Bug#810593: bind9: shouldn't leak .onion queries (RFC7686)

2016-01-11 Thread Robert Edmonds
Adam Borowski wrote: > Hi! > When a client tries to resolve an .onion name, bind will leak such a request > to the outside internet (a forwarder or a root server). This is forbidden > by RFC7686 which demands that both caching and authoritative servers return > NXDOMAIN without looking that up. >

Bug#810593: bind9: shouldn't leak .onion queries (RFC7686)

2016-01-10 Thread Adam Borowski
Source: bind9 Version: 1:9.9.5.dfsg-9 Severity: normal Hi! When a client tries to resolve an .onion name, bind will leak such a request to the outside internet (a forwarder or a root server). This is forbidden by RFC7686 which demands that both caching and authoritative servers return NXDOMAIN wi