ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช ื‘-ProFTPd

ื‘ืฉืจืช ftp ProFTPD ืžื–ื•ื”ื” ืคื’ื™ืขื•ืช ืžืกื•ื›ื ืช (CVE-2019-12815), ื”ืžืืคืฉืจ ืœืš ืœื”ืขืชื™ืง ืงื‘ืฆื™ื ื‘ืชื•ืš ื”ืฉืจืช ืœืœื ืื™ืžื•ืช ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื•ืช "site cpfr" ื•-"site cpto". ื‘ึผึฐืขึธื™ึธื” ืฉื”ื•ืงืฆื” ืจืžืช ืกื›ื ื” 9.8 ืžืชื•ืš 10, ืžื›ื™ื•ื•ืŸ ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื” ื›ื“ื™ ืœืืจื’ืŸ ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง ืชื•ืš ืžืชืŸ ื’ื™ืฉื” ืื ื•ื ื™ืžื™ืช ืœ-FTP.

ืคื’ื™ืขื•ืช ื’ืจื ืœ ื‘ื“ื™ืงื” ืฉื’ื•ื™ื” ืฉืœ ื”ื’ื‘ืœื•ืช ื’ื™ืฉื” ืœืงืจื™ืื” ื•ื›ืชื™ื‘ื” ืฉืœ ื ืชื•ื ื™ื (Limit READ ื•-Limit WRITE) ื‘ืžื•ื“ื•ืœ mod_copy, ื”ืžืฉืžืฉ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื•ืžื•ืคืขืœ ื‘ื—ื‘ื™ืœื•ืช proftpd ืขื‘ื•ืจ ืจื•ื‘ ื”ื”ืคืฆื•ืช. ืจืื•ื™ ืœืฆื™ื™ืŸ ืฉื”ืคื’ื™ืขื•ืช ื”ื™ื ืชื•ืฆืื” ืฉืœ ื‘ืขื™ื” ื“ื•ืžื” ืฉืœื ื ืคืชืจื” ืœื—ืœื•ื˜ื™ืŸ, ืžื–ื•ื”ื” ื‘ืฉื ืช 2015, ืฉืขื‘ื•ืจื” ื–ื•ื”ื• ื›ืขืช ื•ืงื˜ื•ืจื™ ืชืงื™ืคื” ื—ื“ืฉื™ื. ื™ืชืจ ืขืœ ื›ืŸ, ื”ื‘ืขื™ื” ื“ื•ื•ื—ื” ืœืžืคืชื—ื™ื ืขื•ื“ ื‘ืกืคื˜ืžื‘ืจ ื‘ืฉื ื” ืฉืขื‘ืจื”, ืื‘ืœ ื”ืชื™ืงื•ืŸ ื”ื™ื” ืžื•ึผื›ึธืŸ ืจืง ืœืคื ื™ ื›ืžื” ื™ืžื™ื.

ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ื’ื ื‘ืžื”ื“ื•ืจื•ืช ื”ืขื“ื›ื ื™ื•ืช ื”ืื—ืจื•ื ื•ืช ืฉืœ ProFTPd 1.3.6 ื•-1.3.5d. ื”ืชื™ืงื•ืŸ ื–ืžื™ืŸ ื› ืชื™ืงื•ืŸ. ื›ืคืชืจื•ืŸ ืื‘ื˜ื—ื”, ืžื•ืžืœืฅ ืœื”ืฉื‘ื™ืช ืืช mod_copy ื‘ืชืฆื•ืจื”. ื”ืคื’ื™ืขื•ืช ืชื•ืงื ื” ืขื“ ื›ื” ืจืง ื‘ ืคื“ื•ืจื” ื•ื ืฉืืจ ืœื ืžืชื•ืงืŸ ื“ื‘ื™ืืŸ, SUSE/openSUSE, ืื•ื‘ื•ื ื˜ื•, FreeBSD, EPEL-7 (ProFTPD ืื™ื ื• ืžืกื•ืคืง ื‘ืžืื’ืจ RHEL ื”ืจืืฉื™, ื•ื”ื—ื‘ื™ืœื” ืž-EPEL-6 ืื™ื ื” ืžื•ืฉืคืขืช ืžื”ื‘ืขื™ื” ืžื›ื™ื•ื•ืŸ ืฉื”ื™ื ืื™ื ื” ื›ื•ืœืœืช mod_copy).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”