ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ BIND DNS ืกืขืจื•ื•ืขืจ ื•ื•ืึธืก ืงืขืŸ ื ื™ืฉื˜ ื•ื™ืกืฉืœื™ืกืŸ ื“ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื•ื•ื™ื™ึทื˜ ืงืึธื“

ืงืขืจืขืงื˜ื™ื•ื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ื–ืขื ืขืŸ ืืจื•ื™ืก ืคึฟืึทืจ ื“ื™ ืกื˜ืึทื‘ื™ืœ ืฆื•ื•ื™ื™ื’ืŸ ืคื•ืŸ ื“ื™ BIND DNS ืกืขืจื•ื•ืขืจ 9.11.28 ืื•ืŸ 9.16.12, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื™ ื™ืงืกืคึผืขืจืžืขื ืึทืœ ืฆื•ื•ื™ื™ึทื’ 9.17.10, ื•ื•ืึธืก ืื™ื– ืื™ืŸ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’. ื“ื™ ื ื™ื™ึทืข ืจื™ืœื™ืกื™ื– ืึทื“ืจืขืก ืึท ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2020-8625) ื•ื•ืึธืก ืงืขืŸ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืคื™ืจืŸ ืฆื• ื•ื•ื™ื™ึทื˜ ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ื“ื•ืจืš ืึทืŸ ืึทื˜ืึทืงืขืจ. ืงื™ื™ืŸ ืฉืคึผื•ืจ ืคื•ืŸ ืึทืจื‘ืขื˜ ืขืงืกืคึผืœื•ื™ืฅ ื–ืขื ืขืŸ ื ืึธืš ื™ื™ื“ืขื ืึทืคื™ื™ื“.

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืึท ื˜ืขื•ืช ืื™ืŸ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ SPNEGO (Simple and Protected GSSAPI Negotiation Mechanism) ืžืขืงืึทื ื™ื–ืึทื ื’ืขื ื™ืฆื˜ ืื™ืŸ GSSAPI ืฆื• ืคืึทืจื”ืึทื ื“ืœืขืŸ ื“ื™ ืฉื•ืฅ ืžืขื˜ื”ืึธื“ืก ื’ืขื ื™ืฆื˜ ื“ื•ืจืš ื“ืขื ืงืœื™ืขื ื˜ ืื•ืŸ ืกืขืจื•ื•ืขืจ. GSSAPI ืื™ื– ื’ืขื ื™ืฆื˜ ื•ื•ื™ ืึท ื”ื•ื™ืš-ืžื“ืจื’ื” ืคึผืจืึธื˜ืึธืงืึธืœ ืคึฟืึทืจ ื–ื™ื›ืขืจ ืฉืœื™ืกืœ ื•ื•ืขืงืกืœ ืžื™ื˜ ื“ื™ GSS-TSIG ืคืึทืจืœืขื ื’ืขืจื•ื ื’ ื’ืขื ื™ืฆื˜ ืื™ืŸ ื“ืขื ืคึผืจืึธืฆืขืก ืคื•ืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ื™ื ื’ ื“ื™ื ืึทืžื™ืฉ ื“ื ืก ื–ืึธื ืข ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ.

ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืึทืคืขืงืฅ ืกื™ืกื˜ืขืžืขืŸ ื•ื•ืึธืก ื–ืขื ืขืŸ ืงืึทื ืคื™ื’ื™ืขืจื“ ืฆื• ื ื•ืฆืŸ GSS-TSIG (ืœืžืฉืœ ืื•ื™ื‘ ื“ื™ tkey-gssapi-keytab ืื•ืŸ tkey-gssapi-ืงืจืขื“ืขื ืฉืึทืœ ืกืขื˜ื˜ื™ื ื’ืก ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜). GSS-TSIG ืื™ื– ื˜ื™ืคึผื™ืงืœื™ ื’ืขื ื™ืฆื˜ ืื™ืŸ ื’ืขืžื™ืฉื˜ ื™ื ื•ื•ื™ื™ืจืึทื ืžืึทื ืฅ ื•ื•ื• BIND ืื™ื– ืงืึทืžื‘ื™ื™ื ื“ ืžื™ื˜ ืึทืงื˜ื™ื•ื•ืข Directory ืคืขืœื“ ืงืึทื ื˜ืจืึธื•ืœืขืจื–, ืึธื“ืขืจ ื™ื ืึทื’ืจื™ื™ื˜ื™ื“ ืžื™ื˜ ืกืึทืžื‘ืึท. ืื™ืŸ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ, GSS-TSIG ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜.

ื ื•ื•ืึธืจืงืึทืจืึธื•ื ื“ ืคึฟืึทืจ ื‘ืœืึทืงื™ื ื’ ื“ืขื ืคึผืจืึธื‘ืœืขื ื•ื•ืึธืก ื˜ื•ื˜ ื ื™ืฉื˜ ื“ืึทืจืคืŸ ื“ื™ืกื™ื™ื‘ืึทืœื™ื ื’ GSS-TSIG ืื™ื– ืฆื• ื‘ื•ื™ืขืŸ BIND ืึธืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื“ื™ SPNEGO ืžืขืงืึทื ื™ื–ืึทื, ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ืคืึทืจืงืจื™ืคึผืœื˜ ื“ื•ืจืš ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ "--disable-isc-spnego" ืึธืคึผืฆื™ืข ื•ื•ืขืŸ ืคืœื™ืกื ื“ื™ืง ื“ื™ "ืงืึธื ืคื™ื’ื•ืจืข" ืฉืจื™ืคื˜. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ื‘ืœื™ื™ื‘ื˜ ืึทื ืคื™ืงืกื˜ ืื™ืŸ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื–. ืื™ืจ ืงืขื ืขืŸ ืฉืคึผื•ืจ ื“ื™ ืึทื•ื•ื™ื™ืœืึทื‘ื™ืœืึทื˜ื™ ืคื•ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืื•ื™ืฃ ื“ื™ ืคืืœื’ืขื ื“ืข ื‘ืœืขื˜ืขืจ: Debian, RHEL, SUSE, Ubuntu, Fedora, Arch Linux, FreeBSD, NetBSD.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’