ืคื’ื™ืขื•ืช ื‘-ld.so OpenBSD

ืžื˜ืขื™ืŸ ื“ื™ื ืžื™ ld.so, ื”ื›ืœื•ืœ ื‘-OpenBSD, ืขืฉื•ื™, ื‘ืชื ืื™ื ืžืกื•ื™ืžื™ื, SUID/SGID- ื™ื™ืฉื•ืžื™ื ืขื•ื–ื‘ื™ื ืืช ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” LD_LIBRARY_PATH ื•ื‘ื›ืš ืžืืคืฉืจื™ื ืœื˜ืขื•ืŸ ืงื•ื“ ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ื‘ื”ืงืฉืจ ืฉืœ ืชื”ืœื™ืš ื”ืคื•ืขืœ ืขื ื”ืจืฉืื•ืช ื’ื‘ื•ื”ื•ืช. ืชื™ืงื•ื ื™ื ืฉืžืชืงื ื™ื ืืช ื”ืคื’ื™ืขื•ืช ื–ืžื™ื ื™ื ืขื‘ื•ืจ ืžื”ื“ื•ืจื•ืช 6.5 ะธ 6.6. ืชื™ืงื•ื ื™ื ื‘ื™ื ืืจื™ื™ื (syspatch) ืขื‘ื•ืจ ืคืœื˜ืคื•ืจืžื•ืช amd64, i386 ื•-arm64 ื›ื‘ืจ ื ืžืฆืื•ืช ื‘ื™ื™ืฆื•ืจ ื•ืืžื•ืจื•ืช ืœื”ื™ื•ืช ื–ืžื™ื ื•ืช ืœื”ื•ืจื“ื” ืขื“ ืœืคืจืกื•ื ื”ื™ื“ื™ืขื” ื”ื–ื•.

ืžื”ื•ืช ื”ื‘ืขื™ื”: ื‘ืžื”ืœืš ื”ืคืขื•ืœื”, ld.so ืžื—ืœืฅ ืชื—ื™ืœื” ืืช ื”ืขืจืš ืฉืœ ื”ืžืฉืชื ื” LD_LIBRARY_PATH ืžื”ืกื‘ื™ื‘ื” ื•ื‘ืืžืฆืขื•ืช ื”ืคื•ื ืงืฆื™ื” _dl_split_path() ื”ื•ืคืš ืื•ืชื• ืœืžืขืจืš ืฉืœ ืžื—ืจื•ื–ื•ืช - ื ืชื™ื‘ื™ื ืœืกืคืจื™ื•ืช. ืื ืžืื•ื—ืจ ื™ื•ืชืจ ื™ืชื‘ืจืจ ืฉื”ืชื”ืœื™ืš ื”ื ื•ื›ื—ื™ ืžื•ืคืขืœ ืขืœ ื™ื“ื™ ื™ื™ืฉื•ื SUID/SGID, ืื– ื”ืžืขืจืš ืฉื ื•ืฆืจ ื•ืœืžืขืฉื”, ื”ืžืฉืชื ื” LD_LIBRARY_PATH ื ืžื—ืงื™ื. ื™ื—ื“ ืขื ื–ืืช, ืื _dl_split_path() ื ื’ืžืจ ื‘ื–ื™ื›ืจื•ืŸ (ืžื” ืฉืงืฉื” ื‘ื’ืœืœ ื”ืžื’ื‘ืœื” ื”ืžืคื•ืจืฉืช ืฉืœ 256 ืงื™ืœื•ื‘ื™ื™ื˜ ืขืœ ื’ื•ื“ืœ ืžืฉืชื ื™ ื”ืกื‘ื™ื‘ื”, ืืš ืืคืฉืจื™ ืชื™ืื•ืจื˜ื™ืช), ืื– ื”ืžืฉืชื ื” _dl_libpath ื™ืงื‘ืœ ืืช ื”ืขืจืš NULL, ื•ื‘ื“ื™ืงื•ืช ืขื•ืงื‘ื•ืช ืฉืœ ื”ืขืจืš ืฉืœ ืžืฉืชื ื” ื–ื” ื™ืืœืฅ ืœื“ืœื’ ืขืœ ื”ืงืจื™ืื” ืืœ _dl_unsetenv("LD_LIBRARY_PATH").

ืคื’ื™ืขื•ืช ืฉื ืžืฆืื” ืขืœ ื™ื“ื™ ืžื•ืžื—ื™ื ืงื•ื•ืืœื™ืก, ื‘ื ื•ืกืฃ ืœ ื›ืžื” ืฉื ื—ืฉืคื• ื‘ืขื‘ืจ ื‘ืขื™ื•ืช. ื—ื•ืงืจื™ ื”ืื‘ื˜ื—ื” ืฉื–ื™ื”ื• ืืช ื”ืคื’ื™ืขื•ืช ืฆื™ื™ื ื• ื‘ืื™ื–ื• ืžื”ื™ืจื•ืช ื”ื‘ืขื™ื” ื ืคืชืจื”: ื”ื•ื›ืŸ ืชื™ืงื•ืŸ ื•ืขื“ื›ื•ื ื™ื ืฉื•ื—ืจืจื• ืชื•ืš ืฉืœื•ืฉ ืฉืขื•ืช ืœืื—ืจ ืฉืคืจื•ื™ืงื˜ OpenBSD ืงื™ื‘ืœ ื”ื•ื“ืขื”.

ืชื•ืกืคืช: ืœื‘ืขื™ื” ื”ื•ืงืฆื” ืžืกืคืจ CVE-2019-19726. ื ื•ืฆืจ ื‘ืจืฉื™ืžืช ื”ืชืคื•ืฆื” ืฉืœ oss-security ื”ื•ื“ืขื” ืจืฉืžื™ืช, ื›ื•ืœืœ ื ื™ืฆื•ืœ ืื‘ ื˜ื™ืคื•ืก ื”ืคื•ืขืœ ืขืœ ืืจื›ื™ื˜ืงื˜ื•ืจื•ืช OpenBSD 6.6, 6.5, 6.2 ื•-6.1
amd64 ื•-i386 (ื ื™ืชืŸ ืœื”ืชืื™ื ืืช ื”ื ื™ืฆื•ืœ ืœืืจื›ื™ื˜ืงื˜ื•ืจื•ืช ืื—ืจื•ืช).
ื”ื‘ืขื™ื” ื ื™ืชื ืช ืœื ื™ืฆื•ืœ ื‘ื”ืชืงื ืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื•ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœืœื ื”ืจืฉืื•ืช ืœื”ืคืขื™ืœ ืงื•ื“ ื›-root ื‘ืืžืฆืขื•ืช ื”ื—ืœืคืช ืกืคืจื™ื” ื‘ืขืช ื”ืคืขืœืช ื›ืœื™ ื”ืขื–ืจ chpass ืื• passwd suid. ื›ื“ื™ ืœื™ืฆื•ืจ ืืช ืชื ืื™ ื”ื–ื™ื›ืจื•ืŸ ื”ื ืžื•ื›ื™ื ื”ื“ืจื•ืฉื™ื ืœืคืขื•ืœื”, ื”ื’ื“ืจ ืืช ืžื’ื‘ืœืช RLIMIT_DATA ื‘ืืžืฆืขื•ืช setrlimit.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”