A bug in BIND 9.16.17 leads to incorrect handling of the W character in DNS queries.

Corrective updates have been released for the stable branch of the BIND DNS server 9.16.18 and the experimental branch 9.17.15 currently in development, addressing a critical bug that appeared in the releases of BIND 9.16.17 and 9.17.14, published last week (the day after these releases, developers warned about the issue and recommended not to install versions 9.16.17 and 9.17.14).

In versions 9.16.17 and 9.17.14, the character 'w' was omitted in the case mapping tables (maptoupper and maptolower), leading to the replacement of the characters 'W' and 'w' in domain names with the sequence '\000' and returning incorrect results when processing masked queries. For example, if a record '*.sub.test.local. 1 A 127.0.0.1' existed in the DNS zone, a query for the name 'UVW.sub.test.local' would return the output where the name returned was 'uv\/000.sub.test.local' instead of 'uvw.sub.test.local'.

Additionally, there were issues with replacing the character 'w' with '\000' during dynamic zone updates if the case of the 'w' character in the query differed from the case in the DNS zone. For example, if there was a record 'WW.example' in the zone and an update was sent for 'foo.ww.example.', it was processed as 'foo.\000\000.example.'. Character replacement issues could also occur during zone transfers from the primary to the secondary DNS server.

The release of update 9.16.18 was delayed due to the discovery of two additional bugs that remained unresolved in versions 9.16.18 and 9.17.15. These bugs cause mutual blocking during initialization and manifest in configurations where the same zones are used in dnssec-policy present in different views. Users with such settings are recommended to roll back to version BIND 9.16.16.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster