• 公告ID (KylinSec-SA-2024-1606)

摘要:

A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect <domain&gt;;` is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN response.This issue affects BIND 9 versions 9.12.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.

安全等级: Low

公告ID: KylinSec-SA-2024-1606

发布日期: 2024年5月27日

关联CVE: CVE-2023-5517  

  • 详细介绍

1. 漏洞描述

   

A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect <domain&gt;;` is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN response.This issue affects BIND 9 versions 9.12.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2023-5517 KY3.4-4A dhcp Unaffected
CVE-2023-5517 KY3.4-5 dhcp Unaffected
CVE-2023-5517 KY3.5.1 dhcp Unaffected
CVE-2023-5517 KY3.5.2 dhcp Unaffected
CVE-2023-5517 V6 dhcp Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-1605 下一篇:KylinSec-SA-2024-1607