Exim 4.92.3 ืคื•ืจืกื ืขื ื‘ื™ื˜ื•ืœ ื”ืคื’ื™ืขื•ืช ื”ืงืจื™ื˜ื™ืช ื”ืจื‘ื™ืขื™ืช ื‘ืชื•ืš ืฉื ื”

ื™ืฆื ืœืื•ืจ ืžื”ื“ื•ืจื” ืžื™ื•ื—ื“ืช ืฉืœ ืฉืจืช ื”ื“ื•ืืจ Exim 4.92.3 ืขื ื—ื™ืกื•ืœ ืฉืœ ืื—ืจ ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2019-16928), ื”ืขืœื•ืœ ืœืืคืฉืจ ืœืš ืœื‘ืฆืข ืžืจื—ื•ืง ืืช ื”ืงื•ื“ ืฉืœืš ื‘ืฉืจืช ืขืœ ื™ื“ื™ ื”ืขื‘ืจืช ืžื—ืจื•ื–ืช ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“ ื‘ืคืงื•ื“ื” EHLO. ื”ืคื’ื™ืขื•ืช ืžื•ืคื™ืขื” ื‘ืฉืœื‘ ืฉืœืื—ืจ ืื™ืคื•ืก ื”ื”ืจืฉืื•ืช ื•ื”ื™ื ืžื•ื’ื‘ืœืช ืœื‘ื™ืฆื•ืข ืงื•ื“ ืขื ื–ื›ื•ื™ื•ืช ืฉืœ ืžืฉืชืžืฉ ื—ืกืจ ื”ืจืฉืื•ืช, ื‘ืžืกื’ืจืชื• ืžื‘ื•ืฆืข ืžื˜ืคืœ ื”ื”ื•ื“ืขื•ืช ื”ื ื›ื ืกื•ืช.

ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืจืง ื‘ืขื ืฃ Exim 4.92 (4.92.0, 4.92.1 ื•-4.92.2) ื•ืื™ื ื” ื—ื•ืคืคืช ืœืคื’ื™ืขื•ืช ืฉืชื•ืงื ื” ื‘ืชื—ื™ืœืช ื”ื—ื•ื“ืฉ CVE-2019-15846. ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื”ืฆืคืช ืžืื’ืจ ื‘ืคื•ื ืงืฆื™ื” string_vformat(), ื”ืžื•ื’ื“ืจ ื‘ืงื•ื‘ืฅ string.c. ื”ืคื’ื™ื ื• ืœึฐื ึทืฆึตืœ ืžืืคืฉืจ ืœืš ืœื’ืจื•ื ืœืงืจื™ืกื” ืขืœ ื™ื“ื™ ื”ืขื‘ืจืช ืžื—ืจื•ื–ืช ืืจื•ื›ื” (ืžืกืคืจ ืงื™ืœื•ื‘ื™ื™ื˜ื™ื) ื‘ืคืงื•ื“ื” EHLO, ืืš ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ื‘ืืžืฆืขื•ืช ืคืงื•ื“ื•ืช ืื—ืจื•ืช, ื•ืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘ื” ื’ื ืœืืจื’ื•ืŸ ื‘ื™ืฆื•ืข ืงื•ื“.

ืื™ืŸ ื“ืจื›ื™ื ืœืขืงื™ืคืช ื”ื‘ืขื™ื” ืœื—ืกื™ืžืช ื”ืคื’ื™ืขื•ืช, ืœื›ืŸ ืžื•ืžืœืฅ ืœื›ืœ ื”ืžืฉืชืžืฉื™ื ืœื”ืชืงื™ืŸ ื‘ื“ื—ื™ืคื•ืช ืืช ื”ืขื“ื›ื•ืŸ, ืœื”ื—ื™ืœ ืชื™ืงื•ืŸ ืื• ื”ืงืคื“ ืœื”ืฉืชืžืฉ ื‘ื—ื‘ื™ืœื•ืช ื”ืžืกื•ืคืงื•ืช ืขืœ ื™ื“ื™ ื”ืคืฆื•ืช ื”ืžื›ื™ืœื•ืช ืชื™ืงื•ื ื™ื ืขื‘ื•ืจ ืคื’ื™ืขื•ื™ื•ืช ื ื•ื›ื—ื™ื•ืช. ืคื•ืจืกื ืชื™ืงื•ืŸ ื—ื ืขื‘ื•ืจ ืื•ื‘ื•ื ื˜ื• (ืžืฉืคื™ืข ืจืง ืขืœ ืกื ื™ืฃ 19.04), Arch Linux, FreeBSD, ื“ื‘ื™ืืŸ (ืžืฉืคื™ืข ืจืง ืขืœ Debian 10 Buster) ื• ืคื“ื•ืจื”. RHEL ื•-CentOS ืื™ื ื ืžื•ืฉืคืขื™ื ืžื”ื‘ืขื™ื”, ืžื›ื™ื•ื•ืŸ ืฉ-Exim ืื™ื ื• ื›ืœื•ืœ ื‘ืžืื’ืจ ื”ื—ื‘ื™ืœื•ืช ื”ืกื˜ื ื“ืจื˜ื™ ืฉืœื”ื (ื‘ EPEL7 ืขื“ื›ืŸ ืœืขืช ืขืชื” ืœื). ื‘-SUSE/openSUSE ื”ืคื’ื™ืขื•ืช ืœื ืžื•ืคื™ืขื” ืขืงื‘ ื”ืฉื™ืžื•ืฉ ื‘ืขื ืฃ Exim 4.88.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”