ืคื’ื™ืขื•ืช ื‘-Mailman ื”ืžืืคืฉืจืช ืœืš ืœืงื‘ื•ืข ืืช ืกื™ืกืžืช ืžื ื”ืœ ืจืฉื™ืžืช ื”ืชืคื•ืฆื”

ืคื•ืจืกื ืžื”ื“ื•ืจื” ืžืชืงื ืช ืฉืœ ืžืขืจื›ืช ื ื™ื”ื•ืœ ื”ื“ื™ื•ื•ืจ GNU Mailman 2.1.35, ื”ืžืฉืžืฉืช ืœืืจื’ื•ืŸ ืชืงืฉื•ืจืช ื‘ื™ืŸ ืžืคืชื—ื™ื ื‘ืžื’ื•ื•ืŸ ืคืจื•ื™ืงื˜ื™ื ื‘ืงื•ื“ ืคืชื•ื—. ื”ืขื“ื›ื•ืŸ ืžื˜ืคืœ ื‘ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื”: ื”ืคื’ื™ืขื•ืช ื”ืจืืฉื•ื ื” (CVE-2021-42096) ืžืืคืฉืจืช ืœื›ืœ ืžืฉืชืžืฉ ืฉื ืจืฉื ืœืจืฉื™ืžืช ืชืคื•ืฆื” ืœืงื‘ื•ืข ืืช ืกื™ืกืžืช ื”ืžื ื”ืœ ืขื‘ื•ืจ ืจืฉื™ืžืช ืชืคื•ืฆื” ื–ื•. ื”ืคื’ื™ืขื•ืช ื”ืฉื ื™ื™ื” (CVE-2021-42097) ืžืืคืฉืจืช ืœื‘ืฆืข ืžืชืงืคืช CSRF ืขืœ ืžืฉืชืžืฉ ืื—ืจ ื‘ืจืฉื™ืžืช ืชืคื•ืฆื” ื›ื“ื™ ืœืชืคื•ืก ืืช ื—ืฉื‘ื•ื ื•. ื”ืชืงื™ืคื” ื™ื›ื•ืœื” ืœื”ืชื‘ืฆืข ืจืง ืขืœ ื™ื“ื™ ื—ื‘ืจ ืจืฉื•ื ื‘ืจืฉื™ืžืช ื”ืชืคื•ืฆื”. Mailman 3 ืื™ื ื• ืžื•ืฉืคืข ืžื”ื‘ืขื™ื” ื”ื–ื•.

ืฉืชื™ ื”ื‘ืขื™ื•ืช ื ื’ืจืžื•ืช ืžื”ืขื•ื‘ื“ื” ืฉืขืจืš csrf_token ื”ืžืฉืžืฉ ืœื”ื’ื ื” ืžืคื ื™ ื”ืชืงืคื•ืช CSRF ื‘ื“ืฃ ื”ืืคืฉืจื•ื™ื•ืช ื”ื•ื ืชืžื™ื“ ื–ื”ื” ืœืืกื™ืžื•ืŸ ื”ืžื ื”ืœ, ื•ืื™ื ื• ื ื•ืฆืจ ื‘ื ืคืจื“ ืขื‘ื•ืจ ื”ืžืฉืชืžืฉ ืฉืœ ื”ื”ืคืขืœื” ื”ื ื•ื›ื—ื™ืช. ื‘ืขืช ื™ืฆื™ืจืช csrf_token, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžื™ื“ืข ืขืœ ื”-hash ืฉืœ ืกื™ืกืžืช ื”ืžื ื”ืœ, ืžื” ืฉืžืคืฉื˜ ืืช ืงื‘ื™ืขืช ื”ืกื™ืกืžื” ื‘ื›ื•ื— ื’ืก. ืžื›ื™ื•ื•ืŸ ืฉ-csrf_token ืฉื ื•ืฆืจ ืขื‘ื•ืจ ืžืฉืชืžืฉ ืื—ื“ ืžืชืื™ื ื’ื ืœืžืฉืชืžืฉ ืื—ืจ, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื™ืฆื•ืจ ืขืžื•ื“ ืฉื›ืืฉืจ ื”ื•ื ื ืคืชื— ืขืœ ื™ื“ื™ ืžืฉืชืžืฉ ืื—ืจ, ื™ื›ื•ืœ ืœื’ืจื•ื ืœื‘ื™ืฆื•ืข ืคืงื•ื“ื•ืช ื‘ืžืžืฉืง Mailman ืžื˜ืขื ืžืฉืชืžืฉ ื–ื” ื•ืœืงื‘ืœ ืฉืœื™ื˜ื” ืขืœ ื”ื—ืฉื‘ื•ืŸ ืฉืœื•.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”