ืคื’ื™ืขื•ืช ื‘-OpenOffice ื”ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืคืชื™ื—ืช ืงื•ื‘ืฅ

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช (CVE-2021-33035) ื‘ื—ื‘ื™ืœืช ื”ืžืฉืจื“ ืฉืœ Apache OpenOffice ื”ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืคืชื™ื—ืช ืงื•ื‘ืฅ ืฉืชื•ื›ื ืŸ ื‘ืžื™ื•ื—ื“ ื‘ืคื•ืจืžื˜ DBF. ื”ื—ื•ืงืจ ืฉื’ื™ืœื” ืืช ื”ื‘ืขื™ื” ื”ื–ื”ื™ืจ ืžืคื ื™ ื™ืฆื™ืจืช ื ื™ืฆื•ืœ ืขื•ื‘ื“ ืขื‘ื•ืจ ืคืœื˜ืคื•ืจืžืช Windows. ืชื™ืงื•ืŸ ื”ืคื’ื™ืขื•ืช ื–ืžื™ืŸ ื›ืจื’ืข ืจืง ื‘ืฆื•ืจื” ืฉืœ ืชื™ืงื•ืŸ ื‘ืžืื’ืจ ื”ืคืจื•ื™ืงื˜ื™ื, ืฉื ื›ืœืœ ื‘ื‘ื ื™ื™ืช ื”ื‘ื“ื™ืงื” ืฉืœ OpenOffice 4.1.11. ืื™ืŸ ืขื“ื™ื™ืŸ ืขื“ื›ื•ื ื™ื ืœืกื ื™ืฃ ื”ื™ืฆื™ื‘.

ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžื›ืš ืฉ-OpenOffice ืžืกืชืžื›ืช ืขืœ ืขืจื›ื™ fieldLength ื•-fieldType ื‘ื›ื•ืชืจืช ืฉืœ ืงื‘ืฆื™ DBF ื›ื“ื™ ืœื”ืงืฆื•ืช ื–ื™ื›ืจื•ืŸ, ืžื‘ืœื™ ืœื‘ื“ื•ืง ืฉืกื•ื’ ื”ื ืชื•ื ื™ื ื‘ืคื•ืขืœ ื‘ืฉื“ื•ืช ืชื•ืื. ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื”, ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืกื•ื’ INTEGER ื‘ืขืจืš fieldType, ืืš ืœืžืงื ื ืชื•ื ื™ื ื’ื“ื•ืœื™ื ื™ื•ืชืจ ื•ืœืฆื™ื™ืŸ ืขืจืš fieldLength ืฉืื™ื ื• ืžืชืื™ื ืœื’ื•ื“ืœ ื”ื ืชื•ื ื™ื ืขื ืกื•ื’ INTEGER, ืžื” ืฉื™ื•ื‘ื™ืœ ืœื–ื ื‘ ื”ื ืชื•ื ื™ื ืžื”ืฉื“ื” ืฉื ื›ืชื‘ ืžืขื‘ืจ ืœืžืื’ืจ ืฉื”ื•ืงืฆื”. ื›ืชื•ืฆืื” ืžื”ืฆืคืช ืžืื’ืจ ืžื‘ื•ืงืจ, ื”ืฆืœื™ื— ื”ื—ื•ืงืจ ืœื”ื’ื“ื™ืจ ืžื—ื“ืฉ ืืช ืžืฆื‘ื™ืข ื”ื”ื—ื–ืจื” ืžื”ืคื•ื ืงืฆื™ื” ื•ื‘ืืžืฆืขื•ืช ื˜ื›ื ื™ืงื•ืช ืชื›ื ื•ืช ืžื•ื›ื•ื•ื ื•ืช ื”ื—ื–ืจื” (ROP - Return-Oriented Programming), ืœื”ืฉื™ื’ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœื•.

ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ื˜ื›ื ื™ืงืช ROP, ื”ืชื•ืงืฃ ืœื ืžื ืกื” ืœืžืงื ืืช ื”ืงื•ื“ ืฉืœื• ื‘ื–ื™ื›ืจื•ืŸ, ืืœื ืคื•ืขืœ ืขืœ ืคื™ืกื•ืช ืฉืœ ื”ื•ืจืื•ืช ืžื›ื•ื ื” ืฉื›ื‘ืจ ื–ืžื™ื ื•ืช ื‘ืกืคืจื™ื•ืช ื˜ืขื•ื ื•ืช, ื”ืžืกืชื™ื™ืžื•ืช ื‘ื”ื•ืจืื” ืœื”ื—ื–ืจืช ื‘ืงืจื” (ื›ื›ืœืœ, ืืœื• ื”ื ื”ืงืฆื•ื•ืช ืฉืœ ืคื•ื ืงืฆื™ื•ืช ื”ืกืคืจื™ื™ื”) . ืขื‘ื•ื“ืช ื”ื ื™ืฆื•ืœ ืžืกืชื›ืžืช ื‘ื‘ื ื™ื™ืช ืฉืจืฉืจืช ืงืจื™ืื•ืช ืœื‘ืœื•ืงื™ื ื“ื•ืžื™ื ("ื’ืื“ื’'ื˜ื™ื") ื›ื“ื™ ืœื”ืฉื™ื’ ืืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื”ืจืฆื•ื™ื”. ื”ื’ืื“ื’'ื˜ื™ื ืฉืฉื™ืžืฉื• ื‘-OpenOffice Exploit ื”ื™ื• ืงื•ื“ ืžืกืคืจื™ื™ืช libxml2 ื”ืžืฉืžืฉืช ื‘-OpenOffice, ืฉื‘ื ื™ื’ื•ื“ ืœ-OpenOffice ืขืฆืžื”, ื”ื•ืจื›ื‘ื” ืœืœื ืžื ื’ื ื•ื ื™ ื”ื”ื’ื ื” DEP (Data Execution Prevention) ื•-ASLR (Address Space Layout Randomization).

ืžืคืชื—ื™ OpenOffice ืงื™ื‘ืœื• ื”ื•ื“ืขื” ืขืœ ื”ื‘ืขื™ื” ื‘-4 ื‘ืžืื™, ื•ืœืื—ืจ ืžื›ืŸ ื—ืฉื™ืคื” ืคื•ืžื‘ื™ืช ืฉืœ ื”ืคื’ื™ืขื•ืช ื ืงื‘ืขื” ืœ-30 ื‘ืื•ื’ื•ืกื˜. ืžืื—ืจ ืฉื”ืขื“ื›ื•ืŸ ืœืกื ื™ืฃ ื”ื™ืฆื™ื‘ ืœื ื”ื•ืฉืœื ื‘ืžื•ืขื“ ื”ืžืชื•ื›ื ืŸ, ื”ื—ื•ืงืจ ื“ื—ื” ืืช ื—ืฉื™ืคืช ื”ืคืจื˜ื™ื ืœ-18 ื‘ืกืคื˜ืžื‘ืจ, ืืš ืžืคืชื—ื™ OpenOffice ืœื ื”ืฆืœื™ื—ื• ืœื™ืฆื•ืจ ืžื”ื“ื•ืจื” 4.1.11 ืขื“ ืœืชืืจื™ืš ื–ื”. ืจืื•ื™ ืœืฆื™ื™ืŸ ืฉื‘ืžื”ืœืš ืื•ืชื• ืžื—ืงืจ, ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช ื“ื•ืžื” ื‘ืงื•ื“ ื”ืชืžื™ื›ื” ื‘ืคื•ืจืžื˜ DBF ื‘-Microsoft Office Access (CVE-2021โ€“38646), ืฉืคืจื˜ื™ื” ื™ื™ื—ืฉืคื• ื‘ื”ืžืฉืš. ืœื ื ืžืฆืื• ื‘ืขื™ื•ืช ื‘-LibreOffice.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”