Update of the BIND DNS server 9.11.22, 9.16.6, 9.17.4 with the fix of 5 vulnerabilities

Published correction updates for stable branches of the BIND DNS server 9.11.22 and 9.16.6, as well as the experimental branch 9.17.4, currently under development. The new releases address 5 vulnerabilities. The most critical vulnerability (CVE-2020-8620) , rather than taking focus. allows remote denial of service by sending a specific set of packets to the TCP port that BIND accepts connections on. Sending abnormally large AXFR requests to the TCP port can lead to the connecting TCP library libuv passing a size to the server that triggers the assertion check and terminates the process. to the fact that the TCP connection library libuv will pass the size to the server, triggering the assertion check and terminating the process.

Other vulnerabilities:

  • CVE-2020-8621 — an attacker can initiate an assertion check and forcefully terminate the resolver when attempting to minimize QNAME after redirecting the request. This issue only occurs on servers with QNAME minimization enabled, operating in 'forward first' mode.
  • CVE-2020-8622 — an attacker can initiate an assertion check and forcefully terminate a worker process if the attacker’s DNS server returns invalid TSIG-signed responses to the victim's DNS server's request.
  • CVE-2020-8623 — an attacker can initiate an assertion check and forcefully terminate the handler by sending specially crafted zone requests signed with an RSA key. This issue only occurs when the server is built with the '--enable-native-pkcs11' option.
  • CVE-2020-8624 — an attacker with permissions to modify certain fields in DNS zones can gain additional privileges to modify other contents of the DNS zone.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster