ื ื™ืชื•ื— ืื‘ื˜ื—ื” ืฉืœ ื—ื‘ื™ืœืช BusyBox ื—ื•ืฉืฃ 14 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืงืœื•ืช

ื—ื•ืงืจื™ื ืž-Cleroty ื•-JFrog ืคืจืกืžื• ืชื•ืฆืื•ืช ืฉืœ ื‘ื™ืงื•ืจืช ืื‘ื˜ื—ื” ืฉืœ ื—ื‘ื™ืœืช BusyBox, ื‘ืฉื™ืžื•ืฉ ื ืจื—ื‘ ื‘ื”ืชืงื ื™ื ืžืฉื•ื‘ืฆื™ื ื•ืžืฆื™ืขื” ืงื‘ื•ืฆื” ืฉืœ ื›ืœื™ ืขื–ืจ ืกื˜ื ื“ืจื˜ื™ื™ื ืฉืœ UNIX ืืจื•ื–ื™ื ื‘ืงื•ื‘ืฅ ื”ืคืขืœื” ื™ื—ื™ื“. ื‘ืžื”ืœืš ื”ืกืจื™ืงื” ื–ื•ื”ื• 14 ื ืงื•ื“ื•ืช ืชื•ืจืคื”, ืฉื›ื‘ืจ ืชื•ืงื ื• ื‘ืžื”ื“ื•ืจืช ืื•ื’ื•ืกื˜ ืฉืœ BusyBox 1.34. ื›ืžืขื˜ ื›ืœ ื”ื‘ืขื™ื•ืช ืื™ื ืŸ ืžื–ื™ืงื•ืช ื•ืžืคื•ืงืคืงื•ืช ืžื ืงื•ื“ืช ืžื‘ื˜ ืฉืœ ืฉื™ืžื•ืฉ ื‘ื”ืชืงืคื•ืช ืืžื™ืชื™ื•ืช, ืžื›ื™ื•ื•ืŸ ืฉื”ืŸ ื“ื•ืจืฉื•ืช ื”ืคืขืœืช ื›ืœื™ ืขื–ืจ ืขื ื˜ื™ืขื•ื ื™ื ืฉืžืชืงื‘ืœื™ื ืžื‘ื—ื•ืฅ.

ืคื’ื™ืขื•ืช ื ืคืจื“ืช ื”ื™ื CVE-2021-42374, ื”ืžืืคืฉืจืช ืœืš ืœื’ืจื•ื ืœืžื ื™ืขืช ืฉื™ืจื•ืช ื‘ืขืช ืขื™ื‘ื•ื“ ืงื•ื‘ืฅ ื“ื—ื•ืก ืฉืชื•ื›ื ืŸ ื‘ืžื™ื•ื—ื“ ืขื ื›ืœื™ ื”ืฉื™ืจื•ืช unlzma, ื•ื‘ืžืงืจื” ืฉืœ ื”ืจื›ื‘ื” ืขื ืืคืฉืจื•ื™ื•ืช CONFIG_FEATURE_SEAMLESS_LZMA, ื’ื ืขื ื›ืœ ืจื›ื™ื‘ื™ BusyBox ืื—ืจื™ื, ื›ื•ืœืœ tar, unzip, rpm, dpkg, lzma ื•-man .

ื ืงื•ื“ื•ืช ืชื•ืจืคื” CVE-2021-42373, CVE-2021-42375, CVE-2021-42376 ื•-CVE-2021-42377 ืขืœื•ืœื•ืช ืœื’ืจื•ื ืœืžื ื™ืขืช ืฉื™ืจื•ืช, ืืš ืžื—ื™ื™ื‘ื•ืช ื”ืคืขืœืช ื›ืœื™ ื”ืฉื™ืจื•ืช 'ืื™ืฉ, ืืฉ ื•ื”ืฉืชืง' ืขื ืคืจืžื˜ืจื™ื ืฉืฆื•ื™ื ื• ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ. ืคื’ื™ืขื•ื™ื•ืช CVE-2021-42378 ืขื“ CVE-2021-42386 ืžืฉืคื™ืขื•ืช ืขืœ ื›ืœื™ ื”ืฉื™ืจื•ืช awk ื•ืขืœื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“, ืืš ืœืฉื ื›ืš ื”ืชื•ืงืฃ ืฆืจื™ืš ืœื•ื•ื“ื ืฉื“ืคื•ืก ืžืกื•ื™ื ืžื‘ื•ืฆืข ื‘-awk (ื™ืฉ ืฆื•ืจืš ืœื”ืคืขื™ืœ awk ืขื ื”ื ืชื•ื ื™ื ืฉื”ืชืงื‘ืœื• ืžื”ืชื•ืงืฃ).

ื‘ื ื•ืกืฃ, ืืชื” ื™ื›ื•ืœ ื’ื ืœืฆื™ื™ืŸ ืคื’ื™ืขื•ืช (CVE-2021-43523) ื‘ืกืคืจื™ื•ืช uclibc ื•-uclibc-ng, ื‘ืฉืœ ื”ืขื•ื‘ื“ื” ืฉื›ืืฉืจ ื ื™ื’ืฉ ืœืคื•ื ืงืฆื™ื•ืช gethostbyname(), getaddriinfo(), gethostbyaddr() ื•-getnameinfo(), ืฉื ื”ื“ื•ืžื™ื™ืŸ ืœื ื ื‘ื“ืง ื•ื”ืฉื ื”ื ื™ืงื” ืžื•ื—ื–ืจ ืขืœ ื™ื“ื™ ืฉืจืช ื”-DNS. ืœื“ื•ื’ืžื”, ื‘ืชื’ื•ื‘ื” ืœื‘ืงืฉืช ืคืชืจื•ืŸ ืžืกื•ื™ืžืช, ืฉืจืช DNS ื”ื ืฉืœื˜ ืขืœ ื™ื“ื™ ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ื—ื–ื™ืจ ืžืืจื—ื™ื ื›ืžื• " alert(โ€˜xssโ€™) .attacker.com" ื•ื”ื ื™ื•ื—ื–ืจื• ืœืœื ืฉื™ื ื•ื™ ืœืชื•ื›ื ื™ืช ื›ืœืฉื”ื™ ืฉื‘ืœื™ ื ื™ืงื•ื™ ืชื•ื›ืœ ืœื”ืฆื™ื’ ืื•ืชืŸ ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜. ื”ื‘ืขื™ื” ืชื•ืงื ื” ื‘ืžื”ื“ื•ืจืช uclibc-ng 1.0.39 ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ืงื•ื“ ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ื ื›ื•ื ื•ืช ืฉืžื•ืช ื”ื“ื•ืžื™ื™ืŸ ืฉื”ื•ื—ื–ืจื•, ืžื™ื•ืฉื ื‘ื“ื•ืžื” ืœ-Glibc.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”