Ukwenziwa kwekhowudi ekude ukuba semngciphekweni kwi-Unbound DNS server

Kwiseva ye-DNS Engabotshwanga ichongiwe ukuba sesichengeni (I-CVE-2019-18934), enokukhokelela ekuqhutyweni kwekhowudi yomhlaseli xa ifumana iimpendulo ezifomathiweyo ngokukodwa. Iinkqubo zichaphazeleka kuphela yingxaki xa kwakhiwa i-Unbound kunye nemodyuli ye-ipsec ("-enable-ipsecmod") kunye ne-ipsecmod enikwe amandla kwizicwangciso. Ubuthathaka bubonakala buqala kuguqulelo 1.6.4 kwaye lulungisiwe kukhupho Ingabotshwanga 1.9.5.

Ukuba sesichengeni kubangelwa kugqithiso lweempawu ezingaphuncukiyo xa kufowuna umyalelo weqokobhe le-ipsecmod-hook xa ufumana isicelo sommandla apho iirekhodi ze-A/AAAA kunye ne-IPSECKEY zikhona. Ukutshintshwa kwekhowudi kuqhutyelwa ngokucacisa igama lesizinda elenziwe ngokukodwa kwi-qname kunye nesango lesango elinxulumene nerekhodi ye-IPSECKEY.

umthombo: opennet.ru

Yongeza izimvo