• 公告ID (KylinSec-SA-2023-1060)

摘要:

Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure. _x27;Broken_x27; in this context is anything that would cause the resolver to reject the query response, such as a mismatch between query and answer name. This issue affects BIND 9 versions 9.11.4-S1 through 9.11.37-S1 and 9.16.8-S1 through 9.16.36-S1.

安全等级: Low

公告ID: KylinSec-SA-2023-1060

发布日期: 2023年2月13日

关联CVE: CVE-2022-3488  

  • 详细介绍

1. 漏洞描述

   

Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure. _x27;Broken_x27; in this context is anything that would cause the resolver to reject the query response, such as a mismatch between query and answer name. This issue affects BIND 9 versions 9.11.4-S1 through 9.11.37-S1 and 9.16.8-S1 through 9.16.36-S1.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2022-3488 KY3.4-4A bind Unaffected
CVE-2022-3488 KY3.4-5A bind Unaffected
CVE-2022-3488 KY3.5.1 bind Unaffected
CVE-2022-3488 KY3.5.2 bind Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2023-1059 下一篇:KylinSec-SA-2023-1061