BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
Overview
The Internet Systems Consortium (ISC) has rolled out updates for its BIND 9 DNS server software, addressing fourteen security flaws, some of which could have serious implications. Notably, one vulnerability allows attackers to crash a server that uses DNS-over-HTTPS (DoH) with a single request that contains an invalid signature, and this can be done without any authentication. This means that any BIND server configured to handle DoH is at risk. The updates, BIND 9.20.29 and 9.21.26, were released on September 16, and system administrators are urged to apply these patches promptly to prevent potential disruptions. Keeping DNS software up to date is crucial as it serves as the backbone of internet communication, and vulnerabilities can lead to significant outages or service interruptions.
Key Takeaways
- Affected Systems: BIND 9.20.29 and 9.21.26
- Action Required: Update to BIND 9.
- Timeline: Disclosed on September 16, 2023
Original Article Summary
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG
Impact
BIND 9.20.29 and 9.21.26
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Disclosed on September 16, 2023
Remediation
Update to BIND 9.20.29 or 9.21.26
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Vulnerability, Update.