ืขื“ื›ื•ืŸ ืฉืจืช BIND DNS ื›ื“ื™ ืœืชืงืŸ ืคื’ื™ืขื•ืช ืฉืœ ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง

ืคื•ืจืกืžื• ืขื“ื›ื•ื ื™ื ืžืชืงื ื™ื ืขื‘ื•ืจ ื”ืขื ืคื™ื ื”ื™ืฆื™ื‘ื™ื ืฉืœ ืฉืจืช ื”-BIND DNS 9.11.31 ื•-9.16.15 ื•ื›ืŸ ืœืขื ืฃ ื”ื ื™ืกื™ื•ื ื™ 9.17.12 ืฉื ืžืฆื ื‘ืคื™ืชื•ื—. ื”ืžื”ื“ื•ืจื•ืช ื”ื—ื“ืฉื•ืช ืžื˜ืคืœื•ืช ื‘ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื”, ืื—ืช ืžื”ืŸ (CVE-2021-25216) ื’ื•ืจืžืช ืœื”ืฆืคืช ืžืื’ืจ. ื‘ืžืขืจื›ื•ืช 32 ืกื™ื‘ื™ื•ืช, ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ืœื‘ื™ืฆื•ืข ืžืจื—ื•ืง ืฉืœ ืงื•ื“ ืฉืœ ืชื•ืงืฃ ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉืช GSS-TSIG ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“. ื‘-64 ืžืขืจื›ื•ืช ื”ื‘ืขื™ื” ืžื•ื’ื‘ืœืช ืœืงืจื™ืกื” ืฉืœ ื”ืชื”ืœื™ืš ื”ื ืงื•ื‘.

ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืจืง ื›ืืฉืจ ืžื ื’ื ื•ืŸ GSS-TSIG ืžื•ืคืขืœ, ืžื•ืคืขืœ ื‘ืืžืฆืขื•ืช ื”ื’ื“ืจื•ืช tkey-gssapi-keytab ื•-tkey-gssapi-credential. GSS-TSIG ืžื•ืฉื‘ืช ื‘ืชืฆื•ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื•ืžืฉืžืฉ ื‘ื“ืจืš ื›ืœืœ ื‘ืกื‘ื™ื‘ื•ืช ืžืขื•ืจื‘ื•ืช ืฉื‘ื”ืŸ BIND ืžืฉื•ืœื‘ ืขื ื‘ืงืจื™ ืชื—ื•ื Active Directory, ืื• ื‘ืขืช ืฉื™ืœื•ื‘ ืขื Samba.

ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืžืฉื’ื™ืื” ื‘ื™ื™ืฉื•ื ืžื ื’ื ื•ืŸ SPNEGO (Simple and Protected GSSAPI Negotiation Mechanism) ื”ืžืฉืžืฉ ื‘-GSSAPI ื›ื“ื™ ืœื ื”ืœ ืžืฉื ื•ืžืชืŸ ืขืœ ืฉื™ื˜ื•ืช ื”ื”ื’ื ื” ื”ืžืฉืžืฉื•ืช ืืช ื”ืœืงื•ื— ื•ื”ืฉืจืช. GSSAPI ืžืฉืžืฉ ื›ืคืจื•ื˜ื•ืงื•ืœ ื‘ืจืžื” ื’ื‘ื•ื”ื” ืœื”ื—ืœืคืช ืžืคืชื—ื•ืช ืžืื•ื‘ื˜ื—ืช ื‘ืืžืฆืขื•ืช ืชื•ืกืฃ GSS-TSIG ื”ืžืฉืžืฉ ื‘ืชื”ืœื™ืš ืื™ืžื•ืช ืขื“ื›ื•ื ื™ ืื–ื•ืจื™ DNS ื“ื™ื ืžื™ื™ื.

ืžื›ื™ื•ื•ืŸ ืฉื›ื‘ืจ ื ืžืฆืื• ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืงืจื™ื˜ื™ื•ืช ื‘ื™ื™ืฉื•ื ื”ืžื•ื‘ื ื” ืฉืœ SPNEGO, ื”ื™ื™ืฉื•ื ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ ื–ื” ื”ื•ืกืจ ืžื‘ืกื™ืก ื”ืงื•ื“ BIND 9. ืœืžืฉืชืžืฉื™ื ื”ื–ืงื•ืงื™ื ืœืชืžื™ื›ื” ื‘-SPNEGO, ืžื•ืžืœืฅ ืœื”ืฉืชืžืฉ ื‘ื™ื™ืฉื•ื ื—ื™ืฆื•ื ื™ ื”ืžืกื•ืคืง ืขืœ ื™ื“ื™ ื”-GSSAPI ืกืคืจื™ื™ืช ืžืขืจื›ืช (ืžืกื•ืคืงืช ื‘-MIT Kerberos ื•-Heimdal Kerberos).

ืžืฉืชืžืฉื™ื ืฉืœ ื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ ืฉืœ BIND, ื›ืคืชืจื•ืŸ ืขื•ืงืฃ ืœื—ืกื™ืžืช ื”ื‘ืขื™ื”, ื™ื›ื•ืœื™ื ืœื”ืฉื‘ื™ืช ืืช GSS-TSIG ื‘ื”ื’ื“ืจื•ืช (ืืคืฉืจื•ื™ื•ืช tkey-gssapi-keytab ื•-tkey-gssapi-credential) ืื• ืœื‘ื ื•ืช ืžื—ื“ืฉ ืืช BIND ืœืœื ืชืžื™ื›ื” ื‘ืžื ื’ื ื•ืŸ SPNEGO (ืืคืฉืจื•ืช "- -disable-isc-spnego" ื‘ืกืงืจื™ืคื˜ "configure"). ืืชื” ื™ื›ื•ืœ ืœืขืงื•ื‘ ืื—ืจ ื–ืžื™ื ื•ืช ื”ืขื“ื›ื•ื ื™ื ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ื ื”ื‘ืื™ื: Debian, SUSE, Ubuntu, Fedora, Arch Linux, FreeBSD, NetBSD. ื—ื‘ื™ืœื•ืช RHEL ื•-ALT Linux ื‘ื ื•ื™ื•ืช ืœืœื ืชืžื™ื›ื” ืžืงื•ืจื™ืช ืฉืœ SPNEGO.

ื‘ื ื•ืกืฃ, ืฉืชื™ ืคื’ื™ืขื•ื™ื•ืช ื ื•ืกืคื•ืช ืžืชื•ืงื ื•ืช ื‘ืขื“ื›ื•ื ื™ BIND ื”ืžื“ื•ื‘ืจื™ื:

  • CVE-2021-25215 - ื”ืชื”ืœื™ืš ืฉืฉืžื• ืงืจืก ื‘ืขืช ืขื™ื‘ื•ื“ ืจืฉื•ืžื•ืช DNAME (ืขื™ื‘ื•ื“ ืžื—ื“ืฉ ืฉืœ ื—ืœืง ืžืชืช-ื“ื•ืžื™ื™ื ื™ื), ืžื” ืฉื”ื•ื‘ื™ืœ ืœื”ื•ืกืคืช ื›ืคื™ืœื•ื™ื•ืช ืœืงื˜ืข ANSWER. ื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช ื‘ืฉืจืชื™ DNS ืกืžื›ื•ืชื™ื™ื ืžื—ื™ื™ื‘ ื‘ื™ืฆื•ืข ืฉื™ื ื•ื™ื™ื ื‘ืื–ื•ืจื™ ื”-DNS ื”ืžืขื•ื‘ื“ื™ื, ื•ืœื’ื‘ื™ ืฉืจืชื™ื ืจืงื•ืจืกื™ื‘ื™ื™ื ื ื™ืชืŸ ืœืงื‘ืœ ืืช ื”ืจืฉื•ืžื” ื”ื‘ืขื™ื™ืชื™ืช ืœืื—ืจ ืคื ื™ื™ื” ืœืฉืจืช ื”ืกืžื›ื•ืชื™.
  • CVE-2021-25214 - ื”ืชื”ืœื™ืš ื”ื ืงืจื ืงื•ืจืก ื‘ืขืช ืขื™ื‘ื•ื“ ื‘ืงืฉืช IXFR ื ื›ื ืกืช ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“ (ืžืฉืžืฉ ืœื”ืขื‘ืจืช ืฉื™ื ื•ื™ื™ื ื”ื“ืจื’ืชื™ื™ื ื‘ืื–ื•ืจื™ DNS ื‘ื™ืŸ ืฉืจืชื™ DNS). ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืจืง ืขืœ ืžืขืจื›ื•ืช ืฉืืคืฉืจื• ื”ืขื‘ืจื•ืช ืื–ื•ืจื™ DNS ืžื”ืฉืจืช ืฉืœ ื”ืชื•ืงืฃ (ื‘ื“ืจืš ื›ืœืœ ื”ืขื‘ืจื•ืช ืื–ื•ืจื™ื ืžืฉืžืฉื•ืช ืœืกื ื›ืจื•ืŸ ืฉืจืชื™ ืžืืกื˜ืจ ื•ืฉืจืช ืขื‘ื“ื™ื ื•ืžืชื™ืจื•ืช ื‘ืื•ืคืŸ ืกืœืงื˜ื™ื‘ื™ ืจืง ืขื‘ื•ืจ ืฉืจืชื™ื ืžื”ื™ืžื ื™ื). ื›ืคืชืจื•ืŸ ืื‘ื˜ื—ื”, ืืชื” ื™ื›ื•ืœ ืœื”ืฉื‘ื™ืช ืืช ืชืžื™ื›ืช IXFR ื‘ืืžืฆืขื•ืช ื”ื”ื’ื“ืจื” "request-ixfr no;".

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”