ืคื’ื™ืขื•ืช ื‘ืงื•ืฉื—ื” ืฉืœ ืกืžืกื•ื ื’ ืื ื“ืจื•ืื™ื“ ืžื ื•ืฆืœืช ื‘ืืžืฆืขื•ืช ืฉืœื™ื—ืช MMS

ื‘ืžืขื‘ื“ ื”ืชืžื•ื ื” Qmage ื”ืžืกื•ืคืง ื‘ืงื•ืฉื—ื” ืฉืœ ืกืžืกื•ื ื’ ืื ื“ืจื•ืื™ื“, ื”ืžื•ื‘ื ื” ื‘ืžืขืจื›ืช ื”ืขื™ื‘ื•ื“ ื”ื’ืจืคื™ ืฉืœ Skia, ืคื’ื™ืขื•ืช (CVE-2020-8899), ื”ืžืืคืฉืจ ืœืš ืœืืจื’ืŸ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืขื™ื‘ื•ื“ ืชืžื•ื ื•ืช ื‘ืคื•ืจืžื˜ื™ื QM ื•-QG (".qmg") ื‘ื›ืœ ื™ื™ืฉื•ื. ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื”, ื”ืžืฉืชืžืฉ ืื™ื ื• ืฆืจื™ืš ืœื‘ืฆืข ืฉื•ื ืคืขื•ืœื”; ื‘ืžืงืจื” ื”ืคืฉื•ื˜ ื‘ื™ื•ืชืจ, ืžืกืคื™ืง ืœืฉืœื•ื— ืœืงื•ืจื‘ืŸ ื”ื•ื“ืขืช MMS, ื“ื•ืืจ ืืœืงื˜ืจื•ื ื™ ืื• ืฆ'ืื˜ ื”ืžื›ื™ืœื” ืชืžื•ื ื” ืฉืชื•ื›ื ื ื” ื‘ืžื™ื•ื—ื“.

ื”ื”ืขืจื›ื” ื”ื™ื ืฉื”ื‘ืขื™ื” ืงื™ื™ืžืช ืžืื– 2014, ื”ื—ืœ ื‘ืงื•ืฉื—ื” ื”ืžื‘ื•ืกืกืช ืขืœ ืื ื“ืจื•ืื™ื“ 4.4.4, ืฉื”ื•ืกื™ืคื” ืฉื™ื ื•ื™ื™ื ืœื˜ื™ืคื•ืœ ื‘ืคื•ืจืžื˜ื™ื ื ื•ืกืคื™ื ืฉืœ ืชืžื•ื ื” QM, QG, ASTC ื•-PIO (ื•ืจื™ืื ื˜ PNG). ืคื’ื™ืขื•ืช ื—ื•ืกืœื• ะฒ ืขื“ื›ื•ื ื™ื ื”ืงื•ืฉื—ื” ืฉืœ ืกืžืกื•ื ื’ ืฉื•ื—ืจืจื” ื‘-6 ื‘ืžืื™. ืคืœื˜ืคื•ืจืžืช ื”ืื ื“ืจื•ืื™ื“ ื•ื”ืงื•ืฉื—ื” ื”ืจืืฉื™ืช ืฉืœ ื™ืฆืจื ื™ื ืื—ืจื™ื ืื™ื ื ืžื•ืฉืคืขื™ื ืžื”ื‘ืขื™ื”.

ื”ื‘ืขื™ื” ื–ื•ื”ืชื” ื‘ืžื”ืœืš ื‘ื“ื™ืงืช fuzz ืขืœ ื™ื“ื™ ืžื”ื ื“ืก ืžื’ื•ื’ืœ, ืฉื’ื ื”ื•ื›ื™ื— ืฉื”ืคื’ื™ืขื•ืช ืื™ื ื” ืžื•ื’ื‘ืœืช ืœืงืจื™ืกื•ืช ื•ื”ื›ื™ืŸ ืื‘ ื˜ื™ืคื•ืก ืขื•ื‘ื“ ืฉืœ ื ื™ืฆื•ืœ ืฉืขื•ืงืฃ ืืช ื”ื’ื ืช ASLR ื•ืžืฉื’ืจ ืืช ื”ืžื—ืฉื‘ื•ืŸ ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืกื“ืจื” ืฉืœ ื”ื•ื“ืขื•ืช MMS ืœืกืžืกื•ื ื’ ืกืžืืจื˜ืคื•ืŸ Galaxy Note 10+ ื”ืžืจื™ืฅ ืืช ื”ืคืœื˜ืคื•ืจืžื” ืื ื“ืจื•ืื™ื“ 10.


ื‘ื“ื•ื’ืžื” ื”ืžื•ืฆื’ืช, ื ื™ืฆื•ืœ ืžื•ืฆืœื— ื“ืจืฉ ื›-100 ื“ืงื•ืช ื›ื“ื™ ืœืชืงื•ืฃ ื•ืœืฉืœื•ื— ืœืžืขืœื” ืž-120 ื”ื•ื“ืขื•ืช. ื”ื ื™ืฆื•ืœ ืžื•ืจื›ื‘ ืžืฉื ื™ ื—ืœืงื™ื - ื‘ืฉืœื‘ ื”ืจืืฉื•ืŸ, ื›ื“ื™ ืœืขืงื•ืฃ ASLR, ื›ืชื•ื‘ืช ื”ื‘ืกื™ืก ื ืงื‘ืขืช ื‘ืกืคืจื™ื•ืช libskia.so ื•-libhwui.so, ื•ื‘ืฉืœื‘ ื”ืฉื ื™, ื’ื™ืฉื” ืžืจื—ื•ืง ืœืžื›ืฉื™ืจ ืžืกื•ืคืงืช ืขืœ ื™ื“ื™ ื”ืฉืงืช "ื”ื™ืคื•ืš" ืฆื“ืฃ". ื‘ื”ืชืื ืœืคืจื™ืกืช ื”ื–ื™ื›ืจื•ืŸ, ืงื‘ื™ืขืช ื›ืชื•ื‘ืช ื”ื‘ืกื™ืก ื“ื•ืจืฉืช ืฉืœื™ื—ืช 75 ืขื“ 450 ื”ื•ื“ืขื•ืช.

ื‘ื ื•ืกืฃ, ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืคืจืกื•ื ืขืจื›ืช ืชื™ืงื•ื ื™ ืื‘ื˜ื—ื” ื‘ืžืื™ ืขื‘ื•ืจ ืื ื“ืจื•ืื™ื“, ืฉืชื™ืงื ื• 39 ื ืงื•ื“ื•ืช ืชื•ืจืคื”. ืœืฉืœื•ืฉ ื ื•ืฉืื™ื ื ืงื‘ืขื” ืจืžืช ืกื›ื ื” ืงืจื™ื˜ื™ืช (ืคืจื˜ื™ื ื˜ืจื ื ื—ืฉืคื•):

  • CVE-2020-0096 ื”ื™ื ืคื’ื™ืขื•ืช ืžืงื•ืžื™ืช ื”ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืขื™ื‘ื•ื“ ืงื•ื‘ืฅ ืฉืชื•ื›ื ืŸ ื‘ืžื™ื•ื—ื“);
  • CVE-2020-0103 ื”ื™ื ืคื’ื™ืขื•ืช ืžืจื—ื•ืง ื‘ืžืขืจื›ืช ื”ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืขื™ื‘ื•ื“ ื ืชื•ื ื™ื ื—ื™ืฆื•ื ื™ื™ื ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“);
  • CVE-2020-3641 ื”ื™ื ืคื’ื™ืขื•ืช ื‘ืจื›ื™ื‘ื™ื ืงื ื™ื™ื ื™ื™ื ืฉืœ ืงื•ื•ืืœืงื•ื).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”