ืคื’ื™ืขื•ืช ื‘ืฉืจืช Apache 2.4.49 http ื”ืžืืคืฉืจืช ืงื‘ืœืช ืงื‘ืฆื™ื ืžื—ื•ืฅ ืœืฉื•ืจืฉ ื”ืืชืจ

ื ื•ืฆืจ ืขื“ื›ื•ืŸ ื“ื—ื•ืฃ ืœืฉืจืช ื”-Apache 2.4.50 http, ืืฉืจ ืžื‘ื˜ืœ ืคื’ื™ืขื•ืช ืฉืœ 0 ื™ืžื™ื ืฉื›ื‘ืจ ืžื ื•ืฆืœืช ื‘ืื•ืคืŸ ืคืขื™ืœ (CVE-2021-41773), ื”ืžืืคืฉืจืช ื’ื™ืฉื” ืœืงื‘ืฆื™ื ืžืื–ื•ืจื™ื ืžื—ื•ืฅ ืœืกืคืจื™ื™ืช ื”ืฉื•ืจืฉ ืฉืœ ื”ืืชืจ. ื‘ืืžืฆืขื•ืช ื”ืคื’ื™ืขื•ืช, ื ื™ืชืŸ ืœื”ื•ืจื™ื“ ืงื‘ืฆื™ ืžืขืจื›ืช ืฉืจื™ืจื•ืชื™ื™ื ื•ื˜ืงืกื˜ื™ื ืžืงื•ืจื™ื™ื ืฉืœ ืกืงืจื™ืคื˜ื™ื ื‘ืื™ื ื˜ืจื ื˜, ื”ื ื™ืชื ื™ื ืœืงืจื™ืื” ืขืœ ื™ื“ื™ ื”ืžืฉืชืžืฉ ืฉืชื—ืชื™ื• ืคื•ืขืœ ืฉืจืช http. ื”ืžืคืชื—ื™ื ืงื™ื‘ืœื• ื”ื•ื“ืขื” ืขืœ ื”ื‘ืขื™ื” ื‘-17 ื‘ืกืคื˜ืžื‘ืจ, ืืš ื”ืฆืœื™ื—ื• ืœืฉื—ืจืจ ืืช ื”ืขื“ื›ื•ืŸ ืจืง ื”ื™ื•ื, ืœืื—ืจ ืฉืชื•ืขื“ื• ื‘ืจืฉืช ืžืงืจื™ื ืฉืœ ืฉื™ืžื•ืฉ ื‘ืคื’ื™ืขื•ืช ืœืชืงื™ืคืช ืืชืจื™ื.

ืžืคื—ื™ืช ืืช ื”ืกื›ื ื” ืฉืœ ื”ืคื’ื™ืขื•ืช ื”ื™ื ืฉื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืจืง ื‘ื’ืจืกื” 2.4.49 ืฉื™ืฆืื” ืœืื—ืจื•ื ื” ื•ืื™ื ื” ืžืฉืคื™ืขื” ืขืœ ื›ืœ ื”ืžื”ื“ื•ืจื•ืช ื”ืงื•ื“ืžื•ืช. ื”ืขื ืคื™ื ื”ื™ืฆื™ื‘ื™ื ืฉืœ ื”ืคืฆื•ืช ืฉืจืชื™ื ืฉืžืจื ื™ื•ืช ืขื“ื™ื™ืŸ ืœื ื”ืฉืชืžืฉื• ื‘ืžื”ื“ื•ืจืช 2.4.49 (Debian, RHEL, Ubuntu, SUSE), ืืš ื”ื‘ืขื™ื” ื”ืฉืคื™ืขื” ืขืœ ื”ืคืฆื•ืช ื”ืžืชืขื“ื›ื ื•ืช ื‘ืจืฆื™ืคื•ืช ื›ื’ื•ืŸ Fedora, Arch Linux ื•- Gentoo, ื›ืžื• ื’ื ื™ืฆื™ืื•ืช ืฉืœ FreeBSD.

ื”ืคื’ื™ืขื•ืช ื ื•ื‘ืขืช ืžื‘ืื’ ืฉื”ื•ืฆื’ ื‘ืžื”ืœืš ืฉื›ืชื•ื‘ ืฉืœ ื”ืงื•ื“ ืœื ืจืžื•ืœ ื ืชื™ื‘ื™ื ื‘-URI, ืขืงื‘ ื›ืš ืชื• ื ืงื•ื“ื” ืžืงื•ื“ื“ "%2e" ื‘ื ืชื™ื‘ ืœื ื”ื™ื” ืžื ื•ืจืžืœ ืื ืงื•ื“ืžื” ืœื• ื ืงื•ื“ื” ืื—ืจืช. ืœืคื™ื›ืš, ื ื™ืชืŸ ื”ื™ื” ืœื”ื—ืœื™ืฃ ืชื•ื•ื™ "../" ื’ื•ืœืžื™ื™ื ื‘ื ืชื™ื‘ ืฉื ื•ืฆืจ ืขืœ ื™ื“ื™ ืฆื™ื•ืŸ ื”ืจืฆืฃ ".%2e/" ื‘ื‘ืงืฉื”. ืœื“ื•ื’ืžื”, ื‘ืงืฉื” ื›ืžื• "https://example.com/cgi-bin/.%2e/.%2e/.%2e/.%2e/etc/passwd" ืื• "https://example.com/cgi" -bin /.%2e/%2e%2e/%2e%2e/%2e%2e/etc/hosts" ืืคืฉืจื• ืœืš ืœืงื‘ืœ ืืช ื”ืชื•ื›ืŸ ืฉืœ ื”ืงื•ื‘ืฅ "/etc/passwd".

ื”ื‘ืขื™ื” ืื™ื ื” ืžืชืจื—ืฉืช ืื ื”ื’ื™ืฉื” ืœืกืคืจื™ื•ืช ื ื“ื—ืชื” ื‘ืžืคื•ืจืฉ ื‘ืืžืฆืขื•ืช ื”ื”ื’ื“ืจื” "ื“ืจื•ืฉ ื›ืœ ื ื“ื—ื”". ืœื“ื•ื’ืžื”, ืœื”ื’ื ื” ื—ืœืงื™ืช ืืชื” ื™ื›ื•ืœ ืœืฆื™ื™ืŸ ื‘ืงื•ื‘ืฅ ื”ืชืฆื•ืจื”: ื“ื•ืจืฉื™ื ืฉื›ื•ืœื ื™ื“ื—ื•

Apache httpd 2.4.50 ืžืชืงืŸ ื’ื ืคื’ื™ืขื•ืช ื ื•ืกืคืช (CVE-2021-41524) ื”ืžืฉืคื™ืขื” ืขืœ ืžื•ื“ื•ืœ ื”ืžื™ื™ืฉื ืืช ืคืจื•ื˜ื•ืงื•ืœ HTTP/2. ื”ืคื’ื™ืขื•ืช ืืคืฉืจื” ืœื™ื–ื•ื ื”ืคื ื™ื™ืช ืžืฆื‘ื™ืข null ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื” ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“ ื•ืœื’ืจื•ื ืœืชื”ืœื™ืš ืœืงืจื•ืก. ื’ื ืคื’ื™ืขื•ืช ื–ื• ืžื•ืคื™ืขื” ืจืง ื‘ื’ืจืกื” 2.4.49. ื›ืคืชืจื•ืŸ ืื‘ื˜ื—ื”, ืืชื” ื™ื›ื•ืœ ืœื”ืฉื‘ื™ืช ืืช ื”ืชืžื™ื›ื” ื‘ืคืจื•ื˜ื•ืงื•ืœ HTTP/2.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”