ืขื“ื›ืŸ ืืช ืจื•ื‘ื™ 2.6.5, 2.5.7 ื•-2.4.8 ืขื ืคื’ื™ืขื•ื™ื•ืช ืžืชื•ืงื ื•ืช

ืžื”ื“ื•ืจื•ืช ืžืชืงื ื•ืช ืฉืœ ืฉืคืช ื”ืชื›ื ื•ืช Ruby ื ื•ืฆืจื• 2.6.5, 2.5.7 ะธ 2.4.8, ืฉืชื™ืงืŸ ืืจื‘ืข ื ืงื•ื“ื•ืช ืชื•ืจืคื”. ื”ืคื’ื™ืขื•ืช ื”ืžืกื•ื›ื ืช ื‘ื™ื•ืชืจ (CVE-2019-16255) ื‘ืกืคืจื™ื™ื” ื”ืกื˜ื ื“ืจื˜ื™ืช ืคึผึธื’ึธื– (lib/shell.rb), ืืฉืจ ื”ื™ื ืžืืคืฉืจืช ืœื‘ืฆืข ื”ื—ืœืคืช ืงื•ื“. ืื ื”ื ืชื•ื ื™ื ื”ืžืชืงื‘ืœื™ื ืžื”ืžืฉืชืžืฉ ืžืขื•ื‘ื“ื™ื ื‘ืืจื’ื•ืžื ื˜ ื”ืจืืฉื•ืŸ ืฉืœ ืฉื™ื˜ื•ืช Shell#[] ืื• Shell#test ื”ืžืฉืžืฉื•ืช ืœื‘ื“ื™ืงืช ื ื•ื›ื—ื•ืช ืฉืœ ืงื•ื‘ืฅ, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื’ืจื•ื ืœืฉื™ื˜ืช Ruby ืฉืจื™ืจื•ืชื™ืช ืœื”ื™ืงืจื.

ื‘ืขื™ื•ืช ืื—ืจื•ืช:

  • CVE-2019-16254 - ื—ืฉื™ืคื” ืœืฉืจืช ื”-http ื”ืžื•ื‘ื ื” WEBrick ื”ืชืงืคืช ืคื™ืฆื•ืœ ืชื’ื•ื‘ืช HTTP (ืื ืชื•ื›ื ื™ืช ืžื›ื ื™ืกื” ื ืชื•ื ื™ื ืœื ืžืื•ืžืชื™ื ืœื›ื•ืชืจืช ืชื’ื•ื‘ืช HTTP, ืื–ื™ ื ื™ืชืŸ ืœืคืฆืœ ืืช ื”ื›ื•ืชืจืช ืขืœ ื™ื“ื™ ื”ื›ื ืกืช ืชื• ื—ื“ืฉ);
  • CVE-2019-15845 ื”ื—ืœืคื” ืฉืœ ืชื• ื”ืืคืก (\0) ืœืืœื• ืฉื ื‘ื“ืงื• ื‘ืืžืฆืขื•ืช ืฉื™ื˜ื•ืช "File.fnmatch" ื•-"File.fnmatch?". ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื ืชื™ื‘ื™ ืงื•ื‘ืฅ ื›ื“ื™ ืœื”ืคืขื™ืœ ืืช ื”ื‘ื“ื™ืงื” ื‘ืื•ืคืŸ ืฉื’ื•ื™;
  • CVE-2019-16201 - ืžื ื™ืขืช ืฉื™ืจื•ืช ื‘ืžื•ื“ื•ืœ ื”ืื™ืžื•ืช ืฉืœ Diges ืขื‘ื•ืจ WEBrick.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”