ืžื”ื“ื•ืจืช ืฉืจืช http ืฉืœ Apache 2.4.53 ืขื ืคื’ื™ืขื•ื™ื•ืช ืžืกื•ื›ื ื•ืช ืฉืชื•ืงื ื•

ืคื•ืจืกื ื”ืžื”ื“ื•ืจื” ืฉืœ Apache HTTP Server 2.4.53, ืืฉืจ ืžืฆื™ื’ 14 ืฉื™ื ื•ื™ื™ื ื•ืžืชืงืŸ 4 ืคื’ื™ืขื•ื™ื•ืช:

  • CVE-2022-22720 - ื”ืืคืฉืจื•ืช ืœื‘ืฆืข ืžืชืงืคืช HTTP Request Smuggling, ื”ืžืืคืฉืจืช, ื‘ืืžืฆืขื•ืช ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ืœืงื•ื— ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“, ืœื”ืฉืชืœื‘ ื‘ืชื•ื›ืŸ ืฉืœ ื‘ืงืฉื•ืช ืฉืœ ืžืฉืชืžืฉื™ื ืื—ืจื™ื ื”ืžื•ืขื‘ืจื™ื ื‘ืืžืฆืขื•ืช mod_proxy (ืœื“ื•ื’ืžื”, ื ื™ืชืŸ ืœื”ืฉื™ื’ ื”ื—ืœืคื” ืฉืœ ื–ื“ื•ื ื™ ืงื•ื“ JavaScript ืœืชื•ืš ื”ื”ืคืขืœื” ืฉืœ ืžืฉืชืžืฉ ืื—ืจ ื‘ืืชืจ). ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื”ืฉืืจืช ื—ื™ื‘ื•ืจื™ื ื ื›ื ืกื™ื ืคืชื•ื—ื™ื ืœืื—ืจ ื ืชืงืœ ื‘ืฉื’ื™ืื•ืช ื‘ืขืช ืขื™ื‘ื•ื“ ื’ื•ืฃ ื‘ืงืฉื” ืœื ื—ื•ืงื™.
  • CVE-2022-23943 - ื’ืœื™ืฉืช ื—ื•ืฆืฅ ื‘ืžื•ื“ื•ืœ mod_sed ื”ืžืืคืฉืจืช ื”ื—ืœืคืช ืชื•ื›ืŸ ื–ื™ื›ืจื•ืŸ ื”ืขืจื™ืžื” ื‘ื ืชื•ื ื™ื ื”ื ืฉืœื˜ื™ื ืขืœ ื™ื“ื™ ืชื•ืงืฃ.
  • CVE-2022-22721 - ื›ืชื•ื‘ ืžื—ื•ืฅ ืœืชื—ื•ื ืขืงื‘ ื”ืฆืคืช ืžืกืคืจื™ื ืฉืœืžื™ื ื”ืžืชืจื—ืฉืช ื‘ืขืช ื”ืขื‘ืจืช ื’ื•ืฃ ื‘ืงืฉื” ื’ื“ื•ืœ ืž-350MB. ื”ื‘ืขื™ื” ืžืชื‘ื˜ืืช ื‘ืžืขืจื›ื•ืช 32 ืกื™ื‘ื™ื•ืช ืฉื‘ื”ื’ื“ืจื•ืช ืฉืœื”ืŸ ืขืจืš LimitXMLRequestBody ืžื•ื’ื“ืจ ื’ื‘ื•ื” ืžื“ื™ (ื›ื‘ืจื™ืจืช ืžื—ื“ืœ 1 MB, ืขื‘ื•ืจ ื”ืชืงืคื” ื”ื’ื‘ื•ืœ ื—ื™ื™ื‘ ืœื”ื™ื•ืช ื’ื‘ื•ื” ืž-350 MB).
  • CVE-2022-22719 ื”ื™ื ืคื’ื™ืขื•ืช ื‘-mod_lua ื”ืžืืคืฉืจืช ืงืจื™ืืช ืื–ื•ืจื™ ื–ื™ื›ืจื•ืŸ ืืงืจืื™ื™ื ื•ื”ืจื™ืกืช ื”ืชื”ืœื™ืš ื‘ืขืช ืขื™ื‘ื•ื“ ื’ื•ืฃ ื‘ืงืฉื” ื‘ืขืœ ืžื‘ื ื” ืžื™ื•ื—ื“. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ืฉื™ืžื•ืฉ ื‘ืขืจื›ื™ื ืœื ืžืื•ืชื—ืœื™ื ื‘ืงื•ื“ ื”ืคื•ื ืงืฆื™ื” r:parsebody.

ื”ืฉื™ื ื•ื™ื™ื ื”ื‘ื•ืœื˜ื™ื ืฉืื™ื ื ื‘ื™ื˜ื—ื•ื ื™ื™ื ื”ื:

  • ื‘-mod_proxy, ื”ื’ื‘ืœื” ืขืœ ืžืกืคืจ ื”ืชื•ื•ื™ื ื‘ืฉื ื”ืžื˜ืคืœ (ืขื•ื‘ื“) ื”ื•ื’ื“ืœื”. ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืจ ื‘ืื•ืคืŸ ืกืœืงื˜ื™ื‘ื™ ืคืกืงื™ ื–ืžืŸ ืขื‘ื•ืจ ื”-backend ื•ื”-frontend (ืœื“ื•ื’ืžื”, ื‘ื™ื—ืก ืœืขื•ื‘ื“). ืขื‘ื•ืจ ื‘ืงืฉื•ืช ืฉื ืฉืœื—ื•ืช ื“ืจืš websockets ืื• ืฉื™ื˜ืช CONNECT, ื”ื–ืžืŸ ื”ืงืฆื•ื‘ ื”ืฉืชื ื” ืœืขืจืš ื”ืžืงืกื™ืžืœื™ ืฉื ืงื‘ืข ืขื‘ื•ืจ ื”-backend ื•ื”-frontend.
  • ื˜ื™ืคื•ืœ ื ืคืจื“ ื‘ืคืชื™ื—ืช ืงื‘ืฆื™ DBM ื•ื˜ืขื™ื ืช ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ DBM. ื‘ืžืงืจื” ืฉืœ ืงืจื™ืกื”, ื”ื™ื•ืžืŸ ืžืฆื™ื’ ื›ืขืช ืžื™ื“ืข ืžืคื•ืจื˜ ื™ื•ืชืจ ืขืœ ื”ืฉื’ื™ืื” ื•ืขืœ ืžื ื”ืœ ื”ื”ืชืงืŸ.
  • mod_md ื”ืคืกื™ืง ืœืขื‘ื“ ื‘ืงืฉื•ืช ืืœ /.well-known/acme-challenge/ ืืœื ืื ื”ื’ื“ืจื•ืช ื”ื“ื•ืžื™ื™ืŸ ืืคืฉืจื• ื‘ืžืคื•ืจืฉ ืืช ื”ืฉื™ืžื•ืฉ ื‘ืกื•ื’ ื”ืืชื’ืจ 'http-01'.
  • mod_dav ืชื™ืงืŸ ืจื’ืจืกื™ื” ืฉื’ืจืžื” ืœืฆืจื™ื›ืช ื–ื™ื›ืจื•ืŸ ื’ื‘ื•ื”ื” ื‘ืขืช ืขื™ื‘ื•ื“ ืžืกืคืจ ืจื‘ ืฉืœ ืžืฉืื‘ื™ื.
  • ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืกืคืจื™ื™ืช pcre2 (10.x) ื‘ืžืงื•ื pcre (8.x) ืœืขื™ื‘ื•ื“ ื‘ื™ื˜ื•ื™ื™ื ืจื’ื•ืœืจื™ื™ื.
  • ืชืžื™ื›ื” ื‘ื ื™ืชื•ื— ื—ืจื™ื’ื•ืช LDAP ื ื•ืกืคื” ืœืžืกื ื ื™ ืฉืื™ืœืชื•ืช ื›ื“ื™ ืœืกื ืŸ ื ื›ื•ืŸ ื ืชื•ื ื™ื ื‘ืขืช ื ื™ืกื™ื•ืŸ ืœื‘ืฆืข ื”ืชืงืคื•ืช ื”ื—ืœืคืช LDAP.
  • ื‘-mpm_event, ืชื•ืงืŸ ืžื‘ื•ื™ ืกืชื•ื ื”ืžืชืจื—ืฉ ื‘ืขืช ื”ืคืขืœื” ืžื—ื“ืฉ ืื• ื—ืจื™ื’ื” ืžืžื’ื‘ืœืช MaxConnectionsPerChild ื‘ืžืขืจื›ื•ืช ืขืžื•ืกื•ืช ืžืื•ื“.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”