BIND DNS server update 9.11.22, 9.16.6, 9.17.4 nekubviswa kwe5

Rakabudiswa Kugadziriswa kwekugadzirisa kumatavi akagadzikana eBIND DNS server 9.11.22 uye 9.16.6, pamwe chete nebazi rekuedza 9.17.4, riri mukugadzirwa. 5 kusasimba kunogadziriswa mune zvitsva zvinoburitswa. Kusagadzikana kwakanyanya kune ngozi (CVE-2020-8620) Kunoitawo Kure konzera kurambwa kwesevhisi nekutumira yakatarwa seti yemapakiti kune TCP chiteshi inogamuchira BIND kubatana. Kutumira zvikumbiro zvakakura zvisina kujairika zveAXFR kuchiteshi cheTCP, zvinogona kukonzera kune chokwadi chekuti raibhurari yeLibuv inoshandira TCP yekubatanidza ichaendesa saizi kuseva, zvichikonzera kuti cheki yekusimbisa itange uye maitiro achipera.

Zvimwe zvinokanganisa:

  • CVE-2020-8621 - munhu anorwisa anogona kukonzeresa cheki uye kukanganisa mugadziri kana achiedza kudzikisa QNAME mushure mekutungamirazve chikumbiro. Dambudziko rinongoonekwa pamaseva ane QNAME minification inogoneswa uye inoshanda mu 'mberi kutanga' modhi.
  • CVE-2020-8622 -munhu anorwisa anogona kutanga cheki yekusimbisa uye kumisa kwechimbichimbi kwekufambiswa kwebasa kana murwiri weDNS server akadzosera mhinduro dzisiridzo neTSIG siginecha achipindura chikumbiro kubva kune akabatwa DNS server.
  • CVE-2020-8623 - munhu anorwisa anogona kukonzeresa cheki yekusimbisa uye kumisa kwechimbichimbi kwemubati nekutumira zvakagadzirirwa zvikumbiro zvenzvimbo zvakasainwa neRSA kiyi. Dambudziko rinongoonekwa kana uchivaka sevha ne "-enable-native-pkcs11" sarudzo.
  • CVE-2020-8624 - munhu anorwisa ane mvumo yekushandura zviri mune mamwe minda munzvimbo dzeDNS anogona kuwana mamwe maropafadzo ekuchinja zvimwe zvirimo muDNS zone.

Source: opennet.ru

Voeg