ืขื“ื›ื•ืŸ Exim 4.94.2 ืขื ืชื™ืงื•ื ื™ื ืขื‘ื•ืจ 10 ืคื’ื™ืขื•ื™ื•ืช ื”ื ื™ืชื ื•ืช ืœื ื™ืฆื•ืœ ืžืจื—ื•ืง

ืฉื—ืจื•ืจื• ืฉืœ ืฉืจืช ื”ื“ื•ืืจ Exim 4.94.2 ืคื•ืจืกื ืขื ื‘ื™ื˜ื•ืœ 21 ืคืจืฆื•ืช (CVE-2020-28007-CVE-2020-28026, CVE-2021-27216), ืฉื–ื•ื”ื• ืขืœ ื™ื“ื™ Qualys ื•ื”ื•ืฆื’ื• ืชื—ืช ืฉื ื”ืงื•ื“ 21 ืฆื™ืคื•ืจื ื™ื™ื. ื ื™ืชืŸ ืœื ืฆืœ 10 ื‘ืขื™ื•ืช ืžืจื—ื•ืง (ื›ื•ืœืœ ื‘ื™ืฆื•ืข ืงื•ื“ ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ) ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืคืงื•ื“ื•ืช SMTP ื‘ืขืช ืื™ื ื˜ืจืืงืฆื™ื” ืขื ื”ืฉืจืช.

ื›ืœ ื”ื’ืจืกืื•ืช ืฉืœ Exim, ืฉื”ื”ื™ืกื˜ื•ืจื™ื” ืฉืœื” ืžืœื•ื•ื” ื‘-Git ืžืื– 2004, ืžื•ืฉืคืขื•ืช ืžื”ื‘ืขื™ื”. ืื‘ื•ืช ื˜ื™ืคื•ืก ืขื•ื‘ื“ื™ื ืฉืœ ื ื™ืฆื•ืœ ื”ื•ื›ื ื• ืขื‘ื•ืจ 4 ืคื’ื™ืขื•ื™ื•ืช ืžืงื•ืžื™ื•ืช ื•-3 ื‘ืขื™ื•ืช ืžืจื•ื—ืงื•ืช. ื ื™ืฆื•ืœ ืฉืœ ืคื’ื™ืขื•ื™ื•ืช ืžืงื•ืžื™ื•ืช (CVE-2020-28007, CVE-2020-28008, CVE-2020-28015, CVE-2020-28012) ืžืืคืฉืจื™ื ืœืš ืœื”ืขืœื•ืช ืืช ื”ื”ืจืฉืื•ืช ืฉืœืš ืœืžืฉืชืžืฉ ื”ืฉื•ืจืฉ. ืฉืชื™ ื‘ืขื™ื•ืช ืžืจื•ื—ืงื•ืช (CVE-2020-28020, CVE-2020-28018) ืžืืคืฉืจื•ืช ื‘ื™ืฆื•ืข ืงื•ื“ ืœืœื ืื™ืžื•ืช ื›ืžืฉืชืžืฉ Exim (ืœืื—ืจ ืžื›ืŸ ืชื•ื›ืœ ืœืงื‘ืœ ื’ื™ืฉืช ืฉื•ืจืฉ ืขืœ ื™ื“ื™ ื ื™ืฆื•ืœ ืื—ืช ืžื”ื—ื•ืœืฉื•ืช ื”ืžืงื•ืžื™ื•ืช).

ื”ืคื’ื™ืขื•ืช ืฉืœ CVE-2020-28021 ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง ืžื™ื™ื“ื™ ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ, ืืš ื“ื•ืจืฉืช ื’ื™ืฉื” ืžืื•ืžืชืช (ื”ืžืฉืชืžืฉ ื—ื™ื™ื‘ ืœื™ืฆื•ืจ ื”ืคืขืœื” ืžืื•ืžืชืช, ืฉืœืื—ืจื™ื” ื™ื•ื›ืœ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืคืจืžื˜ืจ AUTH ื‘ืคืงื•ื“ื” MAIL FROM). ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžื”ืขื•ื‘ื“ื” ืฉืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืฉื™ื’ ื”ื—ืœืคืช ืžื—ืจื•ื–ืช ื‘ื›ื•ืชืจืช ืฉืœ ืงื•ื‘ืฅ ืกืœื•ืœืจ ืขืœ ื™ื“ื™ ื›ืชื™ื‘ืช ื”ืขืจืš authenticated_sender ืžื‘ืœื™ ืœื‘ืจื•ื— ื›ืจืื•ื™ ืœืชื•ื•ื™ื ืžื™ื•ื—ื“ื™ื (ืœื“ื•ื’ืžื”, ืขืœ ื™ื“ื™ ื”ืขื‘ืจืช ื”ืคืงื•ื“ื” "MAIL FROM:<> AUTH=Raven+0AReyes โ€).

ื‘ื ื•ืกืฃ, ื™ืฉ ืœืฆื™ื™ืŸ ืฉืคื’ื™ืขื•ืช ืžืจื—ื•ืง ื ื•ืกืคืช, CVE-2020-28017, ื ื™ืชื ืช ืœื ื™ืฆื•ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“ ืขื ื–ื›ื•ื™ื•ืช ืžืฉืชืžืฉ "exim" ืœืœื ืื™ืžื•ืช, ืืš ื“ื•ืจืฉืช ื™ื•ืชืจ ืž-25 GB ืฉืœ ื–ื™ื›ืจื•ืŸ. ืขื‘ื•ืจ 13 ื ืงื•ื“ื•ืช ื”ืชื•ืจืคื” ื”ื ื•ืชืจื•ืช, ื™ืชื›ืŸ ื•ืืคืฉืจ ืœื”ื›ื™ืŸ ื’ื ื ื™ืฆื•ืœ, ืืš ืขื‘ื•ื“ื” ื‘ื›ื™ื•ื•ืŸ ื–ื” ื˜ืจื ื‘ื•ืฆืขื”.

ืžืคืชื—ื™ Exim ืงื™ื‘ืœื• ื”ื•ื“ืขื” ืขืœ ื”ื‘ืขื™ื•ืช ืขื•ื“ ื‘ืื•ืงื˜ื•ื‘ืจ ื‘ืฉื ื” ืฉืขื‘ืจื” ื•ื‘ื™ืœื• ื™ื•ืชืจ ืž-6 ื—ื•ื“ืฉื™ื ื‘ืคื™ืชื•ื— ืชื™ืงื•ื ื™ื. ืžื•ืžืœืฅ ืœื›ืœ ื”ืžื ื”ืœื™ื ืœืขื“ื›ืŸ ื‘ื“ื—ื™ืคื•ืช ืืช Exim ื‘ืฉืจืชื™ ื”ื“ื•ืืจ ืฉืœื”ื ืœื’ืจืกื” 4.94.2. ื›ืœ ื”ื’ืจืกืื•ืช ืฉืœ Exim ืœืคื ื™ ืฉื—ืจื•ืจ 4.94.2 ื”ื•ื›ืจื–ื• ืžื™ื•ืฉื ื•ืช. ืคืจืกื•ื ื”ื’ืจืกื” ื”ื—ื“ืฉื” ืชื•ืื ืขื ื”ืคืฆื•ืช ืฉืคืจืกืžื• ื‘ื• ื–ืžื ื™ืช ืขื“ื›ื•ื ื™ ื—ื‘ื™ืœื”: ืื•ื‘ื•ื ื˜ื•, Arch Linux, FreeBSD, Debian, SUSE ื•-Fedora. RHEL ื•-CentOS ืื™ื ื ืžื•ืฉืคืขื™ื ืžื”ื‘ืขื™ื”, ืžื›ื™ื•ื•ืŸ ืฉ-Exim ืื™ื ื• ื›ืœื•ืœ ื‘ืžืื’ืจ ื”ื—ื‘ื™ืœื•ืช ื”ืกื˜ื ื“ืจื˜ื™ ืฉืœื”ื (ืœ-EPEL ืขื“ื™ื™ืŸ ืื™ืŸ ืขื“ื›ื•ืŸ).

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื”ื•ืกืจื•:

  • CVE-2020-28017: ื’ืœื™ืฉืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘ืคื•ื ืงืฆื™ื” receive_add_recipient();
  • CVE-2020-28020: ื’ืœื™ืฉืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘ืคื•ื ืงืฆื™ื” receive_msg();
  • CVE-2020-28023: ืงืจื™ืื” ืžื—ื•ืฅ ืœืชื—ื•ื ื‘-smtp_setup_msg();
  • CVE-2020-28021: ื”ื—ืœืคืช ืฉื•ืจื” ื—ื“ืฉื” ื‘ื›ื•ืชืจืช ืงื•ื‘ืฅ ืกืœื™ืœ;
  • CVE-2020-28022: ื›ืชื•ื‘ ื•ืงืจืื” ื‘ืื–ื•ืจ ืžื—ื•ืฅ ืœืžืื’ืจ ื”ืžื•ืงืฆื” ื‘ืคื•ื ืงืฆื™ื” extract_option();
  • CVE-2020-28026: ื—ื™ืชื•ืš ืžื—ืจื•ื–ืช ื•ื”ื—ืœืคื” ื‘-spool_read_header();
  • CVE-2020-28019: ืงืจื™ืกื” ื‘ืขืช ืื™ืคื•ืก ืžืฆื‘ื™ืข ืคื•ื ืงืฆื™ื” ืœืื—ืจ ืžืชืจื—ืฉืช ืฉื’ื™ืืช BDAT;
  • CVE-2020-28024: ืชืช-ื–ืจื™ืžืช ืžืื’ืจ ื‘ืคื•ื ืงืฆื™ื” smtp_ungetc();
  • CVE-2020-28018: ืฉื™ืžื•ืฉ ื‘ื’ื™ืฉื” ืœืžืื’ืจ ืœืœื ืชืฉืœื•ื ื‘-tls-openssl.c
  • CVE-2020-28025: ืงืจื™ืื” ืžื—ื•ืฅ ืœืชื—ื•ื ื‘ืคื•ื ืงืฆื™ื” pdkim_finish_bodyhash() .

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืžืงื•ืžื™ื•ืช:

  • CVE-2020-28007: ื”ืชืงืคืช ืงื™ืฉื•ืจ ืกืžืœื™ืช ื‘ืกืคืจื™ื™ืช ื™ื•ืžืŸ Exim;
  • CVE-2020-28008: ื”ืชืงืคื•ืช ืกืคืจื™ื™ืช Spool;
  • CVE-2020-28014: ื™ืฆื™ืจืช ืงื‘ืฆื™ื ืฉืจื™ืจื•ืชื™ืช;
  • CVE-2021-27216: ืžื—ื™ืงืช ืงื‘ืฆื™ื ืฉืจื™ืจื•ืชื™ืช;
  • CVE-2020-28011: ื’ืœื™ืฉืช ืžืื’ืจ ื‘-queue_run();
  • CVE-2020-28010: ื›ืชื•ื‘ ืžื—ื•ืฅ ืœืชื—ื•ื ื‘-main();
  • CVE-2020-28013: ื’ืœื™ืฉืช ืžืื’ืจ ื‘ืคื•ื ืงืฆื™ื” parse_fix_phrase();
  • CVE-2020-28016: ื›ืชื•ื‘ ืžื—ื•ืฅ ืœืชื—ื•ื ื‘-parse_fix_phrase();
  • CVE-2020-28015: ื”ื—ืœืคืช ืฉื•ืจื” ื—ื“ืฉื” ื‘ื›ื•ืชืจืช ืงื•ื‘ืฅ ืกืœื™ืœ;
  • CVE-2020-28012: ื—ืกืจ ื“ื’ืœ ืงืจื•ื‘ ืœ-exec ืขื‘ื•ืจ ืฆื™ื ื•ืจ ืžื™ื•ื—ืก ืœืœื ืฉื;
  • CVE-2020-28009: ื’ืœื™ืฉืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘ืคื•ื ืงืฆื™ื” get_stdinput()โ€Ž.



ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”