Howtoforge posted a guide about patching BIND9 against DNS cache poisoning
>> Guide for Debian Etch
>> Guide for CentOS
Dan Kaminsky earlier this month announced a massive, multi-vendor issue with DNS that could allow attackers to compromise any name server - clients, too. These two articles explain how you can fix a BIND9 nameserver on Debian Etch and Fedora/CentOS so that it is not vulnerable anymore to DNS cache poisoning.
>> Guide for Debian Etch
>> Guide for CentOS