ืฉื—ืจื•ืจ ืฉืœ Apache http ืฉืจืช 2.4.43

ื™ืฆื ืœืื•ืจ ืžื”ื“ื•ืจื” ืฉืœ ืฉืจืช ื”-HTTP ืฉืœ Apache 2.4.43 (ื”ื’ืจืกื” 2.4.42 ื ื“ื—ืชื”), ืฉื”ืฆื™ื’ื” 34 ืฉื™ื ื•ื™ื™ื ื•ื—ื•ืกืœื• 3 ืคื’ื™ืขื•ื™ื•ืช:

  • CVE-2020-1927: ืคื’ื™ืขื•ืช ื‘-mod_rewrite ื”ืžืืคืฉืจืช ืœื”ืฉืชืžืฉ ื‘ืฉืจืช ืœื”ืขื‘ืจืช ื‘ืงืฉื•ืช ืœืžืฉืื‘ื™ื ืื—ืจื™ื (ื”ืคื ื™ื” ืคืชื•ื—ื”). ื”ื’ื“ืจื•ืช mod_rewrite ืžืกื•ื™ืžื•ืช ืขืฉื•ื™ื•ืช ืœื’ืจื•ื ืœื›ืš ืฉื”ืžืฉืชืžืฉ ื™ื•ืขื‘ืจ ืœืงื™ืฉื•ืจ ืื—ืจ, ื”ืžืงื•ื“ื“ ื‘ืืžืฆืขื•ืช ืชื• ื—ื“ืฉ ื‘ืชื•ืš ืคืจืžื˜ืจ ื”ืžืฉืžืฉ ื‘ื”ืคื ื™ื” ืงื™ื™ืžืช.
  • CVE-2020-1934: ืคื’ื™ืขื•ืช ื‘-mod_proxy_ftp. ืฉื™ืžื•ืฉ ื‘ืขืจื›ื™ื ืœื ืžืื•ืชื—ืœื™ื ื™ื›ื•ืœ ืœื”ื•ื‘ื™ืœ ืœื“ืœื™ืคื•ืช ื–ื™ื›ืจื•ืŸ ื‘ืขืช โ€‹โ€‹ื”ืขื‘ืจืช ื‘ืงืฉื•ืช ืœืฉืจืช FTP ื”ื ืฉืœื˜ ืขืœ ื™ื“ื™ ืชื•ืงืฃ.
  • ื“ืœื™ืคืช ื–ื™ื›ืจื•ืŸ ื‘-mod_ssl ืฉืžืชืจื—ืฉืช ื‘ืขืช ืฉืจืฉื•ืจ ื‘ืงืฉื•ืช OCSP.

ื”ืฉื™ื ื•ื™ื™ื ื”ื‘ื•ืœื˜ื™ื ืฉืื™ื ื ื‘ื™ื˜ื—ื•ื ื™ื™ื ื”ื:

  • ื ื•ืกืฃ ืžื•ื“ื•ืœ ื—ื“ืฉ mod_systemd, ื”ืžืกืคืง ืื™ื ื˜ื’ืจืฆื™ื” ืขื ืžื ื”ืœ ื”ืžืขืจื›ืช systemd. ื”ืžื•ื“ื•ืœ ืžืืคืฉืจ ืœืš ืœื”ืฉืชืžืฉ ื‘-httpd ื‘ืฉื™ืจื•ืชื™ื ืžืกื•ื’ "Type=notify".
  • ืชืžื™ื›ื” ื‘ื”ื™ื“ื•ืจ ืฆื•ืœื‘ ื ื•ืกืคื” ืœ-apxs.
  • ื”ื™ื›ื•ืœื•ืช ืฉืœ ืžื•ื“ื•ืœ mod_md, ืฉืคื•ืชื— ืขืœ ื™ื“ื™ ืคืจื•ื™ืงื˜ Let's Encrypt ืœืื•ื˜ื•ืžื˜ื™ื•ืช ืฉืœ ืงื‘ืœืช ื•ืชื—ื–ื•ืงื” ืฉืœ ืื™ืฉื•ืจื™ื ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ ACME (Automatic Certificate Management Environment) ื”ื•ืจื—ื‘ื•:
    • ื ื•ืกืคื” ื”ื”ื ื—ื™ื” MDContactEmail, ื“ืจื›ื” ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืžื™ื™ืœ ืœื™ืฆื™ืจืช ืงืฉืจ ืฉืื™ื ื• ื—ื•ืคืฃ ืœื ืชื•ื ื™ื ืžื”ื ื—ื™ื™ืช ServerAdmin.
    • ืขื‘ื•ืจ ื›ืœ ื”ืžืืจื—ื™ื ื”ื•ื•ื™ืจื˜ื•ืืœื™ื™ื, ื”ืชืžื™ื›ื” ื‘ืคืจื•ื˜ื•ืงื•ืœ ื”ืžืฉืžืฉ ื‘ืขืช ื ื™ื”ื•ืœ ืžืฉื ื•ืžืชืŸ ืขืœ ืขืจื•ืฅ ืชืงืฉื•ืจืช ืžืื•ื‘ื˜ื— ("tls-alpn-01") ืžืื•ืžืชืช.
    • ืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘ื”ื ื—ื™ื•ืช mod_md ื‘ื‘ืœื•ืงื™ื ื• .
    • ืžื‘ื˜ื™ื— ืฉื”ื’ื“ืจื•ืช ืงื•ื“ืžื•ืช ื™ื•ื—ืœืคื• ื‘ืขืช ืฉื™ืžื•ืฉ ื—ื•ื–ืจ ื‘-MDCAChallenges.
    • ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืจ ืืช ื›ืชื•ื‘ืช ื”ืืชืจ ืขื‘ื•ืจ CTLog Monitor.
    • ืขื‘ื•ืจ ืคืงื•ื“ื•ืช ื”ืžื•ื’ื“ืจื•ืช ื‘ื”ื ื—ื™ื™ืช MDMessageCmd, ืงืจื™ืื” ืขื ื”ืืจื’ื•ืžื ื˜ "installed" ืžืกื•ืคืงืช ื‘ืขืช ื”ืคืขืœืช ืื™ืฉื•ืจ ื—ื“ืฉ ืœืื—ืจ ื”ืคืขืœื” ืžื—ื“ืฉ ืฉืœ ื”ืฉืจืช (ืœื“ื•ื’ืžื”, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื›ื“ื™ ืœื”ืขืชื™ืง ืื• ืœื”ืžื™ืจ ืื™ืฉื•ืจ ื—ื“ืฉ ืขื‘ื•ืจ ื™ื™ืฉื•ืžื™ื ืื—ืจื™ื).
  • mod_proxy_hcheck ื”ื•ืกื™ืฃ ืชืžื™ื›ื” ื‘ืžืกื›ืช %{Content-Type} ื‘ื‘ื™ื˜ื•ื™ื™ ื‘ื“ื™ืงื”.
  • ืžืฆื‘ื™ CookieSameSite, CookieHTTOnly ื•-CookieSecure ื ื•ืกืคื• ืœ-mod_usertrack ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ืขื™ื‘ื•ื“ ืงื•ื‘ืฆื™ ื”-Usertrack.
  • mod_proxy_ajp ืžื™ื™ืฉืžืช ืืคืฉืจื•ืช "ืกื•ื“ื™ืช" ืขื‘ื•ืจ ืžื˜ืคืœื™ ืคืจื•ืงืกื™ ื›ื“ื™ ืœืชืžื•ืš ื‘ืคืจื•ื˜ื•ืงื•ืœ ื”ืื™ืžื•ืช AJP13 ืžื“ื•ืจ ืงื•ื“ื.
  • ื ื•ืกืคื” ืขืจื›ืช ืชืฆื•ืจื” ืขื‘ื•ืจ OpenWRT.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ืœ-mod_ssl ืœืฉื™ืžื•ืฉ ื‘ืžืคืชื—ื•ืช ืคืจื˜ื™ื™ื ื•ื‘ืื™ืฉื•ืจื™ื ืž-OpenSSL ENGINE ืขืœ-ื™ื“ื™ ืฆื™ื•ืŸ URI PKCS#11 ื‘-SSLCertificateFile/KeyFile.
  • ื‘ื™ืฆื•ืข ื‘ื“ื™ืงื•ืช ื‘ืืžืฆืขื•ืช ืžืขืจื›ืช ื”ืื™ื ื˜ื’ืจืฆื™ื” ื”ืจืฆื™ืคื” Travis CI.
  • ื”ื ื™ืชื•ื— ืฉืœ ื›ื•ืชืจื•ืช ืงื™ื“ื•ื“ ื”ืขื‘ืจื” ื”ื•ื—ื–ืง.
  • mod_ssl ืžืกืคืง ืžืฉื ื•ืžืชืŸ ืขืœ ืคืจื•ื˜ื•ืงื•ืœ TLS ื‘ื™ื—ืก ืœืžืืจื—ื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื (ื ืชืžืš ื›ืืฉืจ ื ื‘ื ื” ืขื OpenSSL-1.1.1+.
  • ืขืœ ื™ื“ื™ ืฉื™ืžื•ืฉ ื‘ื’ื™ื‘ื•ื‘ ืขื‘ื•ืจ ื˜ื‘ืœืื•ืช ืคืงื•ื“ื•ืช, ื”ืคืขืœื” ืžื—ื“ืฉ ื‘ืžืฆื‘ "ื—ื™ื ื ื™" ืžื•ืืฆืช (ืžื‘ืœื™ ืœื”ืคืจื™ืข ืœืžืขื‘ื“ื™ ืฉืื™ืœืชื•ืช ื”ืคื•ืขืœื™ื).
  • ื ื•ืกืคื• ื˜ื‘ืœืื•ืช ืœืงืจื™ืื” ื‘ืœื‘ื“ r:headers_in_table, r:headers_out_table, r:err_headers_out_table, r:notes_table ื•-r:subprocess_env_table ืœ-mod_lua. ืืคืฉืจ ืœื”ืงืฆื•ืช ืœื˜ื‘ืœืื•ืช ืืช ื”ืขืจืš "ืืคืก".
  • ื‘-mod_authn_socache ื”ื”ื’ื‘ืœื” ืขืœ ื’ื•ื“ืœ ืงื• ืฉืžื•ืจ ื”ื•ื’ื“ืœื” ืž-100 ืœ-256.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”