Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check if MiniDNS DNSSEC NSEC verification is affected by CVE-2018-1000002 #79

Open
Flowdalic opened this issue Feb 10, 2018 · 0 comments

Comments

@Flowdalic
Copy link
Collaborator

From http://www.openwall.com/lists/oss-security/2018/02/09/1

Announcement for Knot Resolver 1.5.2 is here:
https://lists.nic.cz/pipermail/knot-resolver-users/2018/000000.html

Nature of the issue is that original DNSSEC specification in dection 5.4
of [RFC4035] under-specifies the algorithm for checking nonexistence
proofs.

While implementing DNSSEC validation into Knot Resolver, we forgot to
implement additional conditions explained in RFC 6840, so our DNSSEC
validator could accept an NSEC or NSEC3 RR proofs from an ancestor zone
as proving the nonexistence of an RR in a child zone.

Please note that Knot Resolver versions older than latest 1.5.z are
obsolete and not maintained by CZ.NIC anymore so all users all advised
to upgrade immediatelly to to latests 1.5 or 2.0 branches.

Version 1.5.z is going to be end-of-life in approximatelly one month so
direct upgrade to version 2.0 or later is strongly recommended.

More links

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant