ืคื’ื™ืขื•ืช ื‘-FreeBSD ftpd ืฉืืคืฉืจื” ื’ื™ืฉื” ืœืฉื•ืจืฉ ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-ftpchroot

ื‘ืฉืจืช ftpd ืฉืกื•ืคืง ืขื FreeBSD ืžื–ื•ื”ื” ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2020-7468), ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉื™ื ืžื•ื’ื‘ืœื™ื ืœืกืคืจื™ื™ืช ื”ื‘ื™ืช ืฉืœื”ื ื‘ืืžืฆืขื•ืช ืืคืฉืจื•ืช ftpchroot ืœืงื‘ืœ ื’ื™ืฉืช ืฉื•ืจืฉ ืžืœืื” ืœืžืขืจื›ืช.

ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžืฉื™ืœื•ื‘ ืฉืœ ื‘ืื’ ื‘ื”ื˜ืžืขืช ืžื ื’ื ื•ืŸ ื‘ื™ื“ื•ื“ ื”ืžืฉืชืžืฉ ื‘ืืžืฆืขื•ืช ืงืจื™ืืช chroot (ืื ืชื”ืœื™ืš ืฉืœ ืฉื™ื ื•ื™ uid ืื• ื‘ื™ืฆื•ืข chroot ื•-chdir ื ื›ืฉืœ, ื ื’ืจืžืช ืฉื’ื™ืื” ืœื ืงื˜ืœื ื™ืช ืฉืื™ื ื” ืžืกื™ื™ืžืช ืืช ื”ืกืฉืŸ) ื•ืžืชืŸ ืœืžืฉืชืžืฉ FTP ืžืื•ืžืช ื–ื›ื•ื™ื•ืช ืžืกืคื™ืงื•ืช ื›ื“ื™ ืœืขืงื•ืฃ ืืช ื”ื’ื‘ืœืช ื ืชื™ื‘ ื”ืฉื•ืจืฉ ื‘ืžืขืจื›ืช ื”ืงื‘ืฆื™ื. ื”ืคื’ื™ืขื•ืช ืื™ื ื” ืžืชืจื—ืฉืช ื‘ืขืช ื’ื™ืฉื” ืœืฉืจืช FTP ื‘ืžืฆื‘ ืื ื•ื ื™ืžื™ ืื• ื›ืืฉืจ ืžืฉืชืžืฉ ืžื—ื•ื‘ืจ ื‘ืžืœื•ืื• ืœืœื ftpchroot. ื”ื‘ืขื™ื” ื ืคืชืจื” ื‘ืขื“ื›ื•ื ื™ื 12.1-RELEASE-p10, 11.4-RELEASE-p4 ื•-11.3-RELEASE-p14.

ื‘ื ื•ืกืฃ, ืื ื• ื™ื›ื•ืœื™ื ืœืฆื™ื™ืŸ ืืช ื‘ื™ื˜ื•ืœืŸ ืฉืœ ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื ื•ืกืคื•ืช ื‘-12.1-RELEASE-p10, 11.4-RELEASE-p4 ื•-11.3-RELEASE-p14:

  • CVE-2020-7467 - ื ืงื•ื“ืช ืชื•ืจืคื” ื‘-Bhyve hypervisor, ื”ืžืืคืฉืจืช ืœืกื‘ื™ื‘ืช ื”ืื•ืจื— ืœื›ืชื•ื‘ ืžื™ื“ืข ืœืื–ื•ืจ ื”ื–ื™ื›ืจื•ืŸ ืฉืœ ื”ืกื‘ื™ื‘ื” ื”ืžืืจื—ืช ื•ืœืงื‘ืœ ื’ื™ืฉื” ืžืœืื” ืœืžืขืจื›ืช ื”ืžืืจื—ืช. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžื”ื™ืขื“ืจ ื”ื’ื‘ืœื•ืช ื’ื™ืฉื” ืœื”ื•ืจืื•ืช ืžืขื‘ื“ ืฉืขื•ื‘ื“ื•ืช ืขื ื›ืชื•ื‘ื•ืช ืžืืจื— ืคื™ื–ื™ื•ืช, ื•ืžื•ืคื™ืขื” ืจืง ื‘ืžืขืจื›ื•ืช ืขื ืžืขื‘ื“ื™ AMD.
  • CVE-2020-24718 - ืคื’ื™ืขื•ืช ื‘-Bhyve hypervisor ื”ืžืืคืฉืจืช ืœืชื•ืงืฃ ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ ื‘ืชื•ืš ืกื‘ื™ื‘ื•ืช ืžื‘ื•ื“ื“ื•ืช ื‘ืืžืฆืขื•ืช Bhyve ืœื”ืคืขื™ืœ ืงื•ื“ ื‘ืจืžืช ื”ืœื™ื‘ื”. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื”ื™ืขื“ืจ ื”ื’ื‘ืœื•ืช ื’ื™ืฉื” ื ืื•ืชื•ืช ืœืžื‘ื ื™ VMCS (Virtual Machine Control Structure) ื‘ืžืขืจื›ื•ืช ืขื ืžืขื‘ื“ื™ ืื™ื ื˜ืœ ื•-VMCB (Virtual).
    Machine Control Block) ื‘ืžืขืจื›ื•ืช ืขื ืžืขื‘ื“ื™ AMD.

  • CVE-2020-7464 - ืคื’ื™ืขื•ืช ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ ure (USB Ethernet Realtek RTL8152 ื•-RTL8153), ื”ืžืืคืฉืจืช ื–ื™ื•ืฃ ืžื ื•ืช ืžืžืืจื—ื™ื ืื—ืจื™ื ืื• ื”ื—ืœืคืช ืžื ื•ืช ืœืจืฉืชื•ืช VLAN ืื—ืจื•ืช ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืžืกื’ืจื•ืช ื’ื“ื•ืœื•ืช (ื™ื•ืชืจ ืž-2048).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”