resolver.c:4858: fatal error

2013-06-04 Thread Stas Pirogov
Hello, since upgrading our binds to 9.9.3 (from 9.9.2-P2) I've got following crash couple of times in last 3 days: 04-Jun-2013 08:33:09.531 general: critical: resolver.c:4858: fatal error: 04-Jun-2013 08:33:09.531 general: critical: RUNTIME_CHECK(tresult == 0) failed 04-Jun-2013 08:33:09.531 gen

RE: does zone trump forward?

2013-06-04 Thread Alan Shackelford
I wasn't trying to start a fight. Perhaps I didn't provide enough detail. We have 2843 authoritative zones. We run a split brain DNS. The new hospitals and other entities need to see our internal zone view once they have "joined". So I have them forward queries during the early stages of the mer

Re: does zone trump forward?

2013-06-04 Thread Matus UHLAR - fantomas
On 04.06.13 13:42, Alan Shackelford wrote: We have 2843 authoritative zones. We run a split brain DNS. The new hospitals and other entities need to see our internal zone view once they have "joined". So I have them forward queries during the early stages of the merger, until I can get control of

Re: does zone trump forward?

2013-06-04 Thread Kevin Darcy
Please excuse my prickliness, but I've spent almost a whole career dealing with the wreckage of inappropriate forwarding... - Kevin On 6/4/2013 9:42 AM, Alan Shackelford wrote: I wasn't trying to start a fight. Perhaps I didn't provide enough detail. We have 2843 authorit

CVE-2013-3919 [was Re: resolver.c:4858: fatal error]

2013-06-04 Thread Michael McNally
On 6/4/13 1:06 AM, Stas Pirogov wrote: Hello, since upgrading our binds to 9.9.3 (from 9.9.2-P2) I've got following crash couple of times in last 3 days: 04-Jun-2013 08:33:09.531 general: critical: resolver.c:4858: fatal error: 04-Jun-2013 08:33:09.531 general: critical: RUNTIME_CHECK(tresult =

CVE-2013-3919: A recursive resolver can be crashed by a query for a malformed zone

2013-06-04 Thread Michael McNally
This is a reminder to all readers of the bind-users list that ISC has recently (within the past six months) changed its policy on list announcements. Prior to the change this list used to routinely receive duplicate copies of official BIND announcements posted in bind-announce. Since the change,

Re: CVE-2013-3919 [was Re: resolver.c:4858: fatal error]

2013-06-04 Thread Warren Kumari
Can you / ISC confirm that authoritative only (recursion no) are not affected? The implication from the advisory is that they are not, but explicit confirmation would be nice... Warren Kumari -- Please excuse typing, etc -- This was sent from a device with a tiny keyboard. On Jun 4, 2013,

Re: CVE-2013-3919 [was Re: resolver.c:4858: fatal error]

2013-06-04 Thread Mark Andrews
In message <3fc34ff5-e0be-4a64-a2fb-dce6025e4...@kumari.net>, Warren Kumari wri tes: > Can you / ISC confirm that authoritative only (recursion no) are not affected > ? > > The implication from the advisory is that they are not, but explicit confirma > tion would be nice... > > Warren Kumari >

RHEL, Centos, Fedora rpm 9.9.3-P1

2013-06-04 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEARECAAYFAlGuo5cACgkQL6j7milTFsHa8ACfcAjO2DvF3hDbNjRA240YDl/i J1kAnAokHUhy/n3hBv0TF