Changelog for
bind-utils-9.3.5-owl11.x86_64.rpm :
* Fri Oct 21 2016 Solar Designer
9.3.5-owl11- Added a patch from bind-9.3.6-25.P1.el5_11.10 for CVE-2016-2848.
* Mon Oct 17 2016 Solar Designer 9.3.5-owl10- Added patches from bind-9.3.6-25.P1.el5_11.9 for CVE-2015-5722 (likelyunneeded since DNSSEC-specific), CVE-2015-8000, CVE-2015-8704, CVE-2016-1285and CVE-2016-1286, CVE-2016-2776.
* Fri Jul 31 2015 Solar Designer 9.3.5-owl9- Reviewed the patches in bind-9.3.6-25.P1.el5_11.3 and added those forCVE-2010-3613, CVE-2011-4313 (probably unneeded here, as per the discussionon oss-security back in 2011), CVE-2012-1667, CVE-2012-4244, CVE-2012-5166,CVE-2015-5477. Some other patches were not added for being DNSSEC-specific,or too invasive (most notably, the one for CVE-2014-8500, which hasn\'t beentested separately from the complex patch for RH bug 572848), or fixing toominor issues (CVE-2012-1033, which isn\'t even included in ISC\'s matrix).
* Mon Jun 30 2014 (GalaxyMaster) 9.3.5-owl8- Replaced the deprecated PreReq tag with Requires(pre,post).- Replaced the deprecated %_initrddir macro with %_initddir.
* Thu Dec 09 2010 Solar Designer 9.3.5-owl7- Disallow zone transfers by default and provide more comments and samples forother settings in options.conf (suggested by galaxyAATT and gremlinAATT).- Added a comment on our \"chroot by default\" into the startup script (suggestedby gremlinAATT).
* Tue Jul 28 2009 Dmitry V. Levin 9.3.5-owl6- Backported upstream fix for a remote DoS bug (CVE-2009-0696).
* Fri Mar 06 2009 Solar Designer 9.3.5-owl5- Dropped the root-delegation-only directive from options.conf, made minorupdates to comments in that file.
* Mon Jan 12 2009 Dmitry V. Levin 9.3.5-owl4- Built without openssl by default, thus disabled DNSSEC support.
* Thu Jan 08 2009 Dmitry V. Levin 9.3.5-owl3- Backported upstream fixes of incorrect checks for malformedDSA signatures (CVE-2008-5077).
* Sun Aug 10 2008 Dmitry V. Levin 9.3.5-owl2- Updated to 9.3.5-P2.- Implemented automatic fdsets expansion to overcome FD_SETSIZE limit.
* Tue Jul 08 2008 Dmitry V. Levin 9.3.5-owl1- Updated to 9.3.5-P1. This release additionally randomizes UDP queryports to improve forgery resilience (VU#800113/CVE-2008-1447).
* Thu Nov 08 2007 Dmitry V. Levin 9.3.4-owl4- Updated L.ROOT-SERVERS.NET address.
* Sun Oct 07 2007 Dmitry V. Levin 9.3.4-owl3- Added recursing-file directive to option.conf file, to make\"rndc recursing\" work in \"control bind-debug enabled\" mode, reportedby galaxyAATTowl.- Changed startup script to use /dev/urandom as a source of randomnessduring rndc key generation.- Replaced \"rndc stop\" with killproc in startup script.
* Mon Jul 30 2007 Dmitry V. Levin 9.3.4-owl2- Updated to 9.3.4-P1. This release fixes a weakness in DNS queryids generator which could be used to perform DNS cache poisoning(CVE-2007-2926).
* Mon Jan 29 2007 Dmitry V. Levin 9.3.4-owl1- Updated to 9.3.4.
* Wed Sep 06 2006 Dmitry V. Levin 9.3.2-owl2- Updated to 9.3.2-P1.
* Tue Jun 06 2006 Dmitry V. Levin 9.3.2-owl1- Updated to 9.3.2.
* Thu Oct 27 2005 (GalaxyMaster) 9.3.1-owl5- Adjusted bind.init to not execute named on system startup by default.
* Fri Oct 21 2005 (GalaxyMaster) 9.3.1-owl4- Removed \'|| :\' from touch in %pre.
* Tue Sep 27 2005 Dmitry V. Levin 9.3.1-owl3- Removed syslog restart code from the %post script.
* Mon Sep 26 2005 Dmitry V. Levin 9.3.1-owl2- Made build of -devel subpackage conditional and disabled it by default.- Fixed /etc/syslog.d/named symlink.- In %post script, restart syslog service instead of reload, to makesyslogd start listening on the additional socket.
* Fri Sep 23 2005 Dmitry V. Levin 9.3.1-owl1- Initial release, based on ALT\'s bind-9.3.1-alt1 package and initialpackaging made by (GalaxyMaster).