nginx: 1-byte memory overwrite vulnerability in DNS resolver (CVE-2021-23017)
x41-dsec.de
x41-dsec.de
I think it's time we come up with something better.
Given how slow dnssec is being adopted, maybe if we hurry our children can enjoy DNSv2
You suggest breaking compatibility for everyone on this planet without giving any specific reason for doing so.
We have had many vulnerabilities related to that single section of the standard over 30 years. At some point you have to ask yourself if the problem lies with the developers or the standard.
If the response is that people would just reuse pre-existing compression libraries, the exact same thing could be said here. In fact, Unix systems provide `dn_expand` and `dn_comp` in libc (e.g. BSDs, Linux/glibc, Linux/musl) or another system library (e.g. -lresolv on Solaris). And of course nginx could have used one of countless other DNS libraries, such as libunbound.