Debian Security Advisory DSA 2208-2 (bind9)

Summary
The remote host is missing an update to bind9 announced via advisory DSA 2208-2.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202208-2
Insight
The BIND, a DNS server, contains a defect related to the processing of new DNSSEC DS records by the caching resolver, which may lead to name resolution failures in the delegated zone. If DNSSEC validation is enabled, this issue can make domains ending in .COM unavailable when the DS record for .COM is added to the DNS root zone on March 31st, 2011. An unpatched server which is affected by this issue can be restarted, thus re-enabling resolution of .COM domains. Configurations not using DNSSEC validations are not affected by this usse. For the oldstable distribution (lenny), this problem has been fixed in version 1:9.6.ESV.R4+dfsg-0+lenny1. We recommend that you upgrade your bind9 packages.