Ukuba semngciphekweni kwiSeva eGunyaziweyo ye-PowerDNS

Iyafumaneka uhlaziyo lweseva ye-DNS enegunya Iseva eGunyaziweyo ye-PowerDNS 4.3.1, 4.2.3 kunye ne-4.1.14apho isusiwe Ubuthathaka obune, ezimbini zazo ezinokukhokelela ekuphunyezweni kwekhowudi ekude ngumhlaseli.

Ubuthathaka CVE-2020-24696, CVE-2020-24697 kunye CVE-2020-24698
ichaphazela ikhowudi ngokuphunyezwa kwendlela yokutshintshiselana engundoqo I-GSS-TSIG. Ubuthathaka buvela kuphela xa i-PowerDNS yakhiwe ngenkxaso ye-GSS-TSIG (β€œ-enable-experimental-gss-tsig”, ingasetyenziswa ngokungagqibekanga) kwaye ingasetyenziswa ngokuthumela ipakethi yenethiwekhi eyenzelwe ngokukodwa. Iimeko zomdyarho kunye nokuba semngciphekweni okuphindwe kabini kwe-CVE-2020-24696 kunye ne-CVE-2020-24698 kunokukhokelela ekuqhekekeni okanye ekuphunyezweni kwekhowudi yomhlaseli xa kusetyenzwa izicelo ngokufomathwa ngokungalunganga kwe-GSS-TSIG utyikityo. Ukuba sesichengeni kwe-CVE-2020-24697 kukhawulelwe kukwaliwa kwenkonzo. Ekubeni ikhowudi ye-GSS-TSIG yayingasetyenziswanga ngokungagqibekanga, kubandakanywa kwiiphakheji zokusabalalisa, kwaye inokuthi iqulethe ezinye iingxaki, kugqitywe ukuba iyisuse ngokupheleleyo ekukhululweni kwe-PowerDNS Authoritative 4.4.0.

I-CVE-2020-17482 ingakhokelela ekuvuzeni kolwazi kwimemori yenkqubo engenziwanga, kodwa kwenzeka kuphela xa kusenziwa izicelo ezivela kubasebenzisi abaqinisekisiweyo abanako ukongeza iirekhodi ezintsha kwiindawo zeDNS ezinikezelwa ngumncedisi.

umthombo: opennet.ru

Yongeza izimvo