ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืžืกื•ื›ื ื•ืช ื‘-QEMU, Node.js, Grafana ื•ืื ื“ืจื•ืื™ื“

ืžืกืคืจ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื–ื•ื”ื• ืœืื—ืจื•ื ื”:

  • ืคื’ื™ืขื•ืช (CVE-2020-13765) ื‘-QEMU, ืฉืขืœื•ืœ ืœื’ืจื•ื ืœืงื•ื“ ืœื”ืชื‘ืฆืข ืขื ื”ืจืฉืื•ืช ืชื”ืœื™ืš QEMU ื‘ืฆื“ ื”ืžืืจื— ื›ืืฉืจ ืชืžื•ื ืช ืœื™ื‘ื” ืžื•ืชืืžืช ืื™ืฉื™ืช ื ื˜ืขื ืช ืœืื•ืจื—. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื”ืฆืคืช ืžืื’ืจ ื‘ืงื•ื“ ื”ืขืชืงืช ื”-ROM ื‘ืžื”ืœืš ืืชื—ื•ืœ ื”ืžืขืจื›ืช ื•ืžืชืจื—ืฉืช ื›ืืฉืจ ื”ืชื•ื›ืŸ ืฉืœ ืชืžื•ื ืช ืœื™ื‘ื” ืฉืœ 32 ืกื™ื‘ื™ื•ืช ื ื˜ืขืŸ ืœื–ื™ื›ืจื•ืŸ. ื”ืชื™ืงื•ืŸ ื–ืžื™ืŸ ื›ืจื’ืข ืจืง ื‘ื˜ื•ืคืก ืชื™ืงื•ืŸ.
  • ืืจื‘ืข ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-Node.js. ืคื’ื™ืขื•ื™ื•ืช ื—ื•ืกืœื• ื‘ืžื”ื“ื•ืจื•ืช 14.4.0, 10.21.0 ื•-12.18.0.
    • CVE-2020-8172 - ืžืืคืฉืจ ืœืขืงื•ืฃ ืื™ืžื•ืช ืื™ืฉื•ืจ ืžืืจื— ื‘ืขืช ืฉื™ืžื•ืฉ ื—ื•ื–ืจ ื‘ื”ืคืขืœืช TLS.
    • CVE-2020-8174 - ืžืืคืฉืจ ืคื•ื˜ื ืฆื™ืืœ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืžืขืจื›ืช ืขืงื‘ ื”ืฆืคืช ืžืื’ืจ ื‘ืคื•ื ืงืฆื™ื•ืช napi_get_value_string_*() ื”ืžืชืจื—ืฉื•ืช ื‘ืžื”ืœืš ืงืจื™ืื•ืช ืžืกื•ื™ืžื•ืช ืืœ N-API (C API ืœื›ืชื™ื‘ืช ื”ืจื—ื‘ื•ืช ืžืงื•ืจื™ื•ืช).
    • CVE-2020-10531 ื”ื•ื ื”ืฆืคืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘-ICU (ืจื›ื™ื‘ื™ื ื‘ื™ื ืœืื•ืžื™ื™ื ืขื‘ื•ืจ Unicode) ืขื‘ื•ืจ C/C++ ืฉื™ื›ื•ืœ ืœื”ื•ื‘ื™ืœ ืœื’ืœื™ืฉื” ื‘ืžืื’ืจ ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืคื•ื ืงืฆื™ื” UnicodeString::doAppend().
    • CVE-2020-11080 - ืžืืคืฉืจ ืžื ื™ืขืช ืฉื™ืจื•ืช (100% ืขื•ืžืก ืžืขื‘ื“) ื‘ืืžืฆืขื•ืช ืฉื™ื“ื•ืจ ืฉืœ ืžืกื’ืจื•ืช "SETTINGS" ื’ื“ื•ืœื•ืช ื‘ืขืช ื—ื™ื‘ื•ืจ ื‘ืืžืฆืขื•ืช HTTP/2.
  • ืคื’ื™ืขื•ืช ื‘ืคืœื˜ืคื•ืจืžืช ื”ื“ืžื™ื” ืฉืœ ืžื“ื“ื™ื ืื™ื ื˜ืจืืงื˜ื™ื‘ื™ื™ื Grafana, ื”ืžืฉืžืฉืช ืœื‘ื ื™ื™ืช ื’ืจืคื™ ื ื™ื˜ื•ืจ ื—ื–ื•ืชื™ื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ ืžืงื•ืจื•ืช ื ืชื•ื ื™ื ืฉื•ื ื™ื. ืฉื’ื™ืื” ื‘ืงื•ื“ ืœืขื‘ื•ื“ื” ืขื ืื•ื•ื˜ืจื™ื ืžืืคืฉืจืช ืœืš ืœื™ื–ื•ื ืฉืœื™ื—ืช ื‘ืงืฉืช HTTP ืž-Grafana ืœื›ืœ ื›ืชื•ื‘ืช URL ืžื‘ืœื™ ืœื”ืขื‘ื™ืจ ืื™ืžื•ืช ื•ืœืจืื•ืช ืืช ื”ืชื•ืฆืื” ืฉืœ ื‘ืงืฉื” ื–ื•. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืชื›ื•ื ื” ื–ื•, ืœืžืฉืœ, ื›ื“ื™ ืœื—ืงื•ืจ ืืช ื”ืจืฉืช ื”ืคื ื™ืžื™ืช ืฉืœ ื—ื‘ืจื•ืช ื”ืžืฉืชืžืฉื•ืช ื‘ื’ืจืคืื ื”. ื‘ึผึฐืขึธื™ึธื” ื—ื•ืกืœื• ื‘ื ื•ืฉืื™ื
    ื’ืจืคื ื” 6.7.4 ื•-7.0.2. ื›ืคืชืจื•ืŸ ืื‘ื˜ื—ื”, ืžื•ืžืœืฅ ืœื”ื’ื‘ื™ืœ ืืช ื”ื’ื™ืฉื” ืœื›ืชื•ื‘ืช ื”-URL "/avatar/*" ื‘ืฉืจืช ืฉื‘ื• ืคื•ืขืœ Grafana.

  • ื™ืฆื ืœืื•ืจ ืกื˜ ืชื™ืงื•ื ื™ ืื‘ื˜ื—ื” ืขื‘ื•ืจ ืื ื“ืจื•ืื™ื“ ื‘ื—ื•ื“ืฉ ื™ื•ื ื™, ื”ืžืชืงืŸ 34 ืคืจืฆื•ืช. ืœืืจื‘ืข ื‘ืขื™ื•ืช ื”ื•ืงืฆืชื” ืจืžืช ื—ื•ืžืจื” ืงืจื™ื˜ื™ืช: ืฉืชื™ ืคื’ื™ืขื•ื™ื•ืช (CVE-2019-14073, CVE-2019-14080) ื‘ืจื›ื™ื‘ื™ Qualcomm ืงื ื™ื™ื ื™ื™ื) ื•ืฉืชื™ ืคื’ื™ืขื•ื™ื•ืช ื‘ืžืขืจื›ืช ื”ืžืืคืฉืจื•ืช ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืขื™ื‘ื•ื“ ื ืชื•ื ื™ื ื—ื™ืฆื•ื ื™ื™ื ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“ (CVE-2020 -0117 - ืžืกืคืจ ืฉืœื ื”ืฆืคื” ื‘ืขืจื™ืžืช Bluetooth, CVE-2020-8597 - ื’ืœื™ืฉืช EAP ื‘-pppd).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”