An update for dnsjava is now available for openEuler-24.03-LTS Security Advisory openeuler-security@openeuler.org openEuler security committee openEuler-SA-2024-1899 Final 1.0 1.0 2024-07-26 Initial 2024-07-26 2024-07-26 openEuler SA Tool V1.0 2024-07-26 dnsjava security update An update for dnsjava is now available for openEuler-24.03-LTS dnsjava is an implementation of DNS in Java. It supports all of the common record types and the DNSSEC types. It can be used for queries, zone transfers, and dynamic updates. It includes a cache which can be used by clients, and a minimal implementation of a server. It supports TSIG authenticated messages, partial DNSSEC verification, and EDNS0. dnsjava provides functionality above and beyond that of the InetAddress class. Since it is written in pure Java, dnsjava is fully threadable, and in many cases is faster than using InetAddress. dnsjava provides both high and low level access to DNS. The high level functions perform queries for records of a given name, type, and class, and return an array of records. There is also a clone of InetAddress, which is even simpler. A cache is used to reduce the number of DNS queries sent. The low level functions allow direct manipulation of dns messages and records, as well as allowing additional resolver properties to be set. A 'dig' clone and a dynamic update program are included, as well as a primary-only server. Security Fix(es): dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. This vulnerability is fixed in 3.6.0.(CVE-2024-25638) An update for dnsjava is now available for openEuler-24.03-LTS. openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section. High dnsjava https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1899 https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-25638 https://nvd.nist.gov/vuln/detail/CVE-2024-25638 openEuler-24.03-LTS dnsjava-3.5.3-2.oe2403.noarch.rpm dnsjava-javadoc-3.5.3-2.oe2403.noarch.rpm dnsjava-3.5.3-2.oe2403.src.rpm dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. This vulnerability is fixed in 3.6.0. 2024-07-26 CVE-2024-25638 openEuler-24.03-LTS High 8.9 AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L dnsjava security update 2024-07-26 https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1899