ืคื’ื™ืขื•ื™ื•ืช ืงืจื™ื˜ื™ื•ืช ื‘-Netatalk ื”ืžื•ื‘ื™ืœื•ืช ืœื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง

ื‘-Netatalk, ืฉืจืช ื”ืžื™ื™ืฉื ืืช ืคืจื•ื˜ื•ืงื•ืœื™ ื”ืจืฉืช ืฉืœ AppleTalk ื•-Apple Filing Protocol (AFP), ื–ื•ื”ื• ืฉืฉ ืคื’ื™ืขื•ื™ื•ืช ื”ื ื™ืชื ื•ืช ืœื ื™ืฆื•ืœ ืžืจื—ื•ืง ื”ืžืืคืฉืจื•ืช ืœืš ืœืืจื’ืŸ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœืš ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืžื ื•ืช ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“. Netatalk ืžืฉืžืฉืช ื™ืฆืจื ื™ื ืจื‘ื™ื ืฉืœ ื”ืชืงื ื™ ืื—ืกื•ืŸ (NAS) ื›ื“ื™ ืœืกืคืง ืฉื™ืชื•ืฃ ืงื‘ืฆื™ื ื•ื’ื™ืฉื” ืœืžื“ืคืกื•ืช ืžืžื—ืฉื‘ื™ ืืคืœ, ืœืžืฉืœ, ื ืขืฉื” ื‘ื• ืฉื™ืžื•ืฉ ื‘ืžื›ืฉื™ืจื™ Western Digital (ื”ื‘ืขื™ื” ื ืคืชืจื” ืขืœ ื™ื“ื™ ื”ืกืจืช Netatalk ืžืงื•ืฉื—ืช WD). Netatalk ื ื›ืœืœ ื’ื ื‘ื”ืคืฆื•ืช ืจื‘ื•ืช, ื›ื•ืœืœ OpenWRT (ื”ื•ืกืจ ื”ื—ืœ ืž-OpenWrt 22.03), Debian, Ubuntu, SUSE, Fedora ื•- FreeBSD, ืืš ืื™ื ื• ื‘ืฉื™ืžื•ืฉ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. ื”ื‘ืขื™ื•ืช ื ืคืชืจื• ื‘ืžื”ื“ื•ืจืช Netatalk 3.1.13.

ื‘ืขื™ื•ืช ืฉื–ื•ื”ื•:

  • CVE-2022-0194 โ€“ ื”ืคื•ื ืงืฆื™ื” ad_addcomment() ืœื ื‘ื•ื“ืงืช ื›ืจืื•ื™ ืืช ื’ื•ื“ืœ ื”ื ืชื•ื ื™ื ื”ื—ื™ืฆื•ื ื™ื™ื ืœืคื ื™ ื”ืขืชืงืชื ืœืžืื’ืจ ืงื‘ื•ืข. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืชื•ืงืฃ ืžืจื•ื—ืง ืœื ืžืื•ืžืช ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœื• ืขื ื”ืจืฉืื•ืช ืฉื•ืจืฉ.
  • CVE-2022-23121 - ื˜ื™ืคื•ืœ ืฉื’ื•ื™ ื‘ืฉื’ื™ืื•ืช ื‘ืคื•ื ืงืฆื™ื” parse_entries() ื”ืžืชืจื—ืฉืช ื‘ืขืช ื ื™ืชื•ื— ืขืจื›ื™ AppleDouble. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืชื•ืงืฃ ืžืจื•ื—ืง ืœื ืžืื•ืžืช ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœื• ืขื ื”ืจืฉืื•ืช ืฉื•ืจืฉ.
  • CVE-2022-23122 โ€“ ื”ืคื•ื ืงืฆื™ื” setfilparams() ืœื ื‘ื•ื“ืงืช ื ื›ื•ืŸ ืืช ื’ื•ื“ืœ ื”ื ืชื•ื ื™ื ื”ื—ื™ืฆื•ื ื™ื™ื ืœืคื ื™ ื”ืขืชืงืชื ืœืžืื’ืจ ืงื‘ื•ืข. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืชื•ืงืฃ ืžืจื•ื—ืง ืœื ืžืื•ืžืช ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœื• ืขื ื”ืจืฉืื•ืช ืฉื•ืจืฉ.
  • CVE-2022-23124 ื”ื™ืขื“ืจ ืื™ืžื•ืช ืงืœื˜ ื ื›ื•ืŸ ื‘ืฉื™ื˜ืช get_finderinfo(), ื•ื›ืชื•ืฆืื” ืžื›ืš ืงืจื™ืื” ืžืื–ื•ืจ ืžื—ื•ืฅ ืœืžืื’ืจ ื”ืžื•ืงืฆื”. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืชื•ืงืฃ ืžืจื•ื—ืง ืœื ืžืื•ืžืช ืœื”ื“ืœื™ืฃ ืžื™ื“ืข ืžื–ื™ื›ืจื•ืŸ ื”ืชื”ืœื™ืš. ื‘ืฉื™ืœื•ื‘ ืขื ืคื’ื™ืขื•ื™ื•ืช ืื—ืจื•ืช, ื”ืคื’ื ื™ื›ื•ืœ ืœืฉืžืฉ ื’ื ืœื‘ื™ืฆื•ืข ืงื•ื“ ืขื ื”ืจืฉืื•ืช ืฉื•ืจืฉ.
  • CVE-2022-23125 ื™ืฉ ื‘ื“ื™ืงืช ื’ื•ื“ืœ ื—ืกืจ ื‘ืขืช ื ื™ืชื•ื— ื”ืืœืžื ื˜ "len" ื‘ืคื•ื ืงืฆื™ื” copyapplfile() ืœืคื ื™ ื”ืขืชืงืช ื”ื ืชื•ื ื™ื ืœืžืื’ืจ ืงื‘ื•ืข. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืชื•ืงืฃ ืžืจื•ื—ืง ืœื ืžืื•ืžืช ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœื• ืขื ื”ืจืฉืื•ืช ืฉื•ืจืฉ.
  • CVE-2022-23123 - ื”ื™ืขื“ืจ ืื™ืžื•ืช ื™ื•ืฆื ื‘ืฉื™ื˜ืช getdirparams(), ื•ื›ืชื•ืฆืื” ืžื›ืš ืงืจื™ืื” ืžืื–ื•ืจ ืžื—ื•ืฅ ืœืžืื’ืจ ื”ืžื•ืงืฆื”. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืชื•ืงืฃ ืžืจื•ื—ืง ืœื ืžืื•ืžืช ืœื”ื“ืœื™ืฃ ืžื™ื“ืข ืžื–ื™ื›ืจื•ืŸ ื”ืชื”ืœื™ืš.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”