ืขื“ื›ื•ื ื™ื ืขื‘ื•ืจ Java SE, MySQL, VirtualBox ื•ืžื•ืฆืจื™ Oracle ืื—ืจื™ื ืขื ืคื’ื™ืขื•ื™ื•ืช ืฉืชื•ืงื ื•

ื—ื‘ืจืช ืื•ืจืงืœ ะพะฟัƒะฑะปะธะบะพะฒะฐะปะฐ ืฉื—ืจื•ืจ ืžืชื•ื›ื ืŸ ืฉืœ ืขื“ื›ื•ื ื™ื ืœืžื•ืฆืจื™ื” (Critical Patch Update), ืฉืžื˜ืจืชื• ื‘ื™ื˜ื•ืœ ื‘ืขื™ื•ืช ื•ืคื’ื™ืขื•ื™ื•ืช ืงืจื™ื˜ื™ื•ืช. ื‘ืขื“ื›ื•ืŸ ื™ื•ืœื™, ืกืš ื”ื›ืœ 319 ื ืงื•ื“ื•ืช ืชื•ืจืคื”.

ื‘ื ื•ืฉืื™ื Java SE 12.0.2, 11.0.4 ื•-8u221 10 ื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ืชื•ืงื ื”. ื ื™ืชืŸ ืœื ืฆืœ 9 ืคื’ื™ืขื•ื™ื•ืช ืžืจื—ื•ืง ืœืœื ืื™ืžื•ืช. ืจืžืช ื”ื—ื•ืžืจื” ื”ื’ื‘ื•ื”ื” ื‘ื™ื•ืชืจ ืฉื”ื•ืงืฆืชื” ื”ื™ื 6.8 (ืคื’ื™ืขื•ืช ื‘-libpng). ืœื ื–ื•ื”ื• ื‘ืขื™ื•ืช ื’ื‘ื•ื”ื•ืช ืื• ืงืจื™ื˜ื™ื•ืช ืฉื™ืืคืฉืจื• ืœืžืฉืชืžืฉ ืœื ืžืื•ืžืช ื“ืจืš ื”ืจืฉืช ืœืกื›ืŸ ื™ื™ืฉื•ืžื™ Java SE.

ื‘ื ื•ืกืฃ ืœื‘ืขื™ื•ืช ื‘-Java SE, ื ื—ืฉืคื• ืคื’ื™ืขื•ื™ื•ืช ื‘ืžื•ืฆืจื™ื ืื—ืจื™ื ืฉืœ Oracle, ื›ื•ืœืœ:

  • 43 ืคื’ื™ืขื•ื™ื•ืช ื‘-MySQL (ืจืžืช ื—ื•ืžืจื” ืžืงืกื™ืžืœื™ืช 9.8, ื”ืžืขื™ื“ื” ืขืœ ื‘ืขื™ื” ืงืจื™ื˜ื™ืช). ื”ื‘ืขื™ื” ื”ื›ื™ ืžืกื•ื›ื ืช
    (CVE-2019-3822) ืงืฉื•ืจ ืœ ื”ืฆืคืช ื—ื™ืฅ ื‘ืงื•ื“ ื ื™ืชื•ื— ื”ื›ื•ืชืจืช NTLM ื‘ืกืคืจื™ื™ืช libcurl, ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื›ื“ื™ ืœืชืงื•ืฃ ืžืจื—ื•ืง ืืช ืฉืจืช MySQL ืขืœ ื™ื“ื™ ืžืฉืชืžืฉ ืœื ืžืื•ืžืช. ื›ืžืขื˜ ื›ืœ ื”ื‘ืขื™ื•ืช ื”ืื—ืจื•ืช ืžื•ืคื™ืขื•ืช ืจืง ืื ื™ืฉ ื’ื™ืฉื” ืžืื•ืžืชืช ืœ-DBMS. ื”ื—ืจื™ื’ ื”ื™ื—ื™ื“ ื”ื•ื ื”ืคื’ื™ืขื•ืช ื‘-Shell: Admin / InnoDB Cluster, ืืฉืจ ืžื•ืงืฆื™ืช ื‘ืจืžืช ื—ื•ืžืจื” ืฉืœ 7.5. ื”ื‘ืขื™ื•ืช ื™ืชื•ืงื ื• ื‘ืžื”ื“ื•ืจื•ืช MySQL Community Server 8.0.17, 5.7.27 ื•-5.6.45.

  • 14 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-VirtualBox, ืžืชื•ื›ื 3 ืžืกื•ื›ื ื™ื ื‘ื™ื•ืชืจ (CVSS ืฆื™ื•ืŸ 8.2 ื•-8.8). ืคื’ื™ืขื•ื™ื•ืช ืžืชื•ืงื ื•ืช ื‘ืขื“ื›ื•ื ื™ื VirtualBox 6.0.10 ื•-5.2.32 (in ื”ืขืจื” ื”ืขื•ื‘ื“ื” ืฉื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ื ืคืชืจื• ืœื ื”ื•ื›ืจื–ื” ืœืคื ื™ ื”ืคืจืกื•ื). ืคืจื˜ื™ื ืื™ื ื ืžืกื•ืคืงื™ื, ืืš, ืื ืœืฉืคื•ื˜ ืœืคื™ ืจืžืช ื”-CVSS, ื‘ื•ื˜ืœื• ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื”ืžืืคืฉืจื•ืช ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืฆื“ ื”ืžืขืจื›ืช ื”ืžืืจื—ืช ืžืกื‘ื™ื‘ืช ื”ืžืขืจื›ืช ื”ืื•ืจื—ืช;
  • 10 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืกื•ืœืืจื™ืก (ืจืžืช ื—ื•ืžืจื” ืžืงืกื™ืžืœื™ืช 9.1 -
    ืคื’ื™ืขื•ืช ื”ืงืฉื•ืจื” ืœ-IPv6 ื‘ืงืจื ืœ (CVE-2019-5597) ื”ืžืืคืฉืจืช ื”ืชืงืคื” ืžืจื—ื•ืง (ืคืจื˜ื™ื ืœื ืžืกื•ืคืงื™ื). ืœืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื™ืฉ ื’ื ืจืžืช ื—ื•ืžืจื” ืงืจื™ื˜ื™ืช ืฉืœ 8.8 - ื‘ืขื™ื•ืช ื”ื ื™ืชื ื•ืช ืœื ื™ืฆื•ืœ ืžืงื•ืžื™ ื‘ืกื‘ื™ื‘ืช ืฉื•ืœื—ืŸ ื”ืขื‘ื•ื“ื” ื”ื ืคื•ืฆื” ื•ื‘ื›ืœื™ ืขื–ืจ ืœืœืงื•ื— ืขื‘ื•ืจ LDAP. ื‘ืขื™ื•ืช ื‘ืจืžืช ื—ื•ืžืจื” ื’ื‘ื•ื”ื” ืž-7 ื›ื•ืœืœื•ืช ื’ื ืคื’ื™ืขื•ื™ื•ืช ื”ื ื™ืชื ื•ืช ืœื ื™ืฆื•ืœ ืžืจื—ื•ืง ื‘ืžื˜ืคืœื™ ICMPv6 ื•-NFS ื‘ืงืจื ืœ ืฉืœ Solaris, ื•ื‘ืขื™ื•ืช ืžืงื•ืžื™ื•ืช ื‘ืžืขืจื›ืช ื”ืงื‘ืฆื™ื ื•ื‘-Gnuplot.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”