing the socket.
[RT #23333]

3043. [test] Merged in the NetBSD ATF test framework (currently
version 0.12) for development of future unit tests.
Use configure --with-atf to build ATF internally
or configure --with-atf=prefix to use an external
copy. [RT #23209]

3042. [bug] dig +trace could fail attempting to use IPv6
addresses on systems with only IPv4 connectivity.
[RT #23297]

3041. [bug] dnssec-signzone failed to generate new signatures on
ttl changes. [RT #23330]

3040. [bug] Named failed to validate insecure zones where a node
with a CNAME existed between the trust anchor and the
top of the zone. [RT #23338]

3037. [doc] Update COPYRIGHT to contain all the individual
copyright notices that cover various parts.

3036. [bug] Check built-in zone arguments to see if the zone
is re-usable or not. [RT #21914]

3035. [cleanup] Simplify by using strlcpy. [RT #22521]

3034. [cleanup] nslookup: use strlcpy instead of safecopy. [RT #22521]

3033. [cleanup] Add two INSIST(bucket != DNS_ADB_INVALIDBUCKET).
[RT #22521]

3032. [bug] rdatalist.c: add missing REQUIREs. [RT #22521]

3031. [bug] dns_rdataclass_format() handle a zero sized buffer.
[RT #22521]

3030. [bug] dns_rdatatype_format() handle a zero sized buffer.
[RT #22521]

3029. [bug] isc_netaddr_format() handle a zero sized buffer.
[RT #22521]

3028. [bug] isc_sockaddr_format() handle a zero sized buffer.
[RT #22521]

3027. [bug] Add documented REQUIREs to cfg_obj_asnetprefix() to
catch NULL pointer dereferences before they happen.
[RT #22521]

3026. [bug] lib/isc/httpd.c: check that we have enough space
after calling grow_headerspace() and if not
re-call grow_headerspace() until we do. [RT #22521]

3025. [bug] Fixed a possible deadlock due to zone resigning.
[RT #22964]

3023. [bug] Named could be left in an inconsistent state when
receiving multiple AXFR response messages that were
not all TSIG-signed. [RT #23254]

3019. [test] Test: check apex NSEC3 records after adding DNSKEY
record via UPDATE. [RT #23229]

3018. [bug] Named failed to check for the "none;" acl when deciding
if a zone may need to be re-signed. [RT #23120]

3016. [bug] rndc usage missing '-b'. [RT #22937]

3015. [port] win32: fix IN6_IS_ADDR_LINKLOCAL and
IN6_IS_ADDR_SITELOCAL macros. [RT #22724]

3014. [bug] Fix the zonechecks system test to match expected
behaviour for 9.6 and to fail on error. [RT #22905]

3012. [bug] Remove DNSKEY TTL change pairs before generating
signing records for any remaining DNSKEY changes.
[RT #22590]


☆ BIND 9.7.4b1
https://www.isc.org/software/bind
ftp://ftp.isc.org/isc/bind/9.7.4b1/bind-9.7.4b1.tar.gz

--- 9.7.4b1 released ---

3095. [bug] Handle isolated reserved ports in the port range.
[RT #23957]

3092. [bug] Signatures for records at the zone apex could go
stale due to an incorrect timer setting. [RT #23769]

3091. [bug] Fixed a bug in which zone keys that were published
and then subsequently activated could fail to trigger
automatic signing. [RT #22911]

3088. [bug] Remove bin/tests/system/logfileconfig/ns1/named.conf
and add setup.sh in order to resolve changing
named.conf issue. [RT #23687]

3086. [bug] Running dnssec-settime -f on an old-style key will
now force an update to the new key format even if no
other change has been specified, using "-P now -A now"
as default values. [RT #22474]

3083. [bug] NOTIFY messages were not being sent when generating
a NSEC3 chain incrementally. [RT #23702]

3081. [bug] Failure of DNAME substitution did not return
YXDOMAIN. [RT #23591]

3080. [cleanup] Replaced compile time constant by STDTIME_ON_32BITS.
[RT #23587]

3079. [bug] Handle isc_event_allocate failures in t_tasks.
[RT #23572]

3077. [bug] zone.c:zone_refreshkeys() incorrectly called
dns_zone_attach(), use zone->irefs instead. [RT #23303]

3075. [bug] dns_dnssec_findzonekeys{2} used a inconsistant
timestamp when determining which keys are active.
[RT #23642]

3074. [bug] Make the adb cache read through for zone data and
glue learn for zone named is authoritative for.
[RT #22842]

3073. [bug] managed-keys changes were not properly being recorded.
[RT #20256]

3071. [bug] has_nsec could be used unintialised in
update.c:next_active. [RT #20256]

3070. [bug] dnssec-signzone potential NULL pointer dereference.
[RT #20256]

3069. [cleanup] Silence warnings messages from clang static analysis.
[RT #20256]

3068. [bug] Named failed to build with a OpenSSL without engine
support. [RT #23473]

3067. [bug] ixfr-from-differences {master|slave}; failed to
select the master/slave zones. [RT #23580]

3065. [bug] RRSIG could have time stamps too far in the future.
[RT #23356]

3064. [bug] powerpc: add sync instructions to the end of atomic
operations. [RT #23469]

3063. [contrib] More verbose error reporting from DLZ LDAP. [RT #23402]

3059. [test] Added a regression test for change #3023.

3058. [bug] Cause named to terminate at startup or rndc reconfig/
reload to fail, if a log file specified in the conf
file isn't a plain file. [RT #22771]

3057. [bug] "rndc secroots" would abort after the first error
and so could miss some views. [RT #23488]

3055. [bug] Load only the desired keys in the
"dnssec-lookaside auto" mode. [RT #23372]

3053. [bug] Under a sustained high query load with a finite
max-cache-size, it was possible for cache memory
to be exhausted and not recovered. [RT #23371]

3052. [test] Fixed last autosign test report. [RT #23256]

3051. [bug] NS records obsure DNAME records at the bottom of the
zone if both are present. [RT #23035]

3050. [bug] The autosign system test was timing dependent.
Wait for the initial autosigning to complete
before running the rest of the test. [RT #23035]

3049. [bug] Save and restore the gid when creating creating
named.pid at startup. [RT #23290]

3048. [bug] Fully separate view key mangement. [RT #23419]

3047. [bug] DNSKEY NODATA responses not cached fixed in
validator.c. Tests added to dnssec system test.
[RT #22908]

3046. [bug] Use RRSIG original TTL to compute validated RRset
and RRSIG TTL. [RT #23332]

3044. [bug] Hold the socket manager lock while freeing the socket.
[RT #23333]

3043. [test] Merged in the NetBSD ATF test framework (currently
version 0.12) for development of future unit tests.
Use configure --with-atf to build ATF internally
or configure --with-atf=prefix to use an external
copy. [RT #23209]

3042. [bug] dig +trace could fail attempting to use IPv6
addresses on systems with only IPv4 connectivity.
[RT #23297]

3041. [bug] dnssec-signzone failed to generate new signatures on
ttl changes. [RT #23330]

3040. [bug] Named failed to validate insecure zones where a node
with a CNAME existed between the trust anchor and the
top of the zone. [RT #23338]

3037. [doc] Update COPYRIGHT to contain all the individual
copyright notices that cover various parts.

3036. [bug] Check built-in zone arguments to see if the zone
is re-usable or not. [RT #21914]

3035. [cleanup] Simplify by using strlcpy. [RT #22521]

3034. [cleanup] nslookup: use strlcpy instead of safecopy. [RT #22521]

3033. [cleanup] Add two INSIST(bucket != DNS_ADB_INVALIDBUCKET).
[RT #22521]

3032. [bug] rdatalist.c: add missing REQUIREs. [RT #22521]

3031. [bug] dns_rdataclass_format() handle a zero sized buffer.
[RT #22521]

3030. [bug] dns_rdatatype_format() handle a zero sized buffer.
[RT #22521]

3029. [bug] isc_netaddr_format() handle a zero sized buffer.
[RT #22521]

3028. [bug] isc_sockaddr_format() handle a zero sized buffer.
[RT #22521]

3027. [bug] Add documented REQUIREs to cfg_obj_asnetprefix() to
catch NULL pointer dereferences before they happen.
[RT #22521]

3026. [bug] lib/isc/httpd.c: check that we have enough space
after calling grow_headerspace() and if not
re-call grow_headerspace() until we do. [RT #22521]

3025. [bug] Fixed a possible deadlock due to zone resigning.
[RT #22964]

3023. [bug] Named could be left in an inconsistent state when
receiving multiple AXFR response messages that were
not all TSIG-signed. [RT #23254]

3021. [bug] Change #3010 was incomplete. [RT #22296]

3020. [bug] auto-dnssec failed to correctly update the zone when
changing the DNSKEY RRset. [RT #23232]

3019. [test] Test: check apex NSEC3 records after adding DNSKEY
record via UPDATE. [RT #23229]

----
こがよういちろう


投稿者 xml-rpc : 2011年5月13日 12:53
役に立ちました?:
過去のフィードバック 平均:(0) 総合:(0) 投票回数:(0)
本記事へのTrackback: http://hoop.euqset.org/blog/mt-tb2006.cgi/103796
トラックバック
コメント
コメントする




画像の中に見える文字を入力してください。