ืขื“ื›ื•ืŸ ืฉืจืช DNS ืฉืœ BIND 9.11.37, 9.16.27 ื•-9.18.1 ืขื 4 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉืชื•ืงื ื•

ืคื•ืจืกืžื• ืขื“ื›ื•ื ื™ื ืžืชืงื™ื ื™ื ืœืขื ืคื™ื ื”ื™ืฆื™ื‘ื™ื ืฉืœ ืฉืจืช BIND DNS 9.11.37, 9.16.27 ื•-9.18.1, ืืฉืจ ืžืชืงื ื™ื ืืจื‘ืข ื ืงื•ื“ื•ืช ืชื•ืจืคื”:

  • CVE-2021-25220 - ืืคืฉืจื•ืช ืœื”ื—ืœื™ืฃ ืจืฉื•ืžื•ืช NS ืฉื’ื•ื™ื•ืช ืœืžื˜ืžื•ืŸ ืฉืจืช ื”-DNS (ื”ืจืขืœืช ืžื˜ืžื•ืŸ), ืžื” ืฉืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœืงืจื™ืื•ืช ืœืฉืจืชื™ DNS ืฉื’ื•ื™ื™ื ื”ืžืกืคืงื™ื ืžื™ื“ืข ืฉืงืจื™. ื”ื‘ืขื™ื” ืžืชื‘ื˜ืืช ื‘ืคื•ืชืจื™ื ื”ืคื•ืขืœื™ื ื‘ืžืฆื‘ "ื”ืขื‘ืจ ืชื—ื™ืœื”" (ื‘ืจื™ืจืช ื”ืžื—ื“ืœ) ืื• "ื”ืขื‘ืจ ื‘ืœื‘ื“", ืื ืื—ื“ ืžื”ืžืฉืœื—ื™ื ื ืคื’ืข (ืจืฉื•ืžื•ืช NS ืฉื”ืชืงื‘ืœื• ืžื”ืžืฉืœื— ืžื’ื™ืขื•ืช ืœืžื˜ืžื•ืŸ ื•ืื– ื™ื›ื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœื’ื™ืฉื” ืœ- ืฉืจืช DNS ืฉื’ื•ื™ ื‘ืขืช ื‘ื™ืฆื•ืข ืฉืื™ืœืชื•ืช ืจืงื•ืจืกื™ื‘ื™ื•ืช).
  • CVE-2022-0396 ื”ื•ื ืžื ื™ืขืช ืฉื™ืจื•ืช (ื—ื™ื‘ื•ืจื™ื ืชืœื•ื™ื™ื ืœืœื ื”ื’ื‘ืœืช ื–ืžืŸ ื‘ืžืฆื‘ CLOSE_WAIT) ื”ืžื•ืคืขืœ ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืžื ื•ืช TCP ื‘ืขืœื•ืช ืžื‘ื ื” ืžื™ื•ื—ื“. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืจืง ื›ืืฉืจ ืžื•ืคืขืœืช ื”ื”ื’ื“ืจื” keep-response-order, ืฉืื™ื ื” ื‘ืฉื™ืžื•ืฉ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื•ื›ืืฉืจ ื”ืืคืฉืจื•ืช keep-response-ord ืžื•ื’ื“ืจืช ื‘-ACL.
  • CVE-2022-0635 - ื”ืชื”ืœื™ืš ื”ื ืงื•ื‘ ื™ื›ื•ืœ ืœืงืจื•ืก ื‘ืขืช ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ืžืกื•ื™ืžื•ืช ืœืฉืจืช. ื”ื‘ืขื™ื” ื‘ืื” ืœื™ื“ื™ ื‘ื™ื˜ื•ื™ ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžื˜ืžื•ืŸ DNSSEC-Validated Cache, ื”ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ืกื ื™ืฃ 9.18 (ื”ื’ื“ืจื•ืช dnssec-validation ื•-synth-from-dnssec).
  • CVE-2022-0667 - ื™ื™ืชื›ืŸ ืฉื”ืชื”ืœื™ืš ื‘ืขืœ ื”ืฉื ื™ืงืจื•ืก ื‘ืขืช ืขื™ื‘ื•ื“ ื‘ืงืฉื•ืช DS ื ื“ื—ื•ืช. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืจืง ื‘ืขื ืฃ BIND 9.18 ื•ื ื’ืจืžืช ืžื˜ืขื•ืช ืฉื ืขืฉืชื” ื‘ืขืช ืขื™ื‘ื•ื“ ืžื—ื“ืฉ ืฉืœ ืงื•ื“ ื”ืœืงื•ื— ืœืขื™ื‘ื•ื“ ืฉืื™ืœืชื•ืช ืจืงื•ืจืกื™ื‘ื™.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”