By Interestana AI Editorial — AI-drafted, human-overseen. How we report
BIND 9 Update Fixes 14 Flaws, One Affects DoH

The Internet Systems Consortium (ISC) has addressed fourteen security vulnerabilities within its widely-used BIND 9 open-source DNS server software, releasing updates BIND 9.20.29 and 9.21.26 on September 16. Among the patched flaws is a critical vulnerability that can lead to an unauthenticated crash when BIND servers are configured to handle DNS-over-HTTPS (DoH) requests. This specific issue allows an attacker to crash the server process with a single, specially crafted request containing an invalid SIG record, without requiring any prior authentication or credentials.
BIND, which stands for Berkeley Internet Name Domain, is one of the most prevalent DNS server software packages globally, managing a significant portion of the internet's domain name resolution. Its widespread adoption means that vulnerabilities within BIND can have far-reaching implications for internet stability and security. The ISC's advisory details the fourteen identified flaws, categorizing them by severity and impact. The DoH vulnerability, identified as CVE-2023-50387, is particularly concerning due to its potential for denial-of-service attacks against DNS infrastructure that utilizes this encrypted protocol.
DNS-over-HTTPS (DoH) is a protocol for performing Domain Name System resolution as an encrypted HTTPS query. It enhances privacy and security by encrypting DNS traffic, making it harder for third parties to intercept or manipulate DNS queries. The vulnerability in BIND's DoH implementation means that servers supporting this feature are susceptible to being taken offline by malicious actors exploiting this unauthenticated crash condition. The ISC urges all users of BIND 9 to update their software to the latest patched versions, 9.20.29 or 9.21.26, as soon as possible to mitigate these risks.
In addition to the DoH-related crash, the other thirteen vulnerabilities patched in these releases address a range of security concerns within the BIND 9 software. While the specific details of each of the remaining thirteen flaws are not elaborated upon in the initial disclosure, the ISC's proactive patching indicates a commitment to maintaining the security posture of its software. The release notes for BIND 9.20.29 and 9.21.26 provide comprehensive information on each vulnerability, including affected versions and the specific fixes implemented. Users are advised to consult these notes for a complete understanding of the security enhancements.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.