bind9 (1:9.3.4-2etch6) oldstable-security; urgency=high * Fix cache poisoning through additional section for secure delegations (CVE-2009-4022). Based on a patch from Red Hat for their 9.3.6 version. -- Florian Weimer Sun, 20 Dec 2009 17:35:02 +0100 bind9 (1:9.3.4-2etch5) oldstable-security; urgency=low [Internet Software Consortium, Inc] * A specially crafted update packet will cause named to exit. CVE-2009-0696, CERT VU#725188. Closes: #538975 -- LaMont Jones Tue, 28 Jul 2009 23:35:53 -0600 bind9 (1:9.3.4-2etch4) stable-security; urgency=high * Fix check of DSA_do_verify return value. -- Florian Weimer Tue, 06 Jan 2009 19:12:14 +0100 bind9 (1:9.3.4-2etch3) stable-security; urgency=high * Randomize UDP query source ports to improve forgery resilience. (CVE-2008-1447) -- LaMont Jones Sun, 06 Jul 2008 19:19:53 -0600 bind9 (1:9.3.4-2etch2) stable-proposed-updates; urgency=low [Thomas Antepoth] * unix/socket.c: don't send to a socket with pending_send. Closes: #430065 [LaMont Jones] * document git repositories * db.root: l.root-servers.net changed IP address. Closes: #449148 -- LaMont Jones Mon, 05 Nov 2007 19:48:23 -0700 bind9 (1:9.3.4-2etch1) stable-security; urgency=high * Fix DNS cache poisoning through predictable query IDs. (CVE-2007-2926) -- Moritz Muehlenhoff Tue, 24 Jul 2007 22:09:35 +0000 bind9 (1:9.3.4-2) unstable; urgency=high * Actually really do the merge of 9.3.4. Sigh. Closes: #408925 -- LaMont Jones Mon, 29 Jan 2007 06:09:03 -0700 bind9 (1:9.3.4-1) unstable; urgency=high * New upstream version. Addresses CVE-2007-0493 CVE-2007-0494 -- LaMont Jones Thu, 25 Jan 2007 14:31:09 -0700 bind9 (1:9.3.3-1) unstable; urgency=low * New upstream version -- LaMont Jones Tue, 12 Dec 2006 23:31:51 -0700 bind9 (1:9.3.2-P1.0-1) unstable; urgency=low * Fix README.Debian to point to the URL. Closes: #387437 * Strip rfc's from orig.tar.gz. Closes: #393359 -- LaMont Jones Mon, 16 Oct 2006 06:38:22 -0600 bind9 (1:9.3.2-P1-2) unstable; urgency=low * Fix init script output. Closes: #354192 Thanks to Joey Hess for the patch. * Default install should listen on ipv6 interfaces. Closes: #382438 -- LaMont Jones Sat, 9 Sep 2006 19:01:53 -0600 bind9 (1:9.3.2-P1-1) unstable; urgency=high * New upstream, fixes CVE-2006-4095 and CVE-2006-4096. Closes: #386237, #386245 * Drop gcc-3.4 [powerpc] dependency. Closes: #342957, #372203 * Add -fno-strict-aliasing for type-punned pointer aliasing issues Closes: #386224 * Use getent in postinst instead of chown/chgrp. Closes: #386091, #239665 * Drop redundant update-rc.d calls. Closes: #356914 -- LaMont Jones Wed, 6 Sep 2006 08:07:13 -0600 bind9 (1:9.3.2-2) unstable; urgency=low * correct force-reload. Closes: #333841 * Fix init.d's usage message. Closes: #331090 * resolvconf tweaks. Closes: #252232, #275412 -- LaMont Jones Mon, 16 Jan 2006 15:17:04 -0700 bind9 (1:9.3.2-1) unstable; urgency=low * New upstream * use lsb-base for start/stop messages in init.d. * switch to debhelper 4 -- LaMont Jones Thu, 5 Jan 2006 12:29:28 -0700 bind9 (1:9.3.1-2) unstable; urgency=low * Getting good reports from experimental, uploading to sid. Release team, please consider this package for sarge. Thanks. * correct pidfile name in init.d/lwresd. Closes: #298100 -- LaMont Jones Sat, 19 Mar 2005 17:46:31 -0700 bind9 (1:9.3.1-1) experimental; urgency=low * Build with gcc-3.4 on powerpc, to work around #292958. -- LaMont Jones Sat, 19 Mar 2005 11:40:06 -0700 bind9 (1:9.3.1-0) experimental; urgency=low * New upstream version. -- LaMont Jones Sun, 13 Mar 2005 21:44:57 -0700 bind9 (1:9.3.0+9.3.1beta2-1) experimental; urgency=low * new upstream version -- LaMont Jones Tue, 25 Jan 2005 14:21:51 -0700 bind9 (1:9.3.0-1) experimental; urgency=low * New upstream version -- LaMont Jones Sat, 25 Sep 2004 21:35:46 -0600 bind9 (1:9.2.4-1) unstable; urgency=high * New upstream version. Closes: #269157 and others. * Version debhelper build-dep. Closes: #262720 -- LaMont Jones Thu, 23 Sep 2004 09:11:37 -0600 bind9 (1:9.2.3+9.2.4-rc7-1) unstable; urgency=low * New upstream -- LaMont Jones Wed, 1 Sep 2004 00:04:55 -0600 bind9 (1:9.2.3+9.2.4-rc6-1) unstable; urgency=low * New upstream. * Comment out delegation-only directives in named.conf -- LaMont Jones Mon, 2 Aug 2004 10:00:38 -0600 bind9 (1:9.2.3+9.2.4-rc5-1) unstable; urgency=low * New upstream release candidate -- LaMont Jones Thu, 17 Jun 2004 19:50:37 -0600 bind9 (1:9.2.3+9.2.4-rc2-1) unstable; urgency=low * New upstream release candidate * Remove shared library symlinks in clean. Closes: #243109 * Deal with capset being a module. Closes: #245043, #240874, #241605 * deliver /var/run/bind/run in lwresd as well. Closes: #186569 -- LaMont Jones Thu, 22 Apr 2004 12:20:05 -0600 bind9 (1:9.2.3-3) unstable; urgency=low * new IP for b.root-servers.net. Closes: #234278 * Fix RC linkages to match bind8. Closes: #218007 -- LaMont Jones Mon, 1 Mar 2004 15:00:44 -0700 bind9 (1:9.2.3-2) unstable; urgency=low * Rebuild autoconf files for mips. Closes: #221419 -- LaMont Jones Tue, 18 Nov 2003 06:33:34 -0700 bind9 (1:9.2.3-1) unstable; urgency=low * New upstream. * cleanup zones.rfc1918/db.empty stuff. * Fix Makefiles to work even if the build environment is unclean. Closes: #211503 * Add comments about root-delegation-only to named.conf. Closes: #212243 * Add resolvconf support. Closes: #199255 * more SO_BSDCOMPAT hacks for linux. Closes: #220735, #214460 -- LaMont Jones Mon, 17 Nov 2003 21:30:33 -0700 bind9 (1:9.2.2+9.2.3rc4-1) unstable; urgency=low * Yet another new upstream release. -- LaMont Jones Mon, 22 Sep 2003 09:39:50 -0600 bind9 (1:9.2.2+9.2.3rc3-1) unstable; urgency=low * New upstream. Closes: #211752. #211503. #211496, #211520 -- LaMont Jones Sat, 20 Sep 2003 12:22:59 -0600 bind9 (1:9.2.2+9.2.3rc2-4) unstable; urgency=low * Really fix versioned depends. Closes: #211590 -- LaMont Jones Thu, 18 Sep 2003 17:29:47 -0600 bind9 (1:9.2.2+9.2.3rc2-3) unstable; urgency=low * Version depends for all the libraries. sigh. Closes: #211412,#210293 -- LaMont Jones Wed, 17 Sep 2003 10:56:36 -0600 bind9 (1:9.2.2+9.2.3rc2-2) unstable; urgency=low * Need a versioned depend. sigh. -- LaMont Jones Wed, 17 Sep 2003 10:25:35 -0600 bind9 (1:9.2.2+9.2.3rc2-1) unstable; urgency=low * New upstream release. Closes: #211373 * Remove RFC's from package, per policy. * Make com and net zones delegation-only by default. -- LaMont Jones Wed, 17 Sep 2003 07:15:37 -0600 bind9 (1:9.2.2+9.2.3rc1-3) unstable; urgency=low * A bit more cleanup of descriptions. * fix package sections * Fix b0rkage with dependencies. -- LaMont Jones Sun, 14 Sep 2003 09:05:10 -0600 bind9 (1:9.2.2+9.2.3rc1-2) unstable; urgency=low * Explicitly link libraries. Closes: #210653 * Fix descriptions. Closes: #209563, #209853, #210063 -- LaMont Jones Sat, 13 Sep 2003 19:29:05 -0600 bind9 (1:9.2.2+9.2.3rc1-1) unstable; urgency=low * New upstream release candidate. * Quit using SO_BSDCOMPAT (why is it still in the header files??) so that the kernel will shut up about it's advertised, obsolete option. Closes: #201293, #204282, #205590 -- LaMont Jones Thu, 28 Aug 2003 14:44:28 -0600 bind9 (1:9.2.2-2) unstable; urgency=low * Fix libtool.m4. Closes: #183791 * move lib packages into Section: libs. Closes: #184788 * make sure it's libssl0.9.7. Closes: #182363 * Add /etc/default/lwresd. Closes: #169727 * Add fakeroot dir to dh_shlibdeps. Closes: #169622 * Fix rndc manpage. Closes: #179353 * Deliver /usr/bin/isc-config.sh (in libbind-dev). Closes: #178186 -- LaMont Jones Sat, 15 Mar 2003 16:34:15 -0700 bind9 (1:9.2.2-1) unstable; urgency=low * New upstream version * Document /etc/default/bind9 in init.d script. Closes: #170267 -- LaMont Jones Tue, 4 Mar 2003 22:43:58 -0700 bind9 (1:9.2.1-7) unstable; urgency=low * One more overrides disparity. * Fix bashism in postinst. Closes: #169531 -- LaMont Jones Sun, 17 Nov 2002 19:22:58 -0700 bind9 (1:9.2.1-6) unstable; urgency=low * The "I give up for now" release. * Only convert to running as bind if named.conf hasn't been modified. * Closes: #163552, #164352 * Fix overrides * Cleanup README.Debian wrt non-root-by-default. * Make sure that /var/run/bind/run exists in init.d script. Closes: #168912 * New IP for j.root-servers.net. Closes: #167818 * Check for 2.2.18 kernel in preinst. Closes: #164349 * Move local options to /etc/default/bind9. Closes: #169132, #163073 * Cleanup old bugs (fixed in -5, really). Closes: #165864 * Add /etc/bind/named.conf.local, included from named.conf. Closes: #129576 * Do options definitions in /etc/bind/named.conf.options, makes life easier in the face of named.conf changes from upstream. * Add missing Depends: adduser -- LaMont Jones Sat, 16 Nov 2002 17:05:45 -0700 bind9 (1:9.2.1-5) unstable; urgency=low * Run named a non-privileged user by default. Closes: #149059 -- LaMont Jones Thu, 12 Sep 2002 16:57:37 -0600 bind9 (1:9.2.1-4) unstable; urgency=low * swap maintainer/uploader status so LaMont is primary and Bdale is backup * Deal with bind/bind9 collisions better. Closes: #149580 * Fix some documentation. Closes: #151579 -- LaMont Jones Wed, 4 Sep 2002 23:25:33 -0600 bind9 (1:9.2.1-3) unstable; urgency=high * fold in lib/bind/resolv from 8.3.3 to resolve buffer overlow issue in resolver library, closes: #151342, #151431 -- Bdale Garbee Mon, 1 Jul 2002 00:16:31 -0600 bind9 (1:9.2.1-1.woody.1) testing-security woody-proposed-updates; urgency=high * backport to woody (simple rebuild) since 9.2.1 resolves a security issue -- Bdale Garbee Tue, 4 Jun 2002 10:30:57 -0600 bind9 (1:9.2.1-2) unstable; urgency=low * don't include nslint man page, closes: #148695 * fix typo in rndc.8, closes: #139602 * add a section to README.Debian explaining the rndc key mode that has been our default since 9.2.0-2, closes: #129849 * fix paths for named.conf in named.8 to reflect our default, closes: #143443 * upstream fixed the nsupdate man page at some point, closes: #121108 -- Bdale Garbee Mon, 3 Jun 2002 15:44:37 -0600 bind9 (1:9.2.1-1) unstable; urgency=medium * new upstream version * have bind9-host provide host, closes: #140174 * move bind9-host to priority standard since dnsutils depends on it or host, and we prefer bind9-host over host. * move libdns5 and libisc4 to priority standard since dnsutils depends on them and is priority standard -- Bdale Garbee Thu, 30 May 2002 10:38:39 -0600 bind9 (1:9.2.0-6) unstable; urgency=low * move to US main! Yippee! Closes: #123969 * add info to README.Debian about 2.5 kernels vs --disable-linux-caps -- Bdale Garbee Sat, 23 Mar 2002 00:18:05 -0700 bind9 (1:9.2.0-5) unstable; urgency=medium * clean up various issues in the rules file * make bind9-host conflict/replace old dnsutils as host does, otherwise we can have problems upgrading from potato to woody, closes: #136686 * use /dev/urandom for rndc-confgen in postinst, it should be good enough for this purpose, and will keep the postinst from blocking arbitrarily. closes: #130372 * add fresh pointers to chroot howto to README.Debian, closes: #135774 -- Bdale Garbee Sun, 3 Mar 2002 16:47:12 -0700 bind9 (1:9.2.0-4) unstable; urgency=low * bind9-host needs to conflict with host, closes: #127395 -- Bdale Garbee Tue, 1 Jan 2002 20:12:14 -0700 bind9 (1:9.2.0-3) unstable; urgency=low * force removal of old diverted files, closes: #126236 * change priority of liblwres1 from optional to standard per ftp admins * add a bind9-host package so that the 'host' provided with the BIND 9.X source tree can be an alternative to the aging NIKHEF version packaged separately. Update dnsutils dependencies to depend on one of the two, with preference to this one since it has fewer bugs (but fewer features, too). -- Bdale Garbee Sun, 23 Dec 2001 00:59:15 -0700 bind9 (1:9.2.0-2) unstable; urgency=medium * change rc.d links to ensure daemon starts before and stops after other daemons that may fail if name service is not working (bug was filed against 8.X bind packages, but is just as relevant here!) * use rndc for daemon shutdown instead of start-stop-daemon, closes: #111935 * add a postinst to dnsutils to remove any lingering diversions from old dnsutils packages, closes: #122227 * not much point in delivering zone2ldap.1 since we aren't delivering zone2ldap right now (though we might someday?), closes: #124058 * be more verbose with shared library descriptions, closes: #123426, #123428 * 9.2.0 added a new rndc.key file that both named and rndc will read to obtain a shared key, and rndc-confgen will easily create this file with a unique-per-system key. Modify named.conf and remove rndc.conf to take advantage of this mechanism and stop delivering a pre-determined static key to all Debian systems (which has been a mild security risk). Create the key in postinst if the key file doesn't already exist, and remove the file in postrm if purging. Closes: #86718, #87208 -- Bdale Garbee Fri, 21 Dec 2001 04:04:30 -0700 bind9 (1:9.2.0-1) unstable; urgency=low * new upstream version, closes: #108243, #112266, #114250, #119506, #120657 * /etc/bind/rndc.conf is now a conffile * minor hacks to the README.Debian since the chroot instructions it points to are 8.X specific, part of addressing bug 111868. * libomapi is gone, replaced by libisccc and libisccfg * a few lintian-motivated cosmetic cleanups * lose task-dns-server meta package, since tasksel doesn't need it now * dig problem not reproducible in this version, closes: #89526 * named-checkconf now uses $sysconfdir, closes: #107835 * no longer deliver man pages for contributed binaries we're not including in dnsutils, closes: #108220 * fix section in nslookup man page, though that's the least of the man page's problems... glitch reported is unreproducible closes: #103630, #120946 * update libbind-dev README.Debian, closes: #121050 -- Bdale Garbee Tue, 27 Nov 2001 01:41:00 -0700 bind9 (1:9.1.3-1) unstable; urgency=low * new upstream version, closes: #96483, #99824, #100647, #101568, #103429 * update config.sub/guess for hppa/ia64 support * small init.d patch from Marco d'Itri to ease adding options on invocation * stop having bind9-doc conflict/replace bind-doc since they don't really conflict and there's no reason to prevent having both installed at the same time, closes: #90994 * the CHANGES file documents fixes since 9.1.1 that probably cured the reported assertion failure. If it turns out that I'm wrong, the bug can be re-opened or a new one filed. I can't see any way to reproduce the bug in a test case here. Closes: #99352 * have libbind-dev depend on the runtime library packages it delivers compile-time symlinks for, closes: #100898, #103855 * fix lwres man pages to source man3/* instead of * so all the page content can actually be found, closes: #85450, #103865 -- Bdale Garbee Mon, 9 Jul 2001 11:30:39 -0600 bind9 (1:9.1.1-1) unstable; urgency=low * new upstream release * update build-depends for libssl-dev * add build-depends on bison, closes: #90150, #90752, #90159 * split up libbind0 since libdns is changing so numbers * downgrade rblcheck from a depends to a suggests, closes: #90783 * bind9 mkdep creates files in the current working directory, closes: #58353 -- Bdale Garbee Wed, 25 Apr 2001 22:53:21 -0600 bind9 (1:9.1.0-3) unstable; urgency=low * merge patch from Zack Weinberg that solves compilation problem, and reduces the memory footprint of applications by making configure.in smarter. Closes: #86776, #86910 * the bind-doc package includes all relevant documentation from the bind9 source tree, including HTML content in /usr/share/doc/bind9-doc/arm, closes: #85718 * default named.conf and rndc.conf to not world-readable. This is an interim step towards addressing the concerns about security raised by bugs 86718 and closes: #86836 A better long-term solution would be for rndc.conf to allow includes, so that both named.conf and rndc.conf could include a key file built on the fly during installation while themselves retaining conffile status. The required functionality has been requested of the bind9 upstream, this will limit vulnerability in the meantime. * add replaces logic to the dnsutils package to avoid complaints about the delivery of nsupdate.8.gz, closes: #86759 * move a couple of man pages back from dnsutils to bind9 that really belong there. sigh. -- Bdale Garbee Thu, 22 Feb 2001 16:39:02 -0700 bind9 (1:9.1.0-2) unstable; urgency=low * merge patch from Luca Filipozzi - thanks! + bind9: ships with a working rndc.conf file, closes: #84572 + bind9: init.d calls rndc rather than ndc on reload, closes: #85481 + bind9: named.conf ships with 'key' and 'control' sections + bind9: correctly creates /var/cache/bind, closes: #85457 + lwresd: lwresd is split off into its own package, closes: #85627 * nsupdate is delivered by the dnsutils package, but the (wrong) man page was accidentally also included in the bind9 package, closes: #85717 * freshen config.sub and config.guess for ia64 and hppa support -- Bdale Garbee Mon, 12 Feb 2001 23:43:55 -0700 bind9 (1:9.1.0-1) unstable; urgency=low * Initial packaging of BIND 9.1.0. Must use epoch so that meta packages retain their sequencing from the bind 8 package version stream. * snarf a couple of man pages from the 8.X tree for now -- Bdale Garbee Thu, 1 Feb 2001 16:30:35 -0700