ืึทืคึผื“ื™ื™ื˜ื™ื ื’ BIND 9.14.4 ืื•ืŸ Knot 2.8.3 ื“ื ืก ืกืขืจื•ื•ืขืจืก

ืคึฟืึทืจืขืคึฟื ื˜ืœืขื›ื˜ ืงืขืจืขืงื˜ื™ื•ื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืฆื• ืกื˜ืึทื‘ื™ืœ ื“ื ืก ืกืขืจื•ื•ืขืจ ืฆื•ื•ื™ื™ื’ืŸ ื‘ื™ื ื“ 9.14.4 ืื•ืŸ 9.11.9, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื™ ื“ืขืจื•ื•ื™ื™ึทืœ ืื•ื ื˜ืขืจ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ื™ืงืกืคึผืขืจืžืขื ืึทืœ ืฆื•ื•ื™ื™ึทื’ 9.15.2. ื“ื™ ื ื™ื™ึทืข ืจื™ืœื™ืกื™ื– ืึทื“ืจืขืก ืึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคื•ืŸ ืจืึทืกืข ืฆื•ืฉื˜ืึทื ื“ (CVE-2019-6471) ื•ื•ืึธืก ืงืขื ืขืŸ ืคื™ืจืŸ ืฆื• ืึท ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ (ืคึผืจืึธืกืขืก ื˜ืขืจืžืึทื ื™ื™ืฉืึทืŸ ื•ื•ืขืŸ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ื˜ืจื™ื’ืขืจื“) ื•ื•ืขืŸ ืึท ื’ืจื•ื™ืก ื ื•ืžืขืจ ืคื•ืŸ ื™ื ืงืึทืžื™ื ื’ ืคึผืึทืงื™ืฅ ื–ืขื ืขืŸ ืืคื’ืขืฉื˜ืขืœื˜.

ืื™ืŸ ืึทื“ื™ืฉืึทืŸ, ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข 9.14.4 ืžื•ืกื™ืฃ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื“ื™ GeoIP2 API ืคึฟืึทืจ ืงืึทื ืขืงื˜ื™ื ื’ ืึท ืึธืจื˜ ื“ืึทื˜ืึทื‘ื™ื™ืก ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ IP ืึทื“ืจืขืกืขืก ืคื•ืŸ ื“ื™ ืคื™ืจืžืข
MaxMind (ืขื ื™ื™ื‘ืึทืœื“ ื“ื•ืจืš ื‘ื•ื™ืขืŸ ืžื™ื˜ ื“ื™ "--ืžื™ื˜-geoip2" ืึธืคึผืฆื™ืข). GeoIP2 ืฉื˜ื™ืฆื˜ ื ื™ื˜ ืžืขืจ ืขื˜ืœืขื›ืข ACLs (ืึทื–ืึท ื•ื•ื™ ื ืขืฅ ื’ื™ื›ืงื™ื™ึทื˜, ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข ืื•ืŸ ืœืึทื ื“ ืงืึธื“) ื‘ื™ื– ืึทื”ืขืจ ื’ืขืฉื˜ื™ืฆื˜ ืคึฟืึทืจ ื“ื™ ืึทืœื˜ GeoIP API, ื•ื•ืึธืก ืื™ื– ื ื™ื˜ ืžืขืจ ืžื™ื™ื ื˜ื™ื™ื ื“ ื“ื•ืจืš MaxMind. ื ื™ื• ืžืขื˜ืจื™ืงืก dnssec-sign ืื•ืŸ dnssec-refresh ื–ืขื ืขืŸ ืื•ื™ืš ืฆื•ื’ืขื’ืขื‘ืŸ ืžื™ื˜ ืงืึธื•ื ื˜ืขืจืก ืคึฟืึทืจ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ืื•ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ DNSSEC ืกื™ื’ื ืึทื˜ืฉืขืจื–.

ืื™ืŸ ื“ืขืจืฆื•, ืขืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื‘ืืžืขืจืงื˜ ืžืขืœื“ื•ื ื’ ื“ื ืก ืกืขืจื•ื•ืขืจ Knot 2.8.3, ืื™ืŸ ื•ื•ืึธืก ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ / ืฉืœื™ืกืœ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข ืคึฟืึทืจ TLS ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• kdig, ื“ื™ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ืœืึธื’ ืื™ื™ื ืกืŸ ืคึฟืึทืจ ืึธืคืคืœื™ื ืข-KSK ืกื™ื’ื ืึทื˜ืฉืขืจื– ืื•ืŸ ื“ื™ RRL ืžืึธื“ื•ืœืข ืื™ื– ื’ืขื•ื•ืืงืกืŸ, ืื•ืŸ DNSSEC ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืฉืขืงืก ื–ืขื ืขืŸ ื™ืงืกืคึผืึทื ื“ื™ื“.

Knot Resolver 4.1.0 ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืื™ื– ืื•ื™ืš ื‘ืืคืจื™ื™ื˜, ื•ื•ืึธืก ื™ืœื™ืžืึทื ื™ื™ื˜ืึทื“ ืฆื•ื•ื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2019-10190, CVE-2019-10191): ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื‘ื™ื™ืคึผืึทืก DNSSEC ื˜ืฉืขืงืก ืคึฟืึทืจ ืคืขืœื ื“ื™ืง ื ืึธืžืขืŸ ืงื•ื•ื™ืจื™ื– (NXDOMAIN) ืื•ืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฆื•ืจื™ืงืงืจื™ื’ืŸ ืึท DNSSEC-ืคึผืจืึธื˜ืขืงื˜ืขื“ ืคืขืœื“ ืฆื• ืึทืŸ ืึทื ืคึผืจืึทื˜ืขืงื˜ื™ื“ DNSSEC ืฉื˜ืึทื˜ ื“ื•ืจืš ืคึผืึทืงืึทื˜ ืกืคึผืึธืึธืคื™ื ื’.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’