Simon Kelley ea9bd30cd4 Fix information disclosure.
An oversight in commit f9f8d19bf5
leaves a code path where a repeat of a query gets an error reply
which discloses the id field used in interactions with upstream
servers ro get an answer to the query. By triggering this
code path, an attacker can determine the id, which makes Kaminsky
cache poisoning attacks much less expensive and much more certain.

This bug exists in stable releases 2.91, 2.92 2.92rel2 and 2.93

Thanks to Ronen Shustin from Project Atlas, Wiz for finding
this problem.
2026-06-14 23:36:43 +01:00
…
…
…
2026-06-11 15:29:35 +01:00
2025-12-07 13:44:40 +00:00
2026-06-14 23:36:43 +01:00
2026-06-04 12:47:22 +01:00
…
…
…
…
2026-04-08 12:08:18 +01:00
…
S
Description
No description provided
12 MiB
Languages
C 94.3%
Perl 2.2%
HTML 1.2%
Shell 1%
Makefile 0.6%
Other 0.6%