Unbound DNS serverində kod icrasına yol açan zəiflik

Unbound DNS server kəşf edilib zəiflik (CVE-2019-18934), which can lead to the execution of the attacker's code when receiving specially crafted responses. Systems are vulnerable only if Unbound is built with the ipsec module ("--enable-ipsecmod") and ipsecmod is enabled in the settings. The vulnerability is present starting from version 1.6.4 and has been fixed in release Unbound 1.9.5.

The vulnerability is caused by the passing of unescaped characters when invoking the shell command ipsecmod-hook, in the case of receiving a query for a domain that has A/AAAA records and an IPSECKEY. Code injection is performed by providing a specially crafted domain name in the qname and gateway fields, which are linked to the IPSECKEY record.

Mənbə: opennet.ru

DDoS qoruması olan saytlara etibarlı hosting satın alın, VPS VDS serverlər 🔥 DDoS qoruması olan saytlara etibarlı hosting satın alın, VPS VDS serverlər | ProHoster