BIND isibuyekezo seseva ye-DNS 9.11.22, 9.16.6, 9.17.4 nokususwa kobungozi obungu-5

Ishicilelwe Izibuyekezo zokulungisa amagatsha azinzile weseva ye-BIND DNS 9.11.22 kanye ne-9.16.6, kanye negatsha lokuhlola elingu-9.17.4, elisathuthukiswayo. 5 ubungozi bulungisiwe ekukhishweni okusha. Ubungozi obuyingozi kakhulu (I-CVE-2020-8620) kuvumela Yenza ukude ukunqatshelwa kwesevisi ngokuthumela isethi ethile yamaphakethe embobeni ye-TCP eyamukela uxhumo lwe-BIND. Ukuthumela izicelo ze-AXFR ezinkulu ngokungavamile echwebeni le-TCP, kungase kubangele eqinisweni lokuthi umtapo wezincwadi we-libuv ohlinzeka ngoxhumano lwe-TCP uzodlulisela usayizi kuseva, okuholela ekucushweni kokuhlola nokusho ukuthi inqubo iyaphela.

Okunye ubungozi:

  • I-CVE-2020-8621 β€” umhlaseli angaqalisa ukuhlola kokugomela futhi aphahlaze isixazululi lapho ezama ukunciphisa i-QNAME ngemva kokuqondisa kabusha isicelo. Inkinga ivela kuphela eziphakelini ezine-QNAME minification enikwe amandla futhi isebenza ngemodi 'yokudlulisela kuqala'.
  • I-CVE-2020-8622 - umhlaseli angakwazi ukuqalisa isheke lokugomela kanye nokunqanyulwa okuphuthumayo kokuhamba komsebenzi uma iseva ye-DNS yomhlaseli ibuyisela izimpendulo ezingalungile ngesiginesha ye-TSIG ephendula isicelo esivela kuseva ye-DNS yesisulu.
  • I-CVE-2020-8623 β€” umhlaseli angaqalisa ukuhlola kokugomela kanye nokunqanyulwa okuphuthumayo kwesibambi ngokuthumela izicelo zendawo eziklanywe ngokukhethekile ezisayinwe ngokhiye we-RSA. Inkinga ivela kuphela lapho wakha iseva ngenketho ethi β€œ-enable-native-pkcs11”.
  • I-CVE-2020-8624 - umhlaseli onegunya lokushintsha okuqukethwe kwezinkambu ezithile ezindaweni ze-DNS angathola amalungelo angeziwe okushintsha okunye okuqukethwe kwendawo ye-DNS.

Source: opennet.ru

Engeza amazwana