ืขื“ื›ื•ืŸ ืฉืœ ื—ื‘ื™ืœืช ื”ืื ื˜ื™ ื•ื™ืจื•ืก ื”ื—ื™ื ืžื™ืช ClamAV 0.102.4

ื ื•ืฆืจ ืฉื—ืจื•ืจ ื—ื‘ื™ืœืช ืื ื˜ื™ ื•ื™ืจื•ืก ื‘ื—ื™ื ื Clam AV 0.102.4, ืฉื‘ื” ื‘ื•ื˜ืœื• ืฉืœื•ืฉื” ืคื’ื™ืขื•ืช:

  • CVE-2020-3350 - ื”ื™ื ืžืืคืฉืจืช ืชื•ืงืฃ ืžืงื•ืžื™ ืœืœื ื”ืจืฉืื•ืช ื™ื›ื•ืœ ืœืืจื’ืŸ ืžื—ื™ืงื” ืื• ืชื ื•ืขื” ืฉืœ ืงื‘ืฆื™ื ืฉืจื™ืจื•ืชื™ื™ื ื‘ืžืขืจื›ืช; ืœื“ื•ื’ืžื”, ืืชื” ื™ื›ื•ืœ ืœืžื—ื•ืง /etc/passwd ืžื‘ืœื™ ืœืงื‘ืœ ืืช ื”ื”ืจืฉืื•ืช ื”ื ื“ืจืฉื•ืช. ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืขืœ ื™ื“ื™ ืžืฆื‘ ืžื™ืจื•ืฅ ื”ืžืชืจื—ืฉ ื‘ืขืช ืกืจื™ืงืช ืงื‘ืฆื™ื ื–ื“ื•ื ื™ื™ื ื•ืžืืคืฉืจ ืœืžืฉืชืžืฉ ืขื ื’ื™ืฉืช ืžืขื˜ืคืช ื‘ืžืขืจื›ืช ืœื”ื—ืœื™ืฃ ืืช ืกืคืจื™ื™ืช ื”ื™ืขื“ ืœื”ืกืจื™ืงื” ื‘ืงื™ืฉื•ืจ ืกืžืœื™ ื”ืžืฆื‘ื™ืข ืขืœ ื ืชื™ื‘ ืื—ืจ.

    ืœื“ื•ื’ืžื”, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื™ืฆื•ืจ ืกืคืจื™ื™ื” "/home/user/exploit/" ื•ืœื”ืขืœื•ืช ืœืชื•ื›ื” ืงื•ื‘ืฅ ืขื ื—ืชื™ืžืช ื•ื™ืจื•ืก ื‘ื“ื™ืงื”, ื•ืœื›ื ื•ืช ืืช ื”ืงื•ื‘ืฅ ื”ื–ื” "passwd". ืœืื—ืจ ื”ืคืขืœืช ืชื•ื›ื ืช ืกืจื™ืงืช ื”ื•ื•ื™ืจื•ืกื™ื, ืืš ืœืคื ื™ ืžื—ื™ืงืช ื”ืงื•ื‘ืฅ ื”ื‘ืขื™ื™ืชื™, ื ื™ืชืŸ ืœื”ื—ืœื™ืฃ ืืช ืกืคืจื™ื™ืช ื”-"exploit" ื‘ืงื™ืฉื•ืจ ืกืžืœื™ ื”ืžืฆื‘ื™ืข ืขืœ ืกืคืจื™ื™ืช "/etc", ืžื” ืฉื™ื’ืจื•ื ืœืื ื˜ื™-ื•ื™ืจื•ืก ืœืžื—ื•ืง ืืช ืงื•ื‘ืฅ /etc/passwd. ื”ืคื’ื™ืขื•ืช ืžื•ืคื™ืขื” ืจืง ื›ืืฉืจ ืžืฉืชืžืฉื™ื ื‘- clamscan, clamdscan ื•- clamonacc ืขื ื”ืืคืฉืจื•ืช "--move" ืื• "--remove".

  • CVE-2020-3327, CVE-2020-3481 ื”ืŸ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืžื•ื“ื•ืœื™ื ืœื ื™ืชื•ื— ืืจื›ื™ื•ื ื™ื ื‘ืคื•ืจืžื˜ื™ื ืฉืœ ARJ ื•-EGG, ื”ืžืืคืฉืจื•ืช ืžื ื™ืขืช ืฉื™ืจื•ืช ื‘ืืžืฆืขื•ืช ื”ืขื‘ืจืช ืืจื›ื™ื•ื ื™ื ืžืขื•ืฆื‘ื™ื ื‘ืžื™ื•ื—ื“, ืฉืขื™ื‘ื•ื“ื ื™ื•ื‘ื™ืœ ืœืงืจื™ืกืช ืชื”ืœื™ืš ื”ืกืจื™ืงื” .

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”