ืžื”ื“ื•ืจืช ืฉืจืช http ืฉืœ Apache 2.4.41 ืขื ืคื’ื™ืขื•ื™ื•ืช ืžืชื•ืงื ื•ืช

ื™ืฆื ืœืื•ืจ ืžื”ื“ื•ืจื” ืฉืœ ืฉืจืช ื”-HTTP ืฉืœ Apache 2.4.41 (ื”ื’ืจืกื” 2.4.40 ื ื“ื—ืชื”), ืฉื”ืฆื™ื’ื” 23 ืฉื™ื ื•ื™ื™ื ื•ื—ื•ืกืœื• 6 ื ืงื•ื“ื•ืช ืชื•ืจืคื”:

  • CVE-2019-10081 ื”ื™ื ื‘ืขื™ื” ื‘-mod_http2 ืฉืขืœื•ืœื” ืœื”ื•ื‘ื™ืœ ืœืคื’ื™ืขื” ื‘ื–ื™ื›ืจื•ืŸ ื‘ืขืช โ€‹โ€‹ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ื“ื—ื™ืคื” ื‘ืฉืœื‘ ืžื•ืงื“ื ืžืื•ื“. ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ื”ื’ื“ืจื” "H2PushResource", ื ื™ืชืŸ ืœื”ื—ืœื™ืฃ ื–ื™ื›ืจื•ืŸ ื‘ืžืื’ืจ ืขื™ื‘ื•ื“ ื”ื‘ืงืฉื•ืช, ืืš ื”ื‘ืขื™ื” ืžื•ื’ื‘ืœืช ืœืงืจื™ืกื” ืžื›ื™ื•ื•ืŸ ืฉื”ื ืชื•ื ื™ื ื”ื ื›ืชื‘ื™ื ืื™ื ื ืžื‘ื•ืกืกื™ื ืขืœ ืžื™ื“ืข ืฉื”ืชืงื‘ืœ ืžื”ืœืงื•ื—;
  • CVE-2019-9517 - ื—ืฉื™ืคื” ืื—ืจื•ื ื” ื”ื›ืจื™ื– ืคื’ื™ืขื•ื™ื•ืช DoS ื‘ื”ื˜ืžืขื•ืช HTTP/2.
    ืชื•ืงืฃ ื™ื›ื•ืœ ืœืžืฆื•ืช ืืช ื”ื–ื™ื›ืจื•ืŸ ื”ื–ืžื™ืŸ ืœืชื”ืœื™ืš ื•ืœื™ืฆื•ืจ ืขื•ืžืก ืžืขื‘ื“ ื›ื‘ื“ ืขืœ ื™ื“ื™ ืคืชื™ื—ืช ื—ืœื•ืŸ HTTP/2 ื”ื–ื–ื” ืœืฉืจืช ื›ื“ื™ ืœืฉืœื•ื— ื ืชื•ื ื™ื ืœืœื ื”ื’ื‘ืœื•ืช, ืืš ืฉืžื™ืจื” ืขืœ ื—ืœื•ืŸ ื”-TCP ืกื’ื•ืจ, ื•ืœืžื ื•ืข ื›ืชื™ื‘ื” ืฉืœ ื ืชื•ื ื™ื ื‘ืคื•ืขืœ ืœืฉืงืข;
  • CVE-2019-10098 - ื‘ืขื™ื” ื‘-mod_rewrite, ื”ืžืืคืฉืจืช ืœืš ืœื”ืฉืชืžืฉ ื‘ืฉืจืช ื›ื“ื™ ืœื”ืขื‘ื™ืจ ื‘ืงืฉื•ืช ืœืžืฉืื‘ื™ื ืื—ืจื™ื (ื”ืคื ื™ื” ืคืชื•ื—ื”). ื”ื’ื“ืจื•ืช mod_rewrite ืžืกื•ื™ืžื•ืช ืขืฉื•ื™ื•ืช ืœื’ืจื•ื ืœื›ืš ืฉื”ืžืฉืชืžืฉ ื™ื•ืขื‘ืจ ืœืงื™ืฉื•ืจ ืื—ืจ, ื”ืžืงื•ื“ื“ ื‘ืืžืฆืขื•ืช ืชื• ื—ื“ืฉ ื‘ืชื•ืš ืคืจืžื˜ืจ ื”ืžืฉืžืฉ ื‘ื”ืคื ื™ื” ืงื™ื™ืžืช. ื›ื“ื™ ืœื—ืกื•ื ืืช ื”ื‘ืขื™ื” ื‘-RegexDefaultOptions, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ื“ื’ืœ PCRE_DOTALL, ืฉืžื•ื’ื“ืจ ื›ืขืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ;
  • CVE-2019-10092 - ื”ื™ื›ื•ืœืช ืœื‘ืฆืข ืกืงืจื™ืคื˜ื™ื ื‘ื™ืŸ ืืชืจื™ื ื‘ื“ืคื™ ืฉื’ื™ืื” ื”ืžื•ืฆื’ื™ื ืขืœ ื™ื“ื™ mod_proxy. ื‘ื“ืคื™ื ืืœื•, ื”ืงื™ืฉื•ืจ ืžื›ื™ืœ ืืช ื›ืชื•ื‘ืช ื”-URL ืฉื”ืชืงื‘ืœื” ืžื”ื‘ืงืฉื”, ื‘ื” ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ื›ื ื™ืก ืงื•ื“ HTML ืฉืจื™ืจื•ืชื™ ื‘ืืžืฆืขื•ืช ื‘ืจื™ื—ืช ืชื•ื•ื™ื;
  • CVE-2019-10097 - ื”ืฆืคืช ืžื—ืกื ื™ืช ื•ื”ืคื ื™ื™ืช ืžืฆื‘ื™ืข NULL ื‘-mod_remoteip, ืžื ื•ืฆืœืช ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ื›ื•ืชืจืช ืคืจื•ื˜ื•ืงื•ืœ PROXY. ื”ื”ืชืงืคื” ื™ื›ื•ืœื” ืœื”ืชื‘ืฆืข ืจืง ืžื”ืฆื“ ืฉืœ ืฉืจืช ื”-proxy ื”ืžืฉืžืฉ ื‘ื”ื’ื“ืจื•ืช, ื•ืœื ื‘ืืžืฆืขื•ืช ื‘ืงืฉืช ืœืงื•ื—;
  • CVE-2019-10082 - ื ืงื•ื“ืช ืชื•ืจืคื” ื‘-mod_http2 ื”ืžืืคืฉืจืช, ื‘ืจื’ืข ืกื™ื•ื ื”ื—ื™ื‘ื•ืจ, ืœื™ื–ื•ื ืงืจื™ืืช ืชื›ื ื™ื ืžืื–ื•ืจ ื–ื™ื›ืจื•ืŸ ืžืฉื•ื—ืจืจ ื›ื‘ืจ (read-after-free).

ื”ืฉื™ื ื•ื™ื™ื ื”ื‘ื•ืœื˜ื™ื ืฉืื™ื ื ื‘ื™ื˜ื—ื•ื ื™ื™ื ื”ื:

  • mod_proxy_balancer ืฉื™ืคืจ ื”ื’ื ื” ืžืคื ื™ ื”ืชืงืคื•ืช XSS/XSRF ืžืขืžื™ืชื™ื ืžื”ื™ืžื ื™ื;
  • ื”ื’ื“ืจืช SessionExpiryUpdateInterval ื ื•ืกืคื” ืœ-mod_session ื›ื“ื™ ืœืงื‘ื•ืข ืืช ื”ืžืจื•ื•ื— ืœืขื“ื›ื•ืŸ ื–ืžืŸ ื”ืชืคื•ื’ื” ืฉืœ ื”ื”ืคืขืœื”/ืขื•ื’ื™ื™ื”;
  • ื ื•ืงื• ื“ืคื™ื ืขื ืฉื’ื™ืื•ืช, ืฉืžื˜ืจืชื ืœืžื ื•ืข ื”ืฆื’ืช ืžื™ื“ืข ืžื‘ืงืฉื•ืช ื‘ื“ืคื™ื ืืœื”;
  • mod_http2 ืœื•ืงื— ื‘ื—ืฉื‘ื•ืŸ ืืช ื”ืขืจืš ืฉืœ ื”ืคืจืžื˜ืจ "LimitRequestFieldSize", ืฉื‘ืขื‘ืจ ื”ื™ื” ืชืงืฃ ืจืง ืœื‘ื“ื™ืงืช ืฉื“ื•ืช ื›ื•ืชืจืช HTTP/1.1;
  • ืžื‘ื˜ื™ื— ืฉืชืฆื•ืจืช mod_proxy_hcheck ื ื•ืฆืจืช ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-BalancerMember;
  • ืฆืจื™ื›ืช ื–ื™ื›ืจื•ืŸ ืžื•ืคื—ืชืช ื‘-mod_dav ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืคืงื•ื“ื” PROPFIND ื‘ืื•ืกืฃ ื’ื“ื•ืœ;
  • ื‘-mod_proxy ื•-mod_ssl, ื‘ืขื™ื•ืช ืขื ืฆื™ื•ืŸ ื”ื’ื“ืจื•ืช ืื™ืฉื•ืจ ื•-SSL ื‘ืชื•ืš ื‘ืœื•ืง Proxy ื ืคืชืจื•;
  • mod_proxy ืžืืคืฉืจ ืœื”ื—ื™ืœ ืืช ื”ื’ื“ืจื•ืช SSLProxyCheckPeer* ืขืœ ื›ืœ ืžื•ื“ื•ืœื™ ื”-proxy;
  • ื™ื›ื•ืœื•ืช ื”ืžื•ื“ื•ืœ ื”ื•ืจื—ื‘ื• mod_md, ืžืคื•ืชื— ื‘ื•ืื• ืœื”ืฆืคื™ืŸ ืคืจื•ื™ืงื˜ ืœืื•ื˜ื•ืžืฆื™ื” ืฉืœ ืงื‘ืœื” ื•ืชื—ื–ื•ืงื” ืฉืœ ืื™ืฉื•ืจื™ื ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ ACME (ืกื‘ื™ื‘ื” ืื•ื˜ื•ืžื˜ื™ืช ืœื ื™ื”ื•ืœ ืชืขื•ื“ื•ืช):
    • ื ื•ืกืคื” ื’ืจืกื” ืฉื ื™ื™ื” ืฉืœ ื”ืคืจื•ื˜ื•ืงื•ืœ ACMEv2, ืฉื”ื•ื ื›ืขืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื• ะธัะฟะพะปัŒะทัƒะตั‚ ื‘ืงืฉื•ืช POST ืจื™ืงื•ืช ื‘ืžืงื•ื GET.
    • ื ื•ืกืคื” ืชืžื™ื›ื” ืœืื™ืžื•ืช ื”ืžื‘ื•ืกืกืช ืขืœ ืกื™ื•ืžืช TLS-ALPN-01 (RFC 7301, Application-Layer Protocol Negotiation), ื”ืžืฉืžืฉืช ื‘-HTTP/2.
    • ื”ืชืžื™ื›ื” ื‘ืฉื™ื˜ืช ื”ืื™ืžื•ืช 'tls-sni-01' ื”ื•ืคืกืงื” (ื‘ืฉืœ ืคื’ื™ืขื•ืช).
    • ื ื•ืกืคื• ืคืงื•ื“ื•ืช ืœื”ื’ื“ืจื” ื•ืฉื‘ื™ืจืช ื”ืกื™ืžื•ืŸ ื‘ืฉื™ื˜ืช 'dns-01'.
    • ื ื•ืกืคื” ืชืžื™ื›ื” ืžืกื›ื•ืช ื‘ืื™ืฉื•ืจื™ื ื›ืืฉืจ ืื™ืžื•ืช ืžื‘ื•ืกืก DNS ืžื•ืคืขืœ ('dns-01').
    • ื”ื˜ืžืขืช ืžื˜ืคืœ 'md-status' ื•ื“ืฃ ืกื˜ื˜ื•ืก ื”ืื™ืฉื•ืจ 'https://domain/.httpd/certificate-status'.
    • ื ื•ืกืคื• ื”ื ื—ื™ื•ืช "MDCertificateFile" ื•-"MDCertificateKeyFile" ืœื”ื’ื“ืจืช ืคืจืžื˜ืจื™ ืชื—ื•ื ื‘ืืžืฆืขื•ืช ืงื‘ืฆื™ื ืกื˜ื˜ื™ื™ื (ืœืœื ืชืžื™ื›ื” ื‘ืขื“ื›ื•ืŸ ืื•ื˜ื•ืžื˜ื™).
    • ื ื•ืกืคื” ื”ื ื—ื™ื™ืช "MDMessageCmd" ืœืงืจื™ืืช ืคืงื•ื“ื•ืช ื—ื™ืฆื•ื ื™ื•ืช ื›ืืฉืจ ืžืชืจื—ืฉื™ื ืื™ืจื•ืขื™ื 'ืžื—ื•ื“ืฉื™ื', 'ืคื’ ืชื•ืงืคื•' ืื• 'ืฉื’ื™ืื•ืช'.
    • ื ื•ืกืคื” ื”ื ื—ื™ื™ืช "MDWarnWindow" ื›ื“ื™ ืœื”ื’ื“ื™ืจ ื”ื•ื“ืขืช ืื–ื”ืจื” ืœื’ื‘ื™ ืชืคื•ื’ืช ืื™ืฉื•ืจ;

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”