ืขื“ื›ืŸ ืฉืจืชื™ DNS BIND 9.14.4 ื•- Knot 2.8.3

ื™ืฆื ืœืื•ืจ ืขื“ื›ื•ื ื™ื ืžืชืงื ื™ื ืœืขื ืคื™ ืฉืจืช DNS ื™ืฆื™ื‘ื™ื BIND 9.14.4 ื•-9.11.9, ื›ืžื• ื’ื ืขื ืฃ ื”ื ื™ืกื•ื™ ืฉื ืžืฆื ื›ืขืช ื‘ืคื™ืชื•ื— 9.15.2. ื”ืžื”ื“ื•ืจื•ืช ื”ื—ื“ืฉื•ืช ืžื˜ืคืœื•ืช ื‘ืคื’ื™ืขื•ืช ืฉืœ ืžืฆื‘ ืžื™ืจื•ืฅ (CVE-2019-6471) ืฉืขืœื•ืœื” ืœื”ื•ื‘ื™ืœ ืœืžื ื™ืขืช ืฉื™ืจื•ืช (ื”ืคืกืงืช ืชื”ืœื™ืš ื›ืืฉืจ ื”ื˜ืขื ื” ืžื•ืคืขืœืช) ื›ืืฉืจ ืžืกืคืจ ื’ื“ื•ืœ ืฉืœ ืžื ื•ืช ื ื›ื ืกื•ืช ื ื—ืกืžื•ืช.

ื‘ื ื•ืกืฃ, ื”ื’ืจืกื” ื”ื—ื“ืฉื” 9.14.4 ืžื•ืกื™ืคื” ืชืžื™ื›ื” ื‘-GeoIP2 API ืœื—ื™ื‘ื•ืจ ืžืกื“ ื ืชื•ื ื™ื ืžื™ืงื•ืžื™ื ืขืœ ื‘ืกื™ืก ื›ืชื•ื‘ื•ืช IP ืžื”ื—ื‘ืจื”
MaxMind (ืžื•ืคืขืœ ื‘ืืžืฆืขื•ืช build ืขื ืืคืฉืจื•ืช "--with-geoip2"). GeoIP2 ื›ื‘ืจ ืœื ืชื•ืžืš ื‘ื—ืœืง ืžื”-ACL (ื›ื’ื•ืŸ ืžื”ื™ืจื•ืช ืจืฉืช, ืืจื’ื•ืŸ ื•ืงื•ื“ ืžื“ื™ื ื”) ืฉื ืชืžื›ื• ื‘ืขื‘ืจ ืขื‘ื•ืจ ื”-GeoIP API ื”ื™ืฉืŸ, ืฉืื™ื ื• ืžืชื•ื—ื–ืง ืขื•ื“ ืขืœ ื™ื“ื™ MaxMind. ืžื“ื“ื™ื ื—ื“ืฉื™ื dnssec-sign ื•-dnssec-refresh ื ื•ืกืคื• ื’ื ืขื ืžื•ื ื™ื ืœืžืกืคืจ ื—ืชื™ืžื•ืช DNSSEC ืฉื ื•ืฆืจื• ื•ืžืขื•ื“ื›ื ื•ืช.

ื‘ื ื•ืกืฃ, ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืกื•ื’ื™ื” ืฉืจืช DNS Knot 2.8.3, ืฉื”ื•ืกื™ืฃ ืงื•ื‘ืฅ ืชืฆื•ืจืช ืื™ืฉื•ืจ/ืžืคืชื— ืขื‘ื•ืจ TLS ืœ-kdig, ื”ื’ื“ื™ืœ ืืช ืชื•ื›ืŸ ื”ืžื™ื“ืข ืฉืœ ืขืจื›ื™ ื™ื•ืžืŸ ืขื‘ื•ืจ ื—ืชื™ืžื•ืช ืœื ืžืงื•ื•ื ื•ืช-KSK ื•ืžื•ื“ื•ืœ RRL, ื•ื”ืจื—ื™ื‘ ืืช ื‘ื“ื™ืงื•ืช ื”ืชืฆื•ืจื” ืฉืœ DNSSEC.

ืขื“ื›ื•ืŸ Knot Resolver 4.1.0 ืฉื•ื—ืจืจ ื’ื ื”ื•ื, ืืฉืจ ื‘ื™ื˜ืœ ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” (CVE-2019-10190, CVE-2019-10191): ื™ื›ื•ืœืช ืœืขืงื•ืฃ ื‘ื“ื™ืงื•ืช DNSSEC ืขื‘ื•ืจ ืฉืื™ืœืชื•ืช ืฉืžื•ืช ื—ืกืจื•ืช (NXDOMAIN) ื•ื”ื™ื›ื•ืœืช ืœื”ื—ื–ื™ืจ ื“ื•ืžื™ื™ืŸ ืžื•ื’ืŸ DNSSEC ืœืžืฆื‘ DNSSEC ืœื ืžื•ื’ืŸ ื‘ืืžืฆืขื•ืช ื–ื™ื•ืฃ ืžื ื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”