15 ืคื’ื™ืขื•ื™ื•ืช ื‘ืžื ื”ืœื™ ื”ืชืงืŸ USB ื”ื ื™ืชื ื™ื ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก

ืื ื“ืจื™ื™ ืงื•ื ื•ื‘ืœื•ื‘ ืžื’ื•ื’ืœ ืคื•ืจืกื ื“ื™ื•ื•ื— ืขืœ ื–ื™ื”ื•ื™ 15 ื”ืคื’ื™ืขื•ื™ื•ืช ื”ื‘ืื•ืช (CVE-2019-19523 - CVE-2019-19537) ื‘ืžื ื”ืœื™ ื”ืชืงืŸ USB ื”ืžื•ืฆืขื™ื ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก. ื–ื•ื”ื™ ืืฆื•ื•ื” ืฉืœื™ืฉื™ืช ืฉืœ ื‘ืขื™ื•ืช ืฉื ืžืฆืื” ื‘ืžื”ืœืš ื‘ื“ื™ืงืช ื”-fuzz ืฉืœ ืขืจื™ืžืช ื”-USB ื‘ื—ื‘ื™ืœื” syzkaller - ื—ื•ืงืจ ืฉื ื™ืชืŸ ื‘ืขื‘ืจ ื›ื‘ืจ ืžืขื•ื“ื›ืŸ ืขืœ ื ื•ื›ื—ื•ืชืŸ ืฉืœ 29 ื ืงื•ื“ื•ืช ืชื•ืจืคื”.

ื”ืคืขื ื”ืจืฉื™ืžื” ื›ื•ืœืœืช ืจืง ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื”ื ื’ืจืžื•ืช ื›ืชื•ืฆืื” ืžื’ื™ืฉื” ืœืื–ื•ืจื™ ื–ื™ื›ืจื•ืŸ ืฉื›ื‘ืจ ืฉื•ื—ืจืจื• (ืฉื™ืžื•ืฉ-ืื—ืจื™-ื—ื•ืคืฉื™) ืื• ื”ืžื•ื‘ื™ืœื” ืœื“ืœื™ืคืช ื ืชื•ื ื™ื ืžื–ื™ื›ืจื•ืŸ ื”ืœื™ื‘ื”. ื‘ืขื™ื•ืช ืฉืขืœื•ืœื•ืช ืœืฉืžืฉ ื›ื“ื™ ืœื’ืจื•ื ืœืžื ื™ืขืช ืฉื™ืจื•ืช ืื™ื ืŸ ื›ืœื•ืœื•ืช ื‘ื“ื•ื—. ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ื™ื•ืช ื›ืืฉืจ ื”ืชืงื ื™ USB ืฉื”ื•ื›ื ื• ื‘ืžื™ื•ื—ื“ ืžื—ื•ื‘ืจื™ื ืœืžื—ืฉื‘. ืชื™ืงื•ื ื™ื ืœื›ืœ ื”ื‘ืขื™ื•ืช ื”ืžื•ื–ื›ืจื•ืช ื‘ื“ื•ื— ื›ื‘ืจ ื›ืœื•ืœื™ื ื‘ืงืจื ืœ, ืืš ื—ืœืงื ืื™ื ื ื›ืœื•ืœื™ื ื‘ื“ื•ื— ืฉื’ื™ืื•ืช ืขื“ ื›ื” ื ื•ืชืจื• ืœืœื ืชื™ืงื•ืŸ.

ื”ืคื’ื™ืขื•ื™ื•ืช ื”ืžืกื•ื›ื ื•ืช ื‘ื™ื•ืชืจ ืœืœื ืฉื™ืžื•ืฉ ืœืื—ืจ-ื—ื•ืคืฉื™ ืฉื™ื›ื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“ ืชื•ืงืฃ ื‘ื•ื˜ืœื• ื‘ืžื ื”ืœื™ ื”ืชืงื ื™ื adutux, ff-memless, ieee802154, pn533, hiddev, iowarrior, mcba_usb ื•-yurex. CVE-2019-19532 ืžืคืจื˜ ื‘ื ื•ืกืฃ 14 ืคื’ื™ืขื•ื™ื•ืช ื‘ืžื ื”ืœื™ ื”ืชืงื ื™ื ืฉืœ HID ื”ื ื’ืจืžื•ืช ืขืœ ื™ื“ื™ ืฉื’ื™ืื•ืช ื”ืžืืคืฉืจื•ืช ื›ืชื™ื‘ื” ืžื—ื•ืฅ ืœืชื—ื•ื. ื ืžืฆืื• ื‘ืขื™ื•ืช ื‘ืžื ื”ืœื™ ื”ื”ืชืงืŸ ttusb_dec, pcan_usb_fd ื•- pcan_usb_pro ืฉื”ื•ื‘ื™ืœื• ืœื“ืœื™ืคืช ื ืชื•ื ื™ื ืžื–ื™ื›ืจื•ืŸ ื”ืœื™ื‘ื”. ื–ื•ื”ืชื” ื‘ืขื™ื” (CVE-2019-19537) ืขืงื‘ ืžืฆื‘ ื’ื–ืข ื‘ืงื•ื“ ืขืจื™ืžืช ื”-USB ืœืขื‘ื•ื“ื” ืขื ื”ืชืงื ื™ ืชื•ื•ื™ื.

ืืคืฉืจ ื’ื ืœืฆื™ื™ืŸ
ื–ื™ื”ื•ื™ ืืจื‘ืข ื ืงื•ื“ื•ืช ืชื•ืจืคื” (CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901) ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ ืฉื‘ื‘ื™ Marvell ืืœื—ื•ื˜ื™ื™ื, ืžื” ืฉืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœื’ืœื™ืฉื” ื‘ืžืื’ืจ. ื”ื”ืชืงืคื” ื™ื›ื•ืœื” ืœื”ืชื‘ืฆืข ืžืจื—ื•ืง ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืžืกื’ืจื•ืช ื‘ืฆื•ืจื” ืžืกื•ื™ืžืช ื‘ืขืช ื—ื™ื‘ื•ืจ ืœื ืงื•ื“ืช ื”ื’ื™ืฉื” ื”ืืœื—ื•ื˜ื™ืช ืฉืœ ื”ืชื•ืงืฃ. ื”ืื™ื•ื ื”ืกื‘ื™ืจ ื‘ื™ื•ืชืจ ื”ื•ื ืžื ื™ืขืช ืฉื™ืจื•ืช ืžืจื—ื•ืง (ืงืจื™ืกืช ืœื™ื‘ื”), ืืš ืœื ื ื™ืชืŸ ืœืฉืœื•ืœ ืืคืฉืจื•ืช ืฉืœ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืžืขืจื›ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”