An update for dnsjava is now available for openEuler-24.03-LTS
Security Advisory
openeuler-security@openeuler.org
openEuler security committee
openEuler-SA-2024-1899
Final
1.0
1.0
2024-07-26
Initial
2024-07-26
2024-07-26
openEuler SA Tool V1.0
2024-07-26
dnsjava security update
An update for dnsjava is now available for openEuler-24.03-LTS
dnsjava is an implementation of DNS in Java. It supports all of the common record types and the DNSSEC types. It can be used for queries, zone transfers, and dynamic updates. It includes a cache which can be used by clients, and a minimal implementation of a server. It supports TSIG authenticated messages, partial DNSSEC verification, and EDNS0. dnsjava provides functionality above and beyond that of the InetAddress class. Since it is written in pure Java, dnsjava is fully threadable, and in many cases is faster than using InetAddress. dnsjava provides both high and low level access to DNS. The high level functions perform queries for records of a given name, type, and class, and return an array of records. There is also a clone of InetAddress, which is even simpler. A cache is used to reduce the number of DNS queries sent. The low level functions allow direct manipulation of dns messages and records, as well as allowing additional resolver properties to be set. A 'dig' clone and a dynamic update program are included, as well as a primary-only server.
Security Fix(es):
dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. This vulnerability is fixed in 3.6.0.(CVE-2024-25638)
An update for dnsjava is now available for openEuler-24.03-LTS.
openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
High
dnsjava
https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1899
https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-25638
https://nvd.nist.gov/vuln/detail/CVE-2024-25638
openEuler-24.03-LTS
dnsjava-3.5.3-2.oe2403.noarch.rpm
dnsjava-javadoc-3.5.3-2.oe2403.noarch.rpm
dnsjava-3.5.3-2.oe2403.src.rpm
dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. This vulnerability is fixed in 3.6.0.
2024-07-26
CVE-2024-25638
openEuler-24.03-LTS
High
8.9
AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
dnsjava security update
2024-07-26
https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1899