ืขื“ื›ื•ืŸ Samba 4.14.2, 4.13.7 ื•-4.12.14 ืขื ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืžืชื•ืงื ื•ืช

ื”ื•ื›ื ื• ืžื”ื“ื•ืจื•ืช ืžืชืงื ื•ืช ืฉืœ ื—ื‘ื™ืœืช Samba 4.14.2, 4.13.7 ื•-4.12.14, ืฉื‘ื”ืŸ ืฉืชื™ ืคื’ื™ืขื•ื™ื•ืช ืžืชื•ืงื ื•ืช:

  • CVE-2020-27840 ื”ื•ื ื”ืฆืคืช ืžืื’ืจ ื”ืžืชืจื—ืฉืช ื‘ืขืช ืขื™ื‘ื•ื“ ืฉืžื•ืช DN (ืฉื ืžื•ื‘ื”ืง) ื‘ืกื’ื ื•ืŸ ืžื™ื•ื—ื“. ืชื•ืงืฃ ืื ื•ื ื™ืžื™ ื™ื›ื•ืœ ืœืงืจื•ืก ืฉืจืช AD DC LDAP ืžื‘ื•ืกืก Samba ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉืช ื—ื™ื‘ื•ืจ ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“. ืžื›ื™ื•ื•ืŸ ืฉื‘ืžื”ืœืš ื”ืžืชืงืคื” ื ื™ืชืŸ ืœืฉืœื•ื˜ ื‘ืื–ื•ืจ ื”ืฉื›ืชื•ื‘, ืœื ื ื™ืชืŸ ืœืฉืœื•ืœ ื”ืฉืœื›ื•ืช ื—ืžื•ืจื•ืช ื™ื•ืชืจ, ื›ืžื• ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœืš ื‘ืฉืจืช, ืืš ืขื“ื™ื™ืŸ ืื™ืŸ ื ื™ืฆื•ืœ ืขื•ื‘ื“. ืžื›ื™ื•ื•ืŸ ืฉืงื•ื“ ื ื™ืชื•ื— ืžื—ืจื•ื–ืช DN ืฉืžื•ื‘ื™ืœ ืœืคื’ื™ืขื•ืช ืžื‘ื•ืฆืข ื‘ืฉืœื‘ ืฉืœืคื ื™ ื‘ื“ื™ืงืช ืคืจืžื˜ืจื™ ื”ืื™ืžื•ืช, ื”ื‘ืขื™ื” ื™ื›ื•ืœื” ืœื”ื™ื•ืช ืžื ื•ืฆืœืช ืขืœ ื™ื“ื™ ืชื•ืงืฃ ืฉืื™ืŸ ืœื• ื—ืฉื‘ื•ืŸ ื‘ืฉืจืช.
  • CVE-2021-20277 ืงืจื™ืืช ืžืื’ืจ ืžื—ื•ืฅ ืœืชื—ื•ื ืžืชืจื—ืฉืช ื›ืืฉืจ ืฉืจืช AD DC LDAP ืžืขื‘ื“ ืžืกื ืŸ ื‘ืขืœ ืžื‘ื ื” ืžื™ื•ื—ื“ ื”ืžื•ื’ื“ืจ ืขืœ ื™ื“ื™ ืžืฉืชืžืฉ. ื”ื‘ืขื™ื” ืขืœื•ืœื” ืœื’ืจื•ื ืœืžื˜ืคืœ ื‘ืฉืจืช ืœืงืจื•ืก ืื• ืœื“ืœื•ืฃ ืชื•ื›ืŸ ืžื–ื™ื›ืจื•ืŸ ื”ืชื”ืœื™ืš.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”