ืคื’ื™ืขื•ื™ื•ืช ื‘-systemd, Flatpak, Samba, FreeRDP, Clamav, Node.js

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช (CVE-2021-3997) ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช systemd-tmpfiles ื”ืžืืคืฉืจืช ืœื”ืชืจื—ืฉ ืจืงื•ืจืกื™ื” ื‘ืœืชื™ ืžื‘ื•ืงืจืช. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื‘ืขื™ื” ื›ื“ื™ ืœื’ืจื•ื ืœืžื ื™ืขืช ืฉื™ืจื•ืช ื‘ืžื”ืœืš ืืชื—ื•ืœ ื”ืžืขืจื›ืช ืขืœ ื™ื“ื™ ื™ืฆื™ืจืช ืžืกืคืจ ืจื‘ ืฉืœ ืกืคืจื™ื•ืช ืžืฉื ื” ื‘ืกืคืจื™ื™ืช /tmp. ื”ืชื™ืงื•ืŸ ื–ืžื™ืŸ ื›ืจื’ืข ื‘ืฆื•ืจืช ืชื™ืงื•ืŸ. ืขื“ื›ื•ื ื™ ื—ื‘ื™ืœื•ืช ืœืชื™ืงื•ืŸ ื”ื‘ืขื™ื” ืžื•ืฆืขื™ื ื‘ืื•ื‘ื•ื ื˜ื• ื•ื‘-SUSE, ืืš ืื™ื ื ื–ืžื™ื ื™ื ืขื“ื™ื™ืŸ ื‘ื“ื‘ื™ืืŸ, RHEL ื•ืคื“ื•ืจื” (ืชื™ืงื•ื ื™ื ื ืžืฆืื™ื ื‘ื‘ื“ื™ืงื”).

ื‘ืขืช ื™ืฆื™ืจืช ืืœืคื™ ืกืคืจื™ื•ืช ืžืฉื ื”, ื‘ื™ืฆื•ืข ืคืขื•ืœืช "systemd-tmpfiles --remove" ืงื•ืจืก ืขืงื‘ ืžื™ืฆื•ื™ ืžื—ืกื ื™ืช. ื‘ื“ืจืš ื›ืœืœ, ื›ืœื™ ื”ืฉื™ืจื•ืช systemd-tmpfiles ืžื‘ืฆืข ืืช ื”ืคืขื•ืœื•ืช ืฉืœ ืžื—ื™ืงื” ื•ื™ืฆื™ืจืช ืกืคืจื™ื•ืช ื‘ืงืจื™ืื” ืื—ืช ("systemd-tmpfiles -create -remove -boot -exclude-prefix=/dev"), ื›ืืฉืจ ื”ืžื—ื™ืงื” ืžืชื‘ืฆืขืช ืชื—ื™ืœื” ื•ืœืื—ืจ ืžื›ืŸ ื”ื™ืฆื™ืจื”, ื›ืœื•ืžืจ. ื›ืฉืœ ื‘ืฉืœื‘ ื”ืžื—ื™ืงื” ื™ื’ืจื•ื ืœื›ืš ืฉื”ืงื‘ืฆื™ื ื”ืงืจื™ื˜ื™ื™ื ืฉืฆื•ื™ื ื• ื‘-/usr/lib/tmpfiles.d/*.conf ืœื ื™ื™ื•ื•ืฆืจื•.

ื›ืžื• ื›ืŸ ืžื•ื–ื›ืจ ืชืจื—ื™ืฉ ื”ืชืงืคื” ืžืกื•ื›ืŸ ื™ื•ืชืจ ื‘ืื•ื‘ื•ื ื˜ื• 21.04: ืžื›ื™ื•ื•ืŸ ืฉื”ืงืจื™ืกืช systemd-tmpfiles ืื™ื ื” ื™ื•ืฆืจืช ืืช ื”ืงื•ื‘ืฅ /run/lock/subsys, ื•ืกืคืจื™ื™ืช /run/lock ื ื™ืชื ืช ืœื›ืชื™ื‘ื” ืขืœ ื™ื“ื™ ื›ืœ ื”ืžืฉืชืžืฉื™ื, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื™ืฆื•ืจ / run/lock/ directory subsys ืชื—ืช ื”ืžื–ื”ื” ืฉืœื”, ื•ื‘ืืžืฆืขื•ืช ื™ืฆื™ืจืช ืงื™ืฉื•ืจื™ื ืกืžืœื™ื™ื ื”ืžืฆื˜ืœื‘ื™ื ืขื ืงื‘ืฆื™ ื ืขื™ืœื” ืžืชื”ืœื™ื›ื™ ืžืขืจื›ืช, ืืจื’ืŸ ืืช ื”ื—ืœืคืช ืงื‘ืฆื™ ื”ืžืขืจื›ืช.

ื‘ื ื•ืกืฃ, ืื ื• ื™ื›ื•ืœื™ื ืœืฆื™ื™ืŸ ืืช ื”ืคืจืกื•ื ืฉืœ ืžื”ื“ื•ืจื•ืช ื—ื“ืฉื•ืช ืฉืœ ื”ืคืจื•ื™ืงื˜ื™ื Flatpak, Samba, FreeRDP, Clamav ื•-Node.js, ืฉื‘ื”ื ืคื’ื™ืขื•ื™ื•ืช ืžืชื•ืงื ื•ืช:

  • ื‘ืžื”ื“ื•ืจื•ืช ื”ืžืชืงื ื•ืช ืฉืœ ืขืจื›ืช ื”ื›ืœื™ื ืœื‘ื ื™ื™ืช ื—ื‘ื™ืœื•ืช Flatpak ืขืฆืžืื™ื•ืช 1.10.6 ื•-1.12.3, ืชื•ืงื ื• ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื”: ื”ืคื’ื™ืขื•ืช ื”ืจืืฉื•ื ื” (CVE-2021-43860) ืžืืคืฉืจืช, ื‘ืขืช ื”ื•ืจื“ืช ื—ื‘ื™ืœื” ืžืžืื’ืจ ืœื ืžื”ื™ืžืŸ, ื“ืจืš ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืžื˜ื ื ืชื•ื ื™ื, ื›ื“ื™ ืœื”ืกืชื™ืจ ืืช ื”ืชืฆื•ื’ื” ืฉืœ ื”ืจืฉืื•ืช ืžืชืงื“ืžื•ืช ืžืกื•ื™ืžื•ืช ื‘ืžื”ืœืš ืชื”ืœื™ืš ื”ื”ืชืงื ื”. ื”ืคื’ื™ืขื•ืช ื”ืฉื ื™ื™ื” (ืœืœื CVE) ืžืืคืฉืจืช ืœืคืงื•ื“ื” "flatpak-builder โ€”mirror-screenshots-url" ืœื™ืฆื•ืจ ืกืคืจื™ื•ืช ื‘ืื–ื•ืจ ืžืขืจื›ืช ื”ืงื‘ืฆื™ื ืžื—ื•ืฅ ืœืกืคืจื™ื™ืช ื”-build ื‘ืžื”ืœืš ื”ืจื›ื‘ืช ื”ื—ื‘ื™ืœื•ืช.
  • ืขื“ื›ื•ืŸ Samba 4.13.16 ืžื‘ื˜ืœ ืคื’ื™ืขื•ืช (CVE-2021-43566) ื”ืžืืคืฉืจืช ืœืœืงื•ื— ืœืชืคืขืœ ืงื™ืฉื•ืจื™ื ืกืžืœื™ื™ื ื‘ืžื—ื™ืฆื•ืช SMB1 ืื• NFS ื›ื“ื™ ืœื™ืฆื•ืจ ืกืคืจื™ื™ื” ื‘ืฉืจืช ืžื—ื•ืฅ ืœืื–ื•ืจ ื”-FS ื”ืžื™ื•ืฆื (ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ืžืฆื‘ ืžื™ืจื•ืฅ ื•ืงืฉื” ืœื ื™ืฆื•ืœ ื‘ืคื•ืขืœ, ืื‘ืœ ืืคืฉืจื™ ืชื™ืื•ืจื˜ื™ืช). ื’ืจืกืื•ืช ืฉืœืคื ื™ 4.13.16 ืžื•ืฉืคืขื•ืช ืžื”ื‘ืขื™ื”.

    ื›ืžื• ื›ืŸ, ืคื•ืจืกื ื“ื•ื— ืขืœ ืคื’ื™ืขื•ืช ื“ื•ืžื” ื ื•ืกืคืช (CVE-2021-20316), ื”ืžืืคืฉืจืช ืœืœืงื•ื— ืžืื•ืžืช ืœืงืจื•ื ืื• ืœืฉื ื•ืช ืืช ื”ืชื•ื›ืŸ ืฉืœ ืžื˜ื ื ืชื•ื ื™ื ืฉืœ ืงื•ื‘ืฅ ืื• ืกืคืจื™ื™ื” ื‘ืื–ื•ืจ ืฉืจืช FS ืžื—ื•ืฅ ืœืžืงื˜ืข ื”ืžื™ื•ืฆื ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืงื™ืฉื•ืจื™ื ืกืžืœื™ื™ื. ื”ื‘ืขื™ื” ืชื•ืงื ื” ื‘ืžื”ื“ื•ืจื” 4.15.0, ืืš ืžืฉืคื™ืขื” ื’ื ืขืœ ืกื ื™ืคื™ื ืงื•ื“ืžื™ื. ืขื ื–ืืช, ืชื™ืงื•ื ื™ื ืœืขื ืคื™ื ื™ืฉื ื™ื ืœื ื™ืคื•ืจืกืžื•, ืฉื›ืŸ ืืจื›ื™ื˜ืงื˜ื•ืจืช Samba VFS ื”ื™ืฉื ื” ืื™ื ื” ืžืืคืฉืจืช ืชื™ืงื•ืŸ ื”ื‘ืขื™ื” ืขืงื‘ ืงืฉื™ืจืช ืคืขื•ืœื•ืช ืžื˜ื ื ืชื•ื ื™ื ืœื ืชื™ื‘ื™ ืงื‘ืฆื™ื (ื‘-Samba 4.15 ืฉื›ื‘ืช VFS ืชื•ื›ื ื ื” ืžื—ื“ืฉ ืœื—ืœื•ื˜ื™ืŸ). ืžื” ืฉื”ื•ืคืš ืืช ื”ื‘ืขื™ื” ืœืคื—ื•ืช ืžืกื•ื›ื ืช ื”ื•ื ืฉื”ื™ื ื“ื™ ืžื•ืจื›ื‘ืช ืœืชืคืขื•ืœ ื•ื–ื›ื•ื™ื•ืช ื”ื’ื™ืฉื” ืฉืœ ื”ืžืฉืชืžืฉ ื—ื™ื™ื‘ื•ืช ืœืืคืฉืจ ืงืจื™ืื” ืื• ื›ืชื™ื‘ื” ืœืงื•ื‘ืฅ ื”ื™ืขื“ ืื• ืกืคืจื™ื™ืช ื”ื™ืขื“.

  • ื”ืฉื—ืจื•ืจ ืฉืœ ืคืจื•ื™ืงื˜ FreeRDP 2.5, ื”ืžืฆื™ืข ื™ื™ืฉื•ื ื—ื•ืคืฉื™ ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ ืฉื•ืœื—ืŸ ื”ืขื‘ื•ื“ื” ื”ืžืจื•ื—ืง (RDP), ืžืชืงืŸ ืฉืœื•ืฉ ื‘ืขื™ื•ืช ืื‘ื˜ื—ื” (ืžื–ื”ื™ CVE ืœื ืžื•ืงืฆื™ื) ืฉืขืœื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœื’ืœื™ืฉื” ื‘ืžืื’ืจ ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžืงื•ื ืฉื’ื•ื™, ืขื™ื‘ื•ื“ ืจื™ืฉื•ื ืฉืชื•ื›ื ืŸ ื‘ืžื™ื•ื—ื“ ื”ื’ื“ืจื•ืช ื•ืฆื™ื•ืŸ ืฉื ืชื•ืกืฃ ื‘ืคื•ืจืžื˜ ืฉื’ื•ื™. ื”ืฉื™ื ื•ื™ื™ื ื‘ื’ืจืกื” ื”ื—ื“ืฉื” ื›ื•ืœืœื™ื ืชืžื™ื›ื” ื‘ืกืคืจื™ื™ืช OpenSSL 3.0, ื”ื˜ืžืขืช ื”ื’ื“ืจืช TcpConnectTimeout, ืชืื™ืžื•ืช ืžืฉื•ืคืจืช ืœ-LibreSSL ื•ืคืชืจื•ืŸ ืœื‘ืขื™ื•ืช ื‘ืœื•ื— ื‘ืกื‘ื™ื‘ื•ืช ืžื‘ื•ืกืกื•ืช Wayland.
  • ื”ืžื”ื“ื•ืจื•ืช ื”ื—ื“ืฉื•ืช ืฉืœ ื—ื‘ื™ืœืช ื”ืื ื˜ื™-ื•ื™ืจื•ืก ื”ื—ื™ื ืžื™ืช ClamAV 0.103.5 ื•-0.104.2 ืžื‘ื˜ืœื•ืช ืืช ื”ืคื’ื™ืขื•ืช CVE-2022-20698, ื”ืงืฉื•ืจื” ืœืงืจื™ืืช ืžืฆื‘ื™ืขื™ื ืฉื’ื•ื™ื” ื•ืžืืคืฉืจืช ืœืš ืœื’ืจื•ื ืœืงืจื™ืกืช ืชื”ืœื™ืš ืžืจื—ื•ืง ืื ื”ื—ื‘ื™ืœื” ืžื•ื“ืจื›ืช ืขื ื”-libjson- ืกืคืจื™ื™ืช c ื•ื”ืืคืฉืจื•ืช CL_SCAN_GENERAL_COLLECT_METADATA ืžื•ืคืขืœืช ื‘ื”ื’ื“ืจื•ืช (clamscan --gen-json).
  • ืคืœื˜ืคื•ืจืžืช Node.js ืžืขื“ื›ื ืช ืืช 16.13.2, 14.18.3, 17.3.1 ื•-12.22.9 ืžืชืงื ืช ืืจื‘ืข ื ืงื•ื“ื•ืช ืชื•ืจืคื”: ืขืงื™ืคืช ืื™ืžื•ืช ืื™ืฉื•ืจ ื‘ืขืช ืื™ืžื•ืช ื—ื™ื‘ื•ืจ ืจืฉืช ืขืงื‘ ื”ืžืจื” ืฉื’ื•ื™ื” ืฉืœ SAN (ืฉืžื•ืช ื—ืœื•ืคื™ื™ื ื‘ื ื•ืฉื) ืœืคื•ืจืžื˜ ืžื—ืจื•ื–ืช (CVE- 2021 -44532); ื˜ื™ืคื•ืœ ืฉื’ื•ื™ ื‘ืกืคื™ืจื” ืฉืœ ืžืกืคืจ ืขืจื›ื™ื ื‘ืฉื“ื•ืช ื”ื ื•ืฉื ื•ื”ืžื ืคื™ืง, ืืฉืจ ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ื ื›ื“ื™ ืœืขืงื•ืฃ ืืช ื”ืื™ืžื•ืช ืฉืœ ื”ืฉื“ื•ืช ื”ืžื•ื–ื›ืจื™ื ื‘ืชืขื•ื“ื•ืช (CVE-2021-44533); ื”ื’ื‘ืœื•ืช ืœืขืงื•ืฃ ื”ืงืฉื•ืจื•ืช ืœืกื•ื’ SAN URI ื‘ืชืขื•ื“ื•ืช (CVE-2021-44531); ืื™ืžื•ืช ืงืœื˜ ืœื ืžืกืคื™ืง ื‘ืคื•ื ืงืฆื™ื” console.table() ืฉื™ื›ื•ืœื” ืœืฉืžืฉ ื›ื“ื™ ืœื”ืงืฆื•ืช ืžื—ืจื•ื–ื•ืช ืจื™ืงื•ืช ืœืžืคืชื—ื•ืช ื“ื™ื’ื™ื˜ืœื™ื™ื (CVE-2022-21824).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”