Nuglaanta fulinta koodka fog ee server-ka DNS ee Unbound

In server-ka DNS Unbound la aqoonsaday nuglaanta (CVE-2019-18934), kaas oo u horseedi kara fulinta koodka weerarka marka la helo jawaabaha si gaar ah u qaabaysan. Nidaamyada waxaa kaliya oo saameeya dhibaatada marka la dhisayo Unbound with module ipsec ("-enable-ipsecmod") iyo ipsecmod karti u leh goobaha. Nuglaanta waxay u muuqataa inay ka bilaabmayso nooca 1.6.4 waxayna ku xidhan tahay siidaynta Furan 1.9.5.

Nuglaanta waxaa sababa gudbinta jilayaasha aan la qarin karin marka la wacayo taliska ipsecmod-hook shell marka la helo codsiga domain kaas oo diiwaanada A/AAAA iyo IPSECKEY ay ku jiraan. Beddelka koodka waxaa lagu fuliyaa iyadoo lagu qeexo magac domain oo si gaar ah loo nashqadeeyay ee ku jira qname iyo garoonnada albaabada ee la xidhiidha diiwaanka IPSECKEY.

Source: opennet.ru

Add a comment