I've been getting people sending me announcements and asking me if our servers are secure or at risk! The bottom line is we've known about the security issues of running both authoritative and caching servers on the same server using Bind for years! We separated ours in July of 2004 for both speed and security.
This exploit was announced by CERT on July 8th 2008