BIND DNS server update 9.11.37, 9.16.27 and 9.18.1 addressing 4 vulnerabilities

Published corrective updates for the stable branches of BIND DNS server 9.11.37, 9.16.27 and 9.18.1, which eliminate four vulnerabilities:

  • CVE-2021-25220 — the possibility of injecting incorrect NS records into the DNS server's cache (cache poisoning), which may lead to queries to incorrect DNS servers providing false information. This issue manifests in resolvers operating in 'forward first' (default) or 'forward only' modes, under a condition where one of the forwarders is compromised (NS records obtained from the forwarder settle in the cache and may consequently lead to queries to the wrong DNS server during recursive requests).
  • CVE-2022-0396 — denial of service (infinite hanging of connections in CLOSE_WAIT state), initiated by sending specially crafted TCP packets. The problem arises only when the keep-response-order setting is enabled, which is not used by default, as well as when the keep-response-order option is specified in the ACL.
  • CVE-2022-0635 — the potential for a crash of the named process via the sending of specific queries to serveri. The issue appears when using the validated DNSSEC query cache (DNSSEC-Validated Cache), which is enabled by default in branch 9.18 (dnssec-validation and synth-from-dnssec settings).
  • CVE-2022-0667 — the possibility of crashing the named process while handling delayed DS queries. The problem occurs only in branch BIND 9.18 and is caused by a bug introduced during the reworking of client code for recursive query processing.

Allikas: opennet.ru

Osta usaldusvÀÀrne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid đŸ”„ Osta usaldusvÀÀrne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid | ProHoster