ืขื“ื›ื•ืŸ ืฉืจืช DNS BIND ื›ื“ื™ ืœืžื ื•ืข ืคื’ื™ืขื•ืช ื‘ื™ื™ืฉื•ื DNS-over-HTTPS

ืขื“ื›ื•ื ื™ื ืžืชืงื ื™ื ืœืขื ืคื™ื ื”ื™ืฆื™ื‘ื™ื ืฉืœ ืฉืจืช BIND DNS 9.16.28 ื•-9.18.3 ืคื•ืจืกืžื•, ื›ืžื• ื’ื ืžื”ื“ื•ืจื” ื—ื“ืฉื” ืฉืœ ื”ืขื ืฃ ื”ื ื™ืกื™ื•ื ื™ 9.19.1. ื‘ื’ื™ืจืกืื•ืช 9.18.3 ื•-9.19.1 ืชื•ืงื ื” ืคื’ื™ืขื•ืช (CVE-2022-1183) ื‘ื™ื™ืฉื•ื ืžื ื’ื ื•ืŸ DNS-over-HTTPS, ื”ื ืชืžืš ืžืื– ืขื ืฃ 9.18. ื”ืคื’ื™ืขื•ืช ื’ื•ืจืžืช ืœืชื”ืœื™ืš ื”ื ืงื•ื‘ ืœืงืจื•ืก ืื ื—ื™ื‘ื•ืจ ื”-TLS ืœืžื˜ืคืœ ืžื‘ื•ืกืก HTTP ื ืคืกืง ื‘ื˜ืจื ืขืช. ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืจืง ืขืœ ืฉืจืชื™ื ื”ืžืฉืจืชื™ื ื‘ืงืฉื•ืช DNS ื‘ืืžืฆืขื•ืช HTTPS (DoH). ืฉืจืชื™ื ืฉืžืงื‘ืœื™ื ืฉืื™ืœืชื•ืช DNS ืขืœ TLS (DoT) ื•ืื™ื ื ืžืฉืชืžืฉื™ื ื‘-DoH ืื™ื ื ืžื•ืฉืคืขื™ื ืžื‘ืขื™ื” ื–ื•.

ืžื”ื“ื•ืจื” 9.18.3 ื’ื ืžื•ืกื™ืคื” ืžืกืคืจ ืฉื™ืคื•ืจื™ื ืคื•ื ืงืฆื™ื•ื ืœื™ื™ื. ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ื’ืจืกื” ื”ืฉื ื™ื™ื” ืฉืœ ืื–ื•ืจื™ ื”ืงื˜ืœื•ื’ ("ืื–ื•ืจื™ ืงื˜ืœื•ื’"), ื”ืžื•ื’ื“ืจืช ื‘ื˜ื™ื•ื˜ื” ื”ื—ืžื™ืฉื™ืช ืฉืœ ืžืคืจื˜ IETF. Zone Directory ืžืฆื™ืขื” ืฉื™ื˜ื” ื—ื“ืฉื” ืœืชื—ื–ื•ืงืช ืฉืจืชื™ DNS ืžืฉื ื™ื™ื ืฉื‘ื”, ื‘ืžืงื•ื ืœื”ื’ื“ื™ืจ ืจืฉื•ืžื•ืช ื ืคืจื“ื•ืช ืขื‘ื•ืจ ื›ืœ ืื–ื•ืจ ืžืฉื ื™ ื‘ืฉืจืช ื”ืžืฉื ื™, ืžื•ืขื‘ืจืช ืงื‘ื•ืฆื” ืžืกื•ื™ืžืช ืฉืœ ืื–ื•ืจื™ื ืžืฉื ื™ื™ื ื‘ื™ืŸ ื”ืฉืจืช ื”ืจืืฉื™ ื•ื”ืžืฉื ื™. ื”ึธื”ึตืŸ. ืขืœ ื™ื“ื™ ื”ื’ื“ืจืช ื”ืขื‘ืจืช ืกืคืจื™ื” ื‘ื“ื•ืžื” ืœื”ืขื‘ืจืช ืื–ื•ืจื™ื ื‘ื•ื“ื“ื™ื, ืื–ื•ืจื™ื ืฉื ื•ืฆืจื• ื‘ืฉืจืช ื”ืจืืฉื™ ื•ืžืกื•ืžื ื™ื ื›ืœื•ืœื™ื ื‘ืกืคืจื™ื™ื” ื™ื™ื•ื•ืฆืจื• ืื•ื˜ื•ืžื˜ื™ืช ื‘ืฉืจืช ื”ืžืฉื ื™ ืœืœื ืฆื•ืจืš ื‘ืขืจื™ื›ืช ืงื‘ืฆื™ ืชืฆื•ืจื”.

ื”ื’ืจืกื” ื”ื—ื“ืฉื” ืžื•ืกื™ืคื” ื’ื ืชืžื™ื›ื” ื‘ืงื•ื“ื™ ืฉื’ื™ืื” ืžื•ืจื—ื‘ื™ื "Stale Answer" ื•-"Stale NXDOMAIN Answer", ื”ืžื•ื ืคืงื™ื ื›ืืฉืจ ืชืฉื•ื‘ื” ืžืขื•ืคืฉืช ืžื•ื—ื–ืจืช ืžื”ืžื˜ืžื•ืŸ. ืœ-named ื•-dig ื™ืฉ ืื™ืžื•ืช ืžื•ื‘ื ื” ืฉืœ ืชืขื•ื“ื•ืช TLS ื—ื™ืฆื•ื ื™ื•ืช, ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ืŸ ื›ื“ื™ ืœื™ื™ืฉื ืื™ืžื•ืช ื—ื–ืง ืื• ืฉื™ืชื•ืคื™ ื”ืžื‘ื•ืกืก ืขืœ TLS (RFC 9103).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”