Security DNS

Technitium 15.5.1 patches a session-token leak and a logs-view XSS

Seven days after the nine-fix 15.5 release, the follow-up patches a session-token prefix oracle that let a low-privilege user recover any active session's full token, a logs-view XSS, and a recursive-resolver regression that broke resolution for some domains.

Technitium DNS Server 15.5.1 is out, seven days after 15.5, and if you run 15.5 or anything older it is the quick update to make. The short release carries two reported security fixes and one resolver regression.

The two reported flaws

The first is a session-token prefix oracle. A low-privilege user could recover the full session token of any user’s active session, which includes an administrator’s. Reported by Elias Hasas of Brickell Technologies.

The second is an XSS in the logs view, reported by Yutthavuth Kak of Karpia Cyber. Its gate is narrower: it needs an attacker who can independently create a file with an arbitrary name on the server and already holds DNS Administrator privileges. Worth patching for anyone who has faced a chained attack before, and worth reading for the reminder that log viewers are an input surface.

Also fixed

The resolver bug: recursive resolver limits that were breaking resolution for some domain names. If a handful of domains had been failing to resolve on 15.5, this is the fix for that.

My read

A week after a nine-fix release, the follow-up lands with both flaws credited and fixed in the same build. That is the cadence you want from infrastructure software: no silent closings, no held-back patch. If Technitium is answering queries anywhere you care about, 15.5.1 is the version to be on.

Source: the v15.5.1 release and the changelog.