ืขื“ื›ื•ืŸ Ruby 3.0.1 ืขื ืคื’ื™ืขื•ื™ื•ืช ืฉืชื•ืงื ื•

ื ื•ืฆืจื• ืžื”ื“ื•ืจื•ืช ืžืชืงื ื•ืช ืฉืœ ืฉืคืช ื”ืชื›ื ื•ืช Ruby 3.0.1, 2.7.3, 2.6.7 ื•-2.5.9, ืฉื‘ื”ืŸ ื‘ื•ื˜ืœื• ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื”:

  • CVE-2021-28965 ื”ื™ื ื ืงื•ื“ืช ืชื•ืจืคื” ื‘ืžื•ื“ื•ืœ REXML ื”ืžื•ื‘ื ื”, ืืฉืจ ื‘ืขืช ื ื™ืชื•ื— ื•ื”ืกื“ืจื” ืฉืœ ืžืกืžืš XML ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“, ืขืœื•ืœื” ืœื”ื•ื‘ื™ืœ ืœื™ืฆื™ืจืช ืžืกืžืš XML ืฉื’ื•ื™ ืฉื”ืžื‘ื ื” ืฉืœื• ืื™ื ื• ืชื•ืื ืœืžืงื•ืจ. ื—ื•ืžืจืช ื”ืคื’ื™ืขื•ืช ืชืœื•ื™ื” ื‘ืžื™ื“ื” ืจื‘ื” ื‘ื”ืงืฉืจ, ืืš ืœื ื ื™ืชืŸ ืœืฉืœื•ืœ ื”ืชืงืคื•ืช ื ื’ื“ ื™ื™ืฉื•ืžื™ื ืžืกื•ื™ืžื™ื ื”ืžืฉืชืžืฉื™ื ื‘- REXML.
  • CVE-2021-28966 ื”ื™ื ืคื’ื™ืขื•ืช ืกืคืฆื™ืคื™ืช ืœืคืœื˜ืคื•ืจืžืช Windows ื”ืžืืคืฉืจืช ื™ืฆื™ืจื” ืฉืœ ืกืคืจื™ื™ื” ืื• ืงื•ื‘ืฅ ืฉืจื™ืจื•ืชื™ื™ื ื‘ื—ืœืงื™ื ืžืžืขืจื›ืช ื”ืงื‘ืฆื™ื ื”ื ื™ืชื ื™ื ืœื›ืชื™ื‘ื” ืขืœ ื™ื“ื™ ื”ืžืฉืชืžืฉ ืฉื‘ื–ื›ื•ื™ื•ืชื™ื• ืคื•ืขืœ ืชื”ืœื™ืš Ruby. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžืขื™ื‘ื•ื“ ืฉื’ื•ื™ ืฉืœ ื”ืงื™ื“ื•ืžืช ื‘ืฉื™ื˜ืช Dir.mktmpdir, ืฉืื™ื ื” ืฉื•ืœืœืช ื”ื—ืœืคื” ืฉืœ ืงื•ื ืกื˜ืจื•ืงืฆื™ื•ืช ื›ืžื• "..\\". ื›ื“ื™ ืœืชืงื•ืฃ, ื”ืชื”ืœื™ืš ื—ื™ื™ื‘ ืœื”ืฉืชืžืฉ ื‘ื ืชื•ื ื™ื ื—ื™ืฆื•ื ื™ื™ื ื‘ืขืช ื™ืฆื™ืจืช ืขืจืš ื”ืงื™ื“ื•ืžืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”