Imelite ihe nkesa BIND DNS iji kpochapụ adịghị ike na mmejuputa DNS-over-HTTPS

Ebipụtala mmelite mmezi na ngalaba kwụsiri ike nke sava DNS 9.16.28 na 9.18.3, yana mwepụta ọhụrụ nke ngalaba nnwale 9.19.1. Na nsụgharị 9.18.3 na 9.19.1, adịghị ike (CVE-2022-1183) na mmejuputa usoro DNS-over-HTTPS, kwadoro kemgbe alaka 9.18. Ọdịmma ahụ na-eme ka usoro aha ya daa ma ọ bụrụ na akwụsịla njikọ TLS na onye na-ahụ maka HTTP n'oge. Okwu a na-emetụta naanị sava na-ejere DNS n'elu arịrịọ HTTPS (DoH). Sava na-anabata ajụjụ DNS n'elu TLS (DoT) na-adịghị eji DoH adịghị emetụta nsogbu a.

Mwepụta 9.18.3 na-agbakwụnyekwa ọtụtụ nkwalite arụ ọrụ. Nkwado agbakwunyere maka ụdị nke abụọ nke mpaghara katalọgụ (“ Mpaghara katalọgụ”), akọwapụtara na ntinye nke ise nke nkọwapụta IETF. Akwụkwọ ndekọ aha mpaghara na-enye usoro ọhụrụ nke idowe sava DNS nke abụọ nke, kama ịkọwa ndekọ dị iche iche maka mpaghara ọ bụla nke abụọ na sava nke abụọ, a na-ebufe otu mpaghara mpaghara nke abụọ n'etiti sava mbụ na nke abụọ. Ndị ahụ. Site na ịtọlite ​​​​ntụgharị ndekọ aha dịka ịnyefe mpaghara nke ọ bụla, mpaghara ndị e kere na isi ihe nkesa na akara dị ka etinyere na ndekọ ahụ ga-emepụta na-akpaghị aka na ihe nkesa nke abụọ na-enweghị mkpa dezie nhazi faịlụ.

Ụdị ọhụrụ a na-agbakwụnye nkwado maka koodu mperi "Stale Azịza" na "Stale NXDOMAIN Azịza" nke ewepụtara mgbe esitere na cache weghachi azịza ọgbaghara. aha na igwu nwere nkwenye nke asambodo TLS mpụga, nke enwere ike iji mejuputa nyocha siri ike ma ọ bụ nkwado dabere na TLS (RFC 9103).

isi: opennet.ru

Tinye a comment