37 ืคื’ื™ืขื•ื™ื•ืช ื‘ื™ื™ืฉื•ืžื™ VNC ืฉื•ื ื™ื

ืคืื‘ืœ ืฆ'ืจืžื•ืฉืงื™ืŸ ืžืžืขื‘ื“ืช ืงืกืคืจืกืงื™ ืžึฐื ื•ึผืชึธื— ื™ื™ืฉื•ืžื™ื ืฉื•ื ื™ื ืฉืœ ืžืขืจื›ืช ื”ื’ื™ืฉื” ืžืจื—ื•ืง VNC (Virtual Network Computing) ื•ื–ื™ื”ื• 37 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื ื’ืจืžื• ืžื‘ืขื™ื•ืช ื‘ืขื‘ื•ื“ื” ืขื ื–ื™ื›ืจื•ืŸ. ืคื’ื™ืขื•ื™ื•ืช ืฉื–ื•ื”ื• ื‘ื”ื˜ืžืขื•ืช ืฉืจืช VNC ื™ื›ื•ืœื•ืช ืœื”ื™ื•ืช ืžื ื•ืฆืœื•ืช ืจืง ืขืœ ื™ื“ื™ ืžืฉืชืžืฉ ืžืื•ืžืช, ื•ื”ืชืงืคื•ืช ืขืœ ืคื’ื™ืขื•ื™ื•ืช ื‘ืงื•ื“ ื”ืœืงื•ื— ืืคืฉืจื™ื•ืช ื›ืืฉืจ ืžืฉืชืžืฉ ืžืชื—ื‘ืจ ืœืฉืจืช ื”ื ืฉืœื˜ ืขืœ ื™ื“ื™ ืชื•ืงืฃ.

ื”ืžืกืคืจ ื”ื’ื“ื•ืœ ื‘ื™ื•ืชืจ ืฉืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื ืžืฆืื• ื‘ื—ื‘ื™ืœื” UltraVNC, ื–ืžื™ืŸ ืจืง ืขื‘ื•ืจ ืคืœื˜ืคื•ืจืžืช Windows. ื‘ืกืš ื”ื›ืœ ื–ื•ื”ื• 22 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-UltraVNC. 13 ืคื’ื™ืขื•ื™ื•ืช ืขืœื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืžืขืจื›ืช, 5 ืœื“ืœื™ืคื•ืช ื–ื™ื›ืจื•ืŸ ื•-4 ืœืžื ื™ืขืช ืฉื™ืจื•ืช.
ืคื’ื™ืขื•ื™ื•ืช ืฉืชื•ืงื ื• ื‘ืฉื—ืจื•ืจ 1.2.3.0.

ื‘ืกืคืจื™ื™ื” ื”ืคืชื•ื—ื” LibVNC (LibVNCServer ื•-LibVNCClient), ืืฉืจ ืžืฉืžืฉ ื‘-VirtualBox ื–ื•ื”ื• 10 ื ืงื•ื“ื•ืช ืชื•ืจืคื”.
5 ืคื’ื™ืขื•ื™ื•ืช (CVE-2018-20020, CVE-2018-20019, CVE-2018-15127, CVE-2018-15126, CVE-2018-6307) ื ื’ืจืžื™ื ืขืœ ื™ื“ื™ ื”ืฆืคืช ืžืื’ืจ ื•ืขืœื•ืœื™ื ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“. 3 ืคื’ื™ืขื•ื™ื•ืช ืขืœื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœื“ืœื™ืคืช ืžื™ื“ืข, 2 ืœืžื ื™ืขืช ืฉื™ืจื•ืช.
ื›ืœ ื”ื‘ืขื™ื•ืช ื›ื‘ืจ ืชื•ืงื ื• ืขืœ ื™ื“ื™ ื”ืžืคืชื—ื™ื, ืื‘ืœ ื”ืฉื™ื ื•ื™ื™ื ืขื“ื™ื™ืŸ ืžืฉืชืงืฃ ืจืง ื‘ืกื ื™ืฃ ื”ืžืืกื˜ืจ.

ะ’ TightVNC (ืขื ืฃ ืžื•ืจืฉืช ื—ื•ืฆื” ืคืœื˜ืคื•ืจืžื•ืช ื ื‘ื“ืง 1.3, ืžื›ื™ื•ื•ืŸ ืฉื”ื’ืจืกื” ื”ื ื•ื›ื—ื™ืช 2.x ืžืฉื•ื—ืจืจืช ืจืง ืขื‘ื•ืจ Windows), ื”ืชื’ืœื• 4 ื ืงื•ื“ื•ืช ืชื•ืจืคื”. ืฉืœื•ืฉ ื‘ืขื™ื•ืช (CVE-2019-15679, CVE-2019-15678, CVE-2019-8287) ื ื’ืจืžื•ืช ืขืœ ื™ื“ื™ ื”ืฆืคืช ืžืื’ืจ ื‘ืคื•ื ืงืฆื™ื•ืช InitialiseRFBConnection, rfbServerCutText ื•-HandleCoRREBBP, ื•ืขืฉื•ื™ื•ืช ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“. ื‘ืขื™ื” ืื—ืช (CVE-2019-15680) ืžื•ื‘ื™ืœ ืœืžื ื™ืขืช ืฉื™ืจื•ืช. ืœืžืจื•ืช ืฉืžืคืชื—ื™ TightVNC ื”ื™ื• ื”ื•ื“ื™ืขื• ืœื’ื‘ื™ ื”ื‘ืขื™ื•ืช ื‘ืฉื ื” ืฉืขื‘ืจื”, ื ืงื•ื“ื•ืช ื”ืชื•ืจืคื” ื ื•ืชืจื• ืœืœื ืชื™ืงื•ืŸ.

ื‘ื—ื‘ื™ืœื” ื—ื•ืฆืช ืคืœื˜ืคื•ืจืžื•ืช TurboVNC (ืžื–ืœื’ ืฉืœ TightVNC 1.3 ืฉืžืฉืชืžืฉ ื‘ืกืคืจื™ื™ืช libjpeg-turbo), ื ืžืฆืื” ืจืง ืคื’ื™ืขื•ืช ืื—ืช (CVE-2019-15683), ืื‘ืœ ื–ื” ืžืกื•ื›ืŸ, ื•ืื ื™ืฉ ืœืš ื’ื™ืฉื” ืžืื•ืžืชืช ืœืฉืจืช, ื–ื” ืžืืคืฉืจ ืœืืจื’ืŸ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœืš, ืฉื›ืŸ ืื ื”ืžืื’ืจ ืขื•ืœื” ืขืœ ื’ื“ื•ืชื™ื•, ืืคืฉืจ ืœืฉืœื•ื˜ ื‘ื›ืชื•ื‘ืช ื”ื”ื—ื–ืจื”. ื”ื‘ืขื™ื” ื ืคืชืจื” 23 ืื•ื’ื•ืกื˜ ื•ืื™ื ื• ืžื•ืคื™ืข ื‘ืžื”ื“ื•ืจื” ื”ื ื•ื›ื—ื™ืช 2.2.3.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”