Update for the BIND DNS server 9.11.37, 9.16.27, and 9.18.1 addressing 4 vulnerabilities.

Corrective updates have been released for the stable branches of the BIND DNS server 9.11.37, 9.16.27, and 9.18.1, addressing four vulnerabilities:

  • CVE-2021-25220 — the potential for incorrect NS records to be substituted in the DNS server cache (cache poisoning), which may lead to requests being sent to incorrect DNS servers that provide false information. This issue occurs in resolvers operating in 'forward first' (default) or 'forward only' modes, under the condition that one of the forwarders is compromised (NS records received from a forwarder are cached and may then result in queries being directed to the wrong DNS server during recursive requests).
  • CVE-2022-0396 — denial of service (infinite hanging of connections in CLOSE_WAIT state), triggered by sending specially crafted TCP packets. The problem occurs only when the keep-response-order setting is enabled, which is not used by default, and the keep-response-order option is specified in the ACL.
  • CVE-2022-0635 — the possibility of the named process crashing through the sending of specific queries to server. The issue occurs when using a cache of validated DNSSEC queries (DNSSEC-Validated Cache), which is enabled by default in branch 9.18 (dnssec-validation and synth-from-dnssec settings).
  • CVE-2022-0667 — the possibility of the named process crashing when handling delayed DS queries. This issue occurs only in the BIND 9.18 branch and is caused by an error made while reworking the client code for recursive query processing.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster