ืคื’ื™ืขื•ืช ืฉืœ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘-libXpm

ืคื•ืจืกื ืžื”ื“ื•ืจื” ืžืชืงื ืช ืฉืœ ืกืคืจื™ื™ืช libXpm 3.5.15, ืฉืคื•ืชื—ื” ืขืœ ื™ื“ื™ ืคืจื•ื™ืงื˜ X.Org ื•ืžืฉืžืฉืช ืœืขื™ื‘ื•ื“ ืงื‘ืฆื™ื ื‘ืคื•ืจืžื˜ XPM. ื”ื’ืจืกื” ื”ื—ื“ืฉื” ืžืชืงื ืช ืฉืœื•ืฉ ืคื’ื™ืขื•ื™ื•ืช, ืฉืชื™ื™ื ืžื”ืŸ (CVE-2022-46285, CVE-2022-44617) ืžื•ื‘ื™ืœื•ืช ืœืœื•ืœืื” ื‘ืขืช ืขื™ื‘ื•ื“ ืงื‘ืฆื™ XPM ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“. ื”ืคื’ื™ืขื•ืช ื”ืฉืœื™ืฉื™ืช (CVE-2022-4883) ืžืืคืฉืจืช ืœื‘ืฆืข ืคืงื•ื“ื•ืช ืฉืจื™ืจื•ืชื™ื•ืช ื‘ืขืช ื”ืคืขืœืช ื™ื™ืฉื•ืžื™ื ื”ืžืฉืชืžืฉื™ื ื‘-libXpm. ื‘ืขืช ื”ืคืขืœืช ืชื”ืœื™ื›ื™ื ืžื•ืจืฉื™ื ื”ืงืฉื•ืจื™ื ืœ-libXpm, ืœืžืฉืœ, ืชื•ื›ื ื™ื•ืช ืขื ื“ื’ืœ ื”ืฉื•ืจืฉ suid, ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœื”ืกืœื™ื ืืช ื”ื”ืจืฉืื•ืช ืฉืœ ื”ืื“ื.

ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืžื”ืื•ืคืŸ ืฉื‘ื• libXpm ืขื•ื‘ื“ ืขื ืงื‘ืฆื™ XPM ื“ื—ื•ืกื™ื - ื‘ืขืช ืขื™ื‘ื•ื“ ืงื‘ืฆื™ XPM.Z ืื• XPM.gz, ื”ืกืคืจื™ื™ื” ืžืฉื™ืงื” ื›ืœื™ ืขื–ืจ ื—ื™ืฆื•ื ื™ื™ื ืœื‘ื™ื˜ื•ืœ ื“ื—ื™ืกื” (uncompress ืื• gunzip) ื‘ืืžืฆืขื•ืช ื”ืงืจื™ืื” execlp() ืฉื”ื ืชื™ื‘ ืืœื™ื” ืžื—ื•ืฉื‘ ืขืœ ื‘ืกื™ืก ืขืœ ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” PATH. ื”ืžืชืงืคื” ืžืกืชื›ืžืช ื‘ื”ืฆื‘ื” ื‘ืกืคืจื™ื™ื” ื ื’ื™ืฉื” ืœืžืฉืชืžืฉ, ื”ืงื™ื™ืžืช ื‘ืจืฉื™ืžืช ื”-PATH, ืงื‘ืฆื™ ื”ืคืขืœื” ืžืฉืœื” ืฉืœ Uncompress ืื• gunzip, ืฉื™ื‘ื•ืฆืขื• ืื ื™ื•ืคืขืœ ื™ื™ืฉื•ื ื”ืžืฉืชืžืฉ ื‘-libXpm.

ื”ืคื’ื™ืขื•ืช ืชื•ืงื ื” ืขืœ ื™ื“ื™ ื”ื—ืœืคืช ืงืจื™ืืช ื”-execlp ื‘-execl ื‘ืืžืฆืขื•ืช ื ืชื™ื‘ื™ื ืžื•ื—ืœื˜ื™ื ืœืฉื™ืจื•ืชื™ื. ื‘ื ื•ืกืฃ, ื ื•ืกืคื” ืืคืฉืจื•ืช ื”ื”ืจื›ื‘ื” "--disable-open-zfile", ื”ืžืืคืฉืจืช ืœืš ืœื‘ื˜ืœ ืืช ื”ืขื™ื‘ื•ื“ ืฉืœ ืงื‘ืฆื™ื ื“ื—ื•ืกื™ื ื•ืœืงืจื•ื ืœื›ืœื™ ืฉื™ืจื•ืช ื—ื™ืฆื•ื ื™ื™ื ืœืคืจื™ืงื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”