Remote code execution kusagadzikana muUnbound DNS server

Mune Unbound DNS server kuzivikanwa vulnerability (CVE-2019-18934), izvo zvinogona kutungamira pakuitwa kweanorwisa kodhi kana uchigamuchira zvakanyatso fomati mhinduro. Masisitimu anongobatwa nedambudziko pakuvaka Unbound ne ipsec module ("-enable-ipsecmod") uye ipsecmod inogoneswa muzvirongwa. Kusagadzikana kunoonekwa kutanga kubva kuvhezheni 1.6.4 uye kunogadziriswa mukuburitswa Unbound 1.9.5.

Kusagadzikana kunokonzerwa nekufambiswa kwemavara asina kupukunyuka pakudaidza ipsecmod-hook shell command kana uchigamuchira chikumbiro chedomeine iyo A/AAAA uye IPSECKEY marekodhi aripo. Code substitution inoitwa nekutsanangudza zita rakagadzirirwa domain mu qname uye gedhi minda ine chekuita neIPSECKEY rekodhi.

Source: opennet.ru

Voeg