[32:9.8.2-0.68.rc1.0.3.8]- Backport fix for CVE-2018-5741 [Orabug: 33496185][32:9.8.2-0.68.rc1.0.2.8]- Backport possible assertion failure on DNAME processing (CVE-2021-25215)[32:9.8.2-0.68.rc1.0.1.8]- Backport the fix for buffer overflow (CVE-2020-8625) (Orabug: 32588749)[32:9.8.2-0.68.rc1.8]- Fix tsig-request verify (CVE-2020-8622)[32:9.8.2-0.68.rc1.7]- Correct tests covering CVE-2020-8617[32:9.8.2-0.68.rc1.6]- Add additional fix to limit recursions[32:9.8.2-0.68.rc1.5]- Add CVE tests to codebase[32:9.8.2-0.68.rc1.4]- Limit number of queries triggered by a request (CVE-2020-8616)- Fix invalid tsig request (CVE-2020-8617)[32:9.8.2-0.68.rc1.3]- Use only selected documentation files[32:9.8.2-0.68.rc1.2]- Fix CVE-2018-5743[32:9.8.2-0.68.rc1.1]- Fix CVE-2018-5740[32:9.8.2-0.68.rc1]- Fix CVE-2017-3145[32:9.8.2-0.67.rc1]- Change EDNS flags only after successful query (#1416035)- Fix crash in ldap driver at bind-sdb stop (#1426626)[32:9.8.2-0.66.rc1]- Fix CVE-2017-3142 and CVE-2017-3143[32:9.8.2-0.65.rc1]- Update root servers and trust anchors[32:9.8.2-0.64.rc1]- Fix DNSKEY that encountered a CNAME (#1447872, ISC change 3391)[32:9.8.2-0.63.rc1]- Fix CVE-2017-3136 (ISC change 4575)- Fix CVE-2017-3137 (ISC change 4578)[32:9.8.2-0.62.rc1]- Fix and test caching CNAME before DNAME (ISC change 4558)[32:9.8.2-0.61.rc1]- Fix CVE-2016-9147 (ISC change 4510)- Fix regression introduced by CVE-2016-8864 (ISC change 4530)[32:9.8.2-0.60.rc1]- Restore SELinux contexts before named restart[32:9.8.2-0.59.rc1]- Use /lib or /lib64 only if directory in chroot already exists- Tighten NSS library pattern, escape chroot mount path[32:9.8.2-0.58.rc1]- Fix CVE-2016-8864[32:9.8.2-0.57.rc1]- Do not change lib permissions in chroot (#1321239)- Support WKS records in chroot (#1297562)[32:9.8.2-0.56.rc1]- Do not include patch backup in docs (fixes #1325081 patch)[32:9.8.2-0.55.rc1]- Backported relevant parts of [RT #39567] (#1259923)[32:9.8.2-0.54.rc1]- Increase ISC_SOCKET_MAXEVENTS to 2048 (#1326283)[32:9.8.2-0.53.rc1]- Fix multiple realms in nsupdate script like upstream (#1313286)[32:9.8.2-0.52.rc1]- Fix multiple realm in nsupdate script (#1313286)[32:9.8.2-0.51.rc1]- Use resolver-query-timeout high enough to recover all forwarders (#1325081)[32:9.8.2-0.50.rc1]- Fix CVE-2016-2848[32:9.8.2-0.49.rc1]- Fix infinite loop in start_lookup (#1306504)[32:9.8.2-0.48.rc1]- Fix CVE-2016-2776[32:9.8.2-0.47.rc1]- Fix CVE-2016-1285 and CVE-2016-1286[32:9.8.2-0.46.rc1]- Fix CVE-2015-8704[32:9.8.2-0.45.rc1]- Updated hints file to the latest version (#1267991)[32:9.8.2-0.44.rc1]- Fix CVE-2015-8000[32:9.8.2-0.43.rc1]- Fix excessive queries caused by DS chasing with stub zones when DNSSEC is not used (#1227189)- Added the fixed tarball with configuration to Sources (Related: #1223359)[32:9.8.2-0.42.rc1]- Don't use ISC's DLV by default (#1223359)[32:9.8.2-0.41.rc1]- Added support for CAA records (#1252611)[32:9.8.2-0.40.rc1]- Fix CVE-2015-5722[32:9.8.2-0.39.rc1]- Fix CVE-2015-5477[32:9.8.2-0.38.rc1]- Fix CVE-2015-4620[32:9.8.2-0.37.rc1]- Resolves: 1215687 - DNS resolution failure in high load environment with SERVFAIL and 'out of memory/success' in the log[32:9.8.2-0.36.rc1]- Fix CVE-2015-1349[32:9.8.2-0.35.rc1]- Enable RPZ-NSIP and RPZ-NSDNAME during compilation (#1176476)[32:9.8.2-0.34.rc1]- Fix race condition when using isc__begin_beginexclusive (#1175321)[32:9.8.2-0.33.rc1]- Sanitize SDB API to better handle database errors (#1146893)[32:9.8.2-0.32.rc1]- Fix CVE-2014-8500 (#1171974)[32:9.8.2-0.31.rc1]- Fix RRL slip behavior when set to 1 (#1112356)- Fix issue causing bind to hang after reload if using DYNDB (#1142152)[32:9.8.2-0.30.rc1]- Use /dev/urandom when generating rndc.key file (#951255)[32:9.8.2-0.29.rc1]- Remove bogus file from /usr/share/doc, introduced by fix for bug #1092035[32:9.8.2-0.28.rc1]- Add support for TLSA resource records (#956685)- Increase defaults for lwresd workers and make workers and client objects number configurable (#1092035)[32:9.8.2-0.27.rc1]- Fix segmentation fault in nsupdate when -r option is used (#1064045)- Fix race condition on send buffer in host tool when sending UDP query (#1008827)- Allow authentication using TSIG in allow-notify configuration statement (#1044545)- Fix SELinux context of /var/named/chroot/etc/localtime (#902431)- Include updated file with root server addresses (#917356)- Don't generate rndc.key if there is rndc.conf on start-up (#997743)- Fix dig man page regarding how to disable IDN (#1023045)- Handle ICMP Destination unreachable (Protocol unreachable) response (#1066876)[32:9.8.2-0.26.rc1]- Configure BIND with --with-dlopen=yes to support dynamically loadable DLZ drivers (#846065)- Fix initscript to return correct exit value when calling checkconfig/configtest/check/test (#848033)- Don't (un)mount chroot filesystem when running initscript command configtest with running server (#851123)- Fix zone2sqlite tool to accept zones containing '.' or '-' or starting with a digit (#919414)- Fix initscript not to mount chroot filesystem is named is already running (#948743)- Fix initscript to check if the PID in PID-file is really s PID of running named server (#980632)- Correct the installed documentation ownership (#1051283)[32:9.8.2-0.25.rc1]- configure with --enable-filter-aaaa to enable use of filter-aaaa-on-v4 option (#1025008)- Fix race condition when destroying a resolver fetch object (#993612)- Fix the RRL functionality to include referrals-per-second and nodata-per-second options (#1036700)- Fix segfault on SERVFAIL to NXDOMAIN failover (#919545)[32:9.8.2-0.24.rc1]- Fix CVE-2014-0591[32:9.8.2-0.23.rc1]- Fix gssapictx memory leak (#911167)[32:9.8.2-0.22.rc1]- fix CVE-2013-4854[32:9.8.2-0.21.rc1]- fix CVE-2013-2266- ship dns/rrl.h in -devel subpkg[32:9.8.2-0.20.rc1]- remove one bogus file from /usr/share/doc, introduced by RRL patch[32:9.8.2-0.19.rc1]- fix CVE-2012-5689[32:9.8.2-0.18.rc1]- add response rate limit patch (#873624)[32:9.8.2-0.17.rc1]- fix CVE-2012-5688[32:9.8.2-0.16.rc1]- initscript: silence spurious ' No such file' error[32:9.8.2-0.15.rc1]- fix CVE-2012-5166[32:9.8.2-0.14.rc1]- allow forward,ers statement in static-stub zones[32:9.8.2-0.13.rc1]- fix CVE-2012-4244[32:9.8.2-0.12.rc1]- fix CVE-2012-3817[32:9.8.2-0.11.rc1]- fix rbtnode.deadlink INSIST failures in rbtdb.c (#837165)[32:9.8.2-0.10.rc1]- fix CVE-2012-1667[32:9.8.2-0.9.rc1]- fix race condition in the resolver module- nslookup: return non-zero exit code when fail to get answer (#816164)[32:9.8.2-0.8.rc1]- initscript: don't umount /var/named when didn't mount it[32:9.8.2-0.7.rc1]- don't fail when logfile cannot be opened (#809084)[32:9.8.2-0.6.rc1]- fix multilib regression in bind-devel (#800053)[32:9.8.2-0.5.rc1]- fix errors reported by Coverity- be more strict when caching NS RRsets (CVE-2012-1033)[32:9.8.2-0.4.rc1]- load dynamic-db plugins later (#795414)[32:9.8.2-0.3.rc1]- decrease severity of various errors related to outside DNS environment (#788870)- fixed various bind-chroot packaging errors (#789886)- use portreserve to reserve rndc control port (#790682)[32:9.8.2-0.2.rc1]- harden dns_zone_setmasterswithkeys() to avoid INSIST failures- build with '--enable-fixed-rrset'- fix potential memory leak in code which processes rndc authentication (#749582)- generate rndc.key during (#768798)- nslookup: improve handling of AA responses with recursion off- removed obsolete bind97-rh714049.patch patch[32:9.8.2-0.1.rc1]- update to 9.8.2rc1- patches merged - bind97-rh754398.patch - bind97-rh700097.patch - bind97-rh734502.patch - bind97-rh746694-1.patch - bind97-rh746694-2.patch - bind97-rh739406-1.patch - bind97-rh739406-2.patch- ship DNSKEY for root zone in default configuration[32:9.7.3-10.P3]- disable atomic ops on ppc* because they caused named to hang/crash[32:9.7.3-9.P3]- fix race condition in resolver.c:validated()- improve error handling in zone.c:zone_refreshkeys() to avoid hang during shutdown[32:9.7.3-8.P3]- fix DOS against recursive servers (#754398)[32:9.7.3-7.P3]- fix memory leak in nsupdate when using SIG(0) keys[32:9.7.3-6.P3]- load/unload dyndb plugins on appropriate places to avoid crashes (#725577)- nsupdate could have failed if server has multiple IPs and the first was unreachable (#714049)- nsupdate returned zero when target zone didn't exist (#700097)- readd configtest target to initscript- print 'the working directory is not writable' as debug message- fix some Coverity warnings[32:9.7.3-5.P3]- fix rare race condition in request.c[32:9.7.3-4.P3]- update to 9.7.3-P3 (CVE-2011-2464)[32:9.7.3-3.P1]- update to 9.7.3-P1 (CVE-2011-1910)[32:9.7.3-2]- don't generate rndc.key during installation[32:9.7.3-1]- update to 9.7.3 (CVE-2011-0414)- patches merged - bind97-gsstsig.patch - bind97-rh664401.patch - bind97-rh623638.patch[32:9.7.2-8.P3]- regenerate fixed nsupdate manual page[32:9.7.2-7.P3]- improve host/dig resolv.conf parser (#rh669163)- improve internal test suite- don't mention that HMAC-MD5 is the only one TSIG algorighm in nsupdate manpage- initscript: sybsys name is always named, not named-sdb[32:9.7.2-6.P3]- named could die on exit after negotiating a GSS-TSIG key (#653486)- fix typo in initscript[32:9.7.2-5.P3]- include root zone DNSKEY in the bind package (#667375)[32:9.7.2-4.P3]- solve conflict between i686 and x86_64 bind-devel packages (#658045)- fix 'service named status' when used with named-sdb- fix 'krb5-self' update-policy rule processing (#664401)- don't check MD5, size and mtime of sysconfig/named[32:9.7.2-3.P3]- use same atomic operations on both ppc and ppc64 (#623638)- add new option DISABLE_ZONE_CHECKING to sysconfig/named (#623673)- document dig exit codes- add Requires: bind-libs to bind subpkgs- remove statement about system-config-bind from named.8 manpage (#660676)[32:9.7.2-2.P3]- host utility now honors 'attempts', 'timeout' and 'debug' options in resolv.conf (#622764)- initscript should kill only the 'correct' named process (#622785)- attempt to reconnect to PostgreSQL during each query if the initial connection failed (#623190)[32:9.7.2-1.P3]- update to 9.7.2-P3 (#623122)- patch bind97-managed-keyfile.patch replaced by bind97-compat-keysdir.patch- patches merged - bind97-rh554316.patch - bind97-rh576906.patch[32:9.7.0-5.P2]- update to 9.7.0-P2[32:9.7.0-4.P1]- fix occassional crash on keytable.c:286 (#554316)- active query might be destroyed in resume_dslookup() which triggered REQUIRE failure (#507429)[32:9.7.0-3.P1]- update to 9.7.0-P1 release[32:9.7.0-2]- improve automatic DNSSEC reconfiguration trigger- initscript now returns 2 in case that action doesn't exist (#523435)- enable/disable chroot when bind-chroot is installed/uninstalled[32:9.7.0-1]- update to production 9.7.0 release[32:9.7.0-0.14.rc2]- obsolete dnssec-conf- automatically update configuration from old dnssec-conf based- improve default configuration; enable DLV by default- remove obsolete triggerpostun from bind-libs subpackage[32:9.7.0-0.13.rc2]- update to 9.7.0rc2 bugfix release (CVE-2010-0097 and CVE-2010-0290)[32:9.7.0-0.12.rc1]- initscript LSB related fixes (#523435)- revert the 'DEBUG' feature (#510283), it causes too many problems (#545128)[32:9.7.0-0.11.rc1]- disable PKCS11 support. PKCS11 support in openssl is not available in RHEL6[32:9.7.0-0.10.rc1]- update to 9.7.0rc1- bind97-headers.patch merged- update default configuration[32:9.7.0-0.9.b3]- update to 9.7.0b3[32:9.7.0-0.8.b2]- install isc/namespace.h header[32:9.7.0-0.7.b2]- update to 9.7.0b2[32:9.7.0-0.6.b1]- update to 9.7.0b1- add bind-pkcs11 subpackage to support PKCS11 compatible keystores for DNSSEC keys[32:9.7.0-0.5.a3]- don't package named-bootconf utility, it is very outdated and unneeded[32:9.7.0-0.4.a3]- determine file size via instead of 32_details32_list32_list_to_copy32_list_to_copy_details32_list_to_copy_details.out32_list_to_copy_details.out_132_list_to_remove_and_ln64_details64_list64_list_to_copy64_list_to_copy_details64_list_to_copy_details.out64_list_to_copy_details.out_164_list_to_remove_and_ln6.667_32_list67_32_list_167_64_list67_64_list_167_src_list67_src_list_1bakbaselistbaselist.outctllist.ELBA-2020-5554-6ctllist.ELSA-2022-9117-6ctllist.RHBA-2020-3543-6ctllist.RHSA-2019-3756-6i386_rpmsknext.ctllist.ELSA-2015-3055-6pendingsav.ctllist.RHBA-2017-3213-6asrc_32_list_to_copy_detailssrc_32_list_to_copy_details.outsrc_32_list_to_copy_details.out_1src_64_list_to_copy_detailssrc_64_list_to_copy_details.outsrc_64_list_to_copy_details.out_1src_detailssrc_listsrc_list_to_copysrc_list_to_copy_32src_list_to_copy_64src_list_to_remove_and_lnsrc_list_to_remove_and_ln_64src_rpmsx86_64_rpms (#523682)[32:9.7.0-0.3.a3]- update to 9.7.0a3[32:9.7.0-0.2.a2]- improve chroot related documentation (#507795)- add NetworkManager dispatcher script to reload named when network interface is activated/deactivated (#490275)- don't set/unset named_write_master_zones SELinux boolean every time in initscript, modify it only when it's actually needed[32:9.7.0-0.1.a2]- update to 9.7.0a2- merged patches - bind-96-db_unregister.patch - bind96-rh507469.patch[32:9.6.1-9.P1]- next attempt to fix the postun trigger (#520385)- remove obsolete bind-9.3.1rc1-fix_libbind_includedir.patch[32:9.6.1-8.P1]- rebuilt with new openssl[32:9.6.1-7.P1]- update the patch for dynamic loading of database backends[32:9.6.1-6.P1]- 9.6.1-P1 release (CVE-2009-0696)- fix postun trigger (#513016, hopefully)[32:9.6.1-5]- Rebuilt for _12_Mass_Rebuild[32:9.6.1-4]- remove useless bind-9.3.3rc2-rndckey.patch[32:9.6.1-3]- fix broken symlinks in bind-libs (#509635)- fix typos in /etc/sysconfig/named (#509650)- add DEBUG option to /etc/sysconfig/named (#510283)[32:9.6.1-2]- improved 'chroot automount' patches (#504596)- host should fail if specified server doesn't respond (#507469)[32:9.6.1-1]- 9.6.1 release- simplify chroot maintenance. Important files and directories are mounted into chroot (see /etc/sysconfig/named for more info, #504596)- fix doc/named.conf.default perms[32:9.6.1-0.4.rc1]- 9.6.1rc1 release[32:9.6.1-0.3.b1]- update the patch for dynamic loading of database backends- create %_libdir/bind directory- copy default named.conf to doc directory, shared with s-c-bind (atkac)[32:9.6.1-0.2.b1]- update the patch for dynamic loading of database backends- fix dns_db_unregister()- useradd now takes '-N' instead of '-n' (atkac, #495726)- print nicer error msg when zone file is actually a directory (atkac, #490837)[32:9.6.1-0.1.b1]- 9.6.1b1 release- patches merged - bind-96-isc_header.patch - bind-95-rh469440.patch - bind-96-realloc.patch - bind9-fedora-0001.diff- use -version-number instead of -version-info libtool param[32:9.6.0-11.1.P1]- logrotate configuration file now points to /var/named/data/ by default (#489986)[32:9.6.0-11.P1]- fall back to insecure mode when no supported DNSSEC algorithm is found instead of SERVFAIL- don't fall back to non-EDNS0 queries when DO bit is set[32:9.6.0-10.P1]- enable DNSSEC only if it is enabled in sysconfig/dnssec[32:9.6.0-9.P1]- add DNSSEC support to initscript, enabled it per default- add requires dnssec-conf[32:9.6.0-8.P1]- fire away libbind, it is now separate package[32:9.6.0-7.P1]- fixed some read buffer overflows (upstream)[32:9.6.0-6.P1]- Rebuilt for _11_Mass_Rebuild[32:9.6.0-5.P1]- update the patch for dynamic loading of database backends- include iterated_hash.h[32:9.6.0-4.P1]- rebuild for dependencies[32:9.6.0-3.P1]- rebuild against new openssl[32:9.6.0-2.P1]- 9.6.0-P1 release (CVE-2009-0025)[32:9.6.0-1]- Happy new year- 9.6.0 release[32:9.6.0-0.7.rc2]- 9.6.0rc2 release- bind-96-rh475120.patch merged[32:9.6.0-0.6.rc1]- add patch for dynamic loading of database backends[32:9.6.0-0.5.1.rc1]- allow to reuse address for non-random query-source ports (#475120)[32:9.6.0-0.5.rc1]- 9.6.0rc1 release- patches merged - bind-9.2.0rc3-varrun.patch - bind-95-sdlz-include.patch - bind-96-libxml2.patch- fixed rare use-after-free problem in host utility (#452060)- enabled chase of DNSSEC signature chains in dig[32:9.6.0-0.4.1.b1]- improved sample config file (#473586)[32:9.6.0-0.4.b1]- reverted previous change, koji doesn't like it[32:9.6.0-0.3.b1]- build bind-chroot as noarch[32:9.6.0-0.2.1.b1]- updates due libtool 2.2.6- don't pass -DLDAP_DEPRECATED to cpp, handle it directly in sources[32:9.6.0-0.2.b1]- make statistics http server working, patch backported from 9.6 HEAD[32:9.6.0-0.1.b1]- 9.6.0b1 release- don't build ODBC and Berkeley DB DLZ drivers- end of bind-chroot-admin script, copy config files to chroot manually- /proc doesn't have to be mounted to chroot- temporary use libbind from 9.5 series, noone has been released for 9.6 yet[32:9.5.1-0.8.4.b2]- dig/host: use only IPv4 addresses when -4 option is specified (#469440)[32:9.5.1-0.8.2.b2]- removed unneeded bind-9.4.1-ldap-api.patch[32:9.5.1-0.8.1.b2]- ship dns/s,dlz.h and isc/radix.h in bind-devel[32:9.5.1-0.8.b2]- removed bind-9.4.0-dnssec-directory.patch, it is wrong[32:9.5.1-0.7.b2]- 9.5.1b2 release- patches merged - bind95-rh454783.patch - bind-9.5-edns.patch - bind95-rh450995.patch - bind95-rh457175.patch[32:9.5.1-0.6.b1]- IDN output strings didn't honour locale settings (#461409)[32:9.5.1-0.5.b1]- disable transfer stats on DLZ zones (#454783)[32:9.5.1-0.4.b1]- add forgotten patch for #457175- build with -O2[32:9.5.1-0.3.b1]- static libraries are no longer s


