unbound-1.6.6-5.0.1.el7.AXS7

エラータID: AXSA:2024-8714:05

Release date: 
Monday, August 26, 2024 - 18:07
Subject: 
unbound-1.6.6-5.0.1.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Unbound is a validating, recursive, and caching DNS(SEC) resolver.

The C implementation of Unbound is developed and maintained by NLnet Labs. It is
based on ideas and algorithms taken from a java prototype developed by Verisign
labs, Nominet, Kirei and ep.net.

Unbound is designed as a set of modular components, so that also DNSSEC (secure
DNS) validation and stub-resolvers (that do not run as a server, but are linked
into an application) are easily possible.

Security Fix(es):

* CVE-2023-50387: enhanced DNS resolver performance and stability by optimizing
the handling of DNSSEC responses, reducing the potential for resource exhaustion

CVE(s):
CVE-2023-50387
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

Asianux Server 7 for x86_64
  1. unbound-1.6.6-5.0.1.el7.AXS7.x86_64.rpm
    MD5: 60c66279adac1f35a3c061348b1154af
    SHA-256: 43d03c5bbb5cb8970eed88dc11a576c48d96ce07882bd6fd5946056509ace947
    Size: 683.18 kB
  2. unbound-libs-1.6.6-5.0.1.el7.AXS7.i686.rpm
    MD5: 1415c1559d06f7d8e996efc779da7647
    SHA-256: 82012b591f6fcd663688f98aad4e31f437480da394cee27559b168d6cef1d21f
    Size: 397.55 kB
  3. unbound-libs-1.6.6-5.0.1.el7.AXS7.x86_64.rpm
    MD5: e6643ec0b19b964d40c2f66da4da7aa0
    SHA-256: 44b132e430969df5da2bac8ee0416c5030138e1594b4d705a358f4cb64f307af
    Size: 407.06 kB