ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืงืจื™ื˜ื™ื•ืช ื‘-Exim ื”ืžืืคืฉืจื•ืช ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง ื‘ืฉืจืช

ืคืจื•ื™ืงื˜ Zero Day Initiative (ZDI) ื—ืฉืฃ ืžื™ื“ืข ืขืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืœืœื ืชื™ืงื•ืŸ (0-ื™ื•ื) (CVE-2023-42115, CVE-2023-42116, CVE-2023-42117) ื‘ืฉืจืช ื”ื“ื•ืืจ ืฉืœ Exim, ื”ืžืืคืฉืจ ืœืš ืœื‘ืฆืข ืžืจื—ื•ืง ืฉืœืš ืงื•ื“ ื‘ืฉืจืช ืขื ืชื”ืœื™ืš ื”ื–ื›ื•ื™ื•ืช ืฉืžืงื‘ืœ ื—ื™ื‘ื•ืจื™ื ื‘ื™ืฆื™ืืช ืจืฉืช 25. ืœื ื ื“ืจืฉ ืื™ืžื•ืช ื›ื“ื™ ืœื‘ืฆืข ืืช ื”ืžืชืงืคื”.

ื”ืคื’ื™ืขื•ืช ื”ืจืืฉื•ื ื” (CVE-2023-42115) ื ื’ืจืžืช ืžืฉื’ื™ืื” ื‘ืฉื™ืจื•ืช smtp ื•ื”ื™ื ืงืฉื•ืจื” ืœื—ื•ืกืจ ื‘ื“ื™ืงื•ืช ื ืื•ืชื•ืช ืฉืœ ื”ื ืชื•ื ื™ื ืฉื”ืชืงื‘ืœื• ืžื”ืžืฉืชืžืฉ ื‘ืžื”ืœืš ืกืฉืŸ ื”-SMTP ื•ืžืฉืžืฉื™ื ืœื—ื™ืฉื•ื‘ ื’ื•ื“ืœ ื”ืžืื’ืจ. ื›ืชื•ืฆืื” ืžื›ืš, ื”ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืฉื™ื’ ื›ืชื™ื‘ื” ืžื‘ื•ืงืจืช ืฉืœ ื”ื ืชื•ื ื™ื ืฉืœื• ืœืื–ื•ืจ ื–ื™ื›ืจื•ืŸ ืžืขื‘ืจ ืœื’ื‘ื•ืœ ื”ืžืื’ืจ ื”ืžื•ืงืฆื”.

ื”ืคื’ื™ืขื•ืช ื”ืฉื ื™ื™ื” (CVE-2023-42116) ืงื™ื™ืžืช ื‘ืžื˜ืคืœ ื”ื‘ืงืฉื•ืช ืฉืœ NTLM ื•ื”ื™ื ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื”ืขืชืงืช ื ืชื•ื ื™ื ืฉื”ืชืงื‘ืœื• ืžื”ืžืฉืชืžืฉ ืœืžืื’ืจ ื‘ื’ื•ื“ืœ ืงื‘ื•ืข ืœืœื ื”ื‘ื“ื™ืงื•ืช ื”ื ื“ืจืฉื•ืช ืœื’ื•ื“ืœ ื”ืžื™ื“ืข ื”ื ื›ืชื‘.

ื”ืคื’ื™ืขื•ืช ื”ืฉืœื™ืฉื™ืช (CVE-2023-42117) ืงื™ื™ืžืช ื‘ืชื”ืœื™ืš smtp ืงื‘ืœืช ื—ื™ื‘ื•ืจื™ื ื‘ื™ืฆื™ืืช TCP 25 ื•ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื—ื•ืกืจ ืื™ืžื•ืช ืงืœื˜, ืžื” ืฉืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœื›ืชื™ื‘ื” ืฉืœ ื ืชื•ื ื™ื ืฉืกื•ืคืงื• ืขืœ ื™ื“ื™ ื”ืžืฉืชืžืฉ ืœืื–ื•ืจ ื–ื™ื›ืจื•ืŸ ืžื—ื•ืฅ ืœืžืื’ืจ ื”ืžื•ืงืฆื” .

ืคื’ื™ืขื•ื™ื•ืช ืžืกื•ืžื ื•ืช ื›-0-ื™ื•ื, ื›ืœื•ืžืจ. ื ื•ืชืจื• ืœื ืžืชื•ืงื ื™ื, ืืš ื“ื•"ื— ZDI ืงื•ื‘ืข ื›ื™ ืžืคืชื—ื™ Exim ืงื™ื‘ืœื• ื”ื•ื“ืขื” ืขืœ ื”ื‘ืขื™ื•ืช ืžืจืืฉ. ื”ืฉื™ื ื•ื™ ื”ืื—ืจื•ืŸ ื‘ื‘ืกื™ืก ื”ืงื•ื“ ืฉืœ Exim ื‘ื•ืฆืข ืœืคื ื™ ื™ื•ืžื™ื™ื ื•ื˜ืจื ื‘ืจื•ืจ ืžืชื™ ื”ื‘ืขื™ื•ืช ื™ืชื•ืงื ื• (ื™ืฆืจื ื™ ื”ื”ืคืฆื” ื˜ืจื ื”ืกืคื™ืงื• ืœื”ื’ื™ื‘ ืžืื– ื—ืฉื™ืคืช ื”ืžื™ื“ืข ืœืœื ืคืจื˜ื™ื ืœืคื ื™ ืžืกืคืจ ืฉืขื•ืช). ื ื›ื•ืŸ ืœืขื›ืฉื™ื•, ืžืคืชื—ื™ Exim ืžืชื›ื•ื ื ื™ื ืœืฉื—ืจืจ ื’ืจืกื” ื—ื“ืฉื” 4.97, ืืš ืื™ืŸ ืžื™ื“ืข ืžื“ื•ื™ืง ืœื’ื‘ื™ ืžื•ืขื“ ืคืจืกื•ืžื• ืขื“ื™ื™ืŸ. ืฉื™ื˜ืช ื”ื”ื’ื ื” ื”ื™ื—ื™ื“ื” ื”ืžื•ื–ื›ืจืช ื›ืจื’ืข ื”ื™ื ื”ื’ื‘ืœืช ื”ื’ื™ืฉื” ืœืฉื™ืจื•ืช SMTP ืžื‘ื•ืกืก Exim.

ื‘ื ื•ืกืฃ ืœืคื’ื™ืขื•ื™ื•ืช ื”ืงืจื™ื˜ื™ื•ืช ืฉื”ื•ื–ื›ืจื• ืœืขื™ืœ, ื ื—ืฉืฃ ืžื™ื“ืข ื’ื ืขืœ ืžืกืคืจ ื‘ืขื™ื•ืช ืคื—ื•ืช ืžืกื•ื›ื ื•ืช:

  • CVE-2023-42118 ื”ื•ื ื”ืฆืคืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘ืกืคืจื™ื™ืช libspf2 ื‘ืขืช ื ื™ืชื•ื— ืคืงื•ื“ื•ืช ืžืืงืจื• SPF. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืš ืœื™ื–ื•ื ื”ืฉื—ืชื” ืžืจื—ื•ืง ืฉืœ ืชื•ื›ืŸ ื”ื–ื™ื›ืจื•ืŸ ื•ืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘ื” ื›ื“ื™ ืœืืจื’ืŸ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœืš ื‘ืฉืจืช.
  • CVE-2023-42114 ื”ื•ื ืงืจื™ืื” ืžื—ื•ืฅ ืœืžืื’ืจ ื‘ืžื˜ืคืœ NTLM. ื”ื‘ืขื™ื” ืขืœื•ืœื” ืœื’ืจื•ื ืœื“ืœื™ืคื” ืฉืœ ืชื•ื›ืŸ ื”ื–ื™ื›ืจื•ืŸ ืฉืœ ืชื”ืœื™ืš ืฉื™ืจื•ืช ื‘ืงืฉื•ืช ื”ืจืฉืช.
  • CVE-2023-42119 ื”ื™ื ืคื’ื™ืขื•ืช ื‘ืžื˜ืคืœ dnsdb ืฉืžื•ื‘ื™ืœื” ืœื“ืœื™ืคืช ื–ื™ื›ืจื•ืŸ ื‘ืชื”ืœื™ืš smtp.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”