ืขื“ื›ื•ื ื™ื ืขื‘ื•ืจ Java SE, MySQL, VirtualBox ื•ืžื•ืฆืจื™ Oracle ืื—ืจื™ื ืขื ืคื’ื™ืขื•ื™ื•ืช ืฉืชื•ืงื ื•

ื—ื‘ืจืช ืื•ืจืงืœ ะพะฟัƒะฑะปะธะบะพะฒะฐะปะฐ ืฉื—ืจื•ืจ ืžืชื•ื›ื ืŸ ืฉืœ ืขื“ื›ื•ื ื™ื ืœืžื•ืฆืจื™ื” (Critical Patch Update), ืฉืžื˜ืจืชื• ื‘ื™ื˜ื•ืœ ื‘ืขื™ื•ืช ื•ืคื’ื™ืขื•ื™ื•ืช ืงืจื™ื˜ื™ื•ืช. ื‘ืขื“ื›ื•ืŸ ืืคืจื™ืœ ื–ื” ื‘ื•ื˜ืœ ื‘ืกืš ื”ื›ืœ 297 ื ืงื•ื“ื•ืช ืชื•ืจืคื”.

ื‘ื ื•ืฉืื™ื Java SE 12.0.1, 11.0.3 ื•-8u212 5 ื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ืชื•ืงื ื”. ื ื™ืชืŸ ืœื ืฆืœ ืืช ื›ืœ ื”ืคื’ื™ืขื•ืช ืžืจื—ื•ืง ืœืœื ืื™ืžื•ืช. ืคื’ื™ืขื•ืช ืื—ืช ืกืคืฆื™ืคื™ืช ืœืคืœื˜ืคื•ืจืžืช Windows ืฉื”ื•ืงืฆื” CVSS Score 9.0 (CVE-2019-2699), ื”ืชื•ืื ืจืžืช ืกื›ื ื” ืงืจื™ื˜ื™ืช ื•ืžืืคืฉืจ ืœืžืฉืชืžืฉ ืœื ืžืื•ืžืช ื“ืจืš ื”ืจืฉืช ืœืกื›ืŸ ื™ื™ืฉื•ืžื™ Java SE. ืœืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืชืช-ื”ืžืขืจื›ืช ืœืขื™ื‘ื•ื“ ื’ืจืคื™ 2D ื”ื•ืงืฆื• ืจืžื” 8.1 (CVE-2019-2697, CVE-2019-2698). ื˜ืจื ื ื—ืฉืคื• ืคืจื˜ื™ื.

ื‘ื ื•ืกืฃ ืœื‘ืขื™ื•ืช ื‘-Java SE, ื ื—ืฉืคื• ืคื’ื™ืขื•ื™ื•ืช ื‘ืžื•ืฆืจื™ื ืื—ืจื™ื ืฉืœ Oracle, ื›ื•ืœืœ:

  • 40 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-MySQL (ืจืžืช ื—ื•ืžืจื” ืžืงืกื™ืžืœื™ืช 7.5). ื”ื‘ืขื™ื” ื”ื›ื™ ืžืกื•ื›ื ืช
    (CVE-2019-2632) ืžืฉืคื™ืข ืขืœ ืชืช-ืžืขืจื›ืช ื”ืคืœืื’ื™ืŸ ืœืื™ืžื•ืช. ื”ื‘ืขื™ื•ืช ื™ืชื•ืงื ื• ื‘ืžื”ื“ื•ืจื•ืช MySQL Community Server 8.0.16, 5.7.26 ื•-5.6.44.

  • 12 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-VirtualBox, ืžืชื•ื›ื 7 ื‘ื“ืจื’ื” ืงืจื™ื˜ื™ืช ืฉืœ ืกื›ื ื” (CVSS ืฆื™ื•ืŸ 8.8). ืคื’ื™ืขื•ื™ื•ืช ืžืชื•ืงื ื•ืช ื‘ืขื“ื›ื•ื ื™ื VirtualBox 6.0.6 ื•-5.2.28 (ื‘ ื”ืขืจื” ื”ืขื•ื‘ื“ื” ืฉื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ื ืคืชืจื• ืœื ืคื•ืจืกืžื” ืœืคื ื™ ื”ืคืจืกื•ื). ืคืจื˜ื™ื ืœื ืžืกื•ืคืงื™ื, ืื‘ืœ ืื ืœืฉืคื•ื˜ ืœืคื™ ืจืžืช ื”-CVSS, ื”ืคื’ื™ืขื•ื™ื•ืช ืชื•ืงื ื•, ื”ืคื’ื™ื ื• ื‘ืชื—ืจื•ืช Pwn2Own 2019 ื•ืžืืคืฉืจื™ื ืœืš ืœื‘ืฆืข ืงื•ื“ ื‘ืฆื“ ื”ืžืขืจื›ืช ื”ืžืืจื—ืช ืžืกื‘ื™ื‘ืช ื”ืžืขืจื›ืช ื”ืื•ืจื—ืช.

    ืžืืคืฉืจื™ื ืœืš ืœืชืงื•ืฃ ืืช ื”ืžืขืจื›ืช ื”ืžืืจื—ืช ืžืกื‘ื™ื‘ืช ื”ืื•ืจื—.

  • 3 ืคื’ื™ืขื•ื™ื•ืช ืขืœ Solaris (ื—ื•ืžืจื” ืžืงืกื™ืžืœื™ืช 5.3 - ื‘ืขื™ื•ืช ื‘ืžื ื”ืœ ื”ื—ื‘ื™ืœื•ืช ืฉืœ IPS, SunSSH ื•ืฉื™ืจื•ืช ื ื™ื”ื•ืœ ืžื ืขื•ืœื™ื. ื‘ืขื™ื•ืช ื ืคืชืจื• ื‘ืžื”ื“ื•ืจื”
    Solaris 11.4 SRU8, ืืฉืจ ื’ื ื—ื™ื“ืฉื” ืืช ื”ืชืžื™ื›ื” ื‘ืกืคืจื™ื•ืช UCB (libucb, librpcsoc, libdbm, libtermcap, libcurses) ื•ืฉื™ืจื•ืช fc-fabric, ื’ืจืกืื•ืช ื—ื‘ื™ืœื” ืžืขื•ื“ื›ื ื•ืช
    ibus 1.5.19, NTP 4.2.8p12,
    Firefox 60.6.0esr,
    ื›ืจื™ื›ื” 9.11.6
    OpenSSL 1.0.2r,
    MySQL 5.6.43 ื•-5.7.25,
    libxml2 2.9.9,
    libxslt 1.1.33,
    Wireshark 2.6.7,
    ncurses 6.1.0.20190105,
    Apache httpd 2.4.38,
    perl 5.22.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”