Update of the DNS server BIND 9.14.3, 9.11.8, 9.15.1 with the elimination of the DoS vulnerability

Published Corrective updates for stable branches of the DNS server BIND 9.14.3, 9.11.8, and 9.12.4-P2, as well as the experimental branch 9.15.1, which is currently under development. At the same time, it has been announced that further support for branch 9.12 will cease, and no more updates will be released for it.

The updates are notable for the elimination of a vulnerability (CVE-2019-6471), which allows for denial of service (process termination with assertion REQUIRE). The issue is caused by a race condition that occurs when processing a very large number of specially crafted incoming packets that trigger the blocking filter. To exploit the vulnerability, an attacker must send a large number of requests to the victim's resolver, which leads to calls to a malicious DNS server that returns incorrect responses.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster