ืคื’ื™ืขื•ืช ื‘-pppd ื•-lwIP ื”ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง ืขื ื”ืจืฉืื•ืช ืฉื•ืจืฉ

ื‘ื—ื‘ื™ืœื” pppd ืžื–ื•ื”ื” ืคื’ื™ืขื•ืช (CVE-2020-8597), ื”ืžืืคืฉืจ ืœืš ืœื‘ืฆืข ืืช ื”ืงื•ื“ ืฉืœืš ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ืื™ืžื•ืช ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“ ืœืžืขืจื›ื•ืช ื”ืžืฉืชืžืฉื•ืช ื‘ืคืจื•ื˜ื•ืงื•ืœ PPP (Point-to-Point Protocol) ืื• PPPoE (PPP over Ethernet). ืคืจื•ื˜ื•ืงื•ืœื™ื ืืœื” ืžืฉืžืฉื™ื ื‘ื“ืจืš ื›ืœืœ ืขืœ ื™ื“ื™ ืกืคืงื™ื ืœืืจื’ื•ืŸ ื—ื™ื‘ื•ืจื™ื ื‘ืืžืฆืขื•ืช Ethernet ืื• DSL, ื•ื”ื ืžืฉืžืฉื™ื ื’ื ื‘ื›ืžื” VPNs (ืœื“ื•ื’ืžื”, pptpd ื•- openfortivpn). ื›ื“ื™ ืœื‘ื“ื•ืง ืื ื”ืžืขืจื›ื•ืช ืฉืœืš ืžื•ืฉืคืขื•ืช ืžื”ื‘ืขื™ื” ืžื•ึผื›ึธืŸ ืœื ืฆืœ ืื‘ ื˜ื™ืคื•ืก.

ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื”ืฆืคืช ืžืื’ืจ ื‘ื™ื™ืฉื•ื ืคืจื•ื˜ื•ืงื•ืœ ื”ืื™ืžื•ืช EAP (Extensible Authentication Protocol). ื ื™ืชืŸ ืœื‘ืฆืข ืืช ื”ืžืชืงืคื” ื‘ืฉืœื‘ ื”ืื™ืžื•ืช ืžืจืืฉ ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื—ื‘ื™ืœื” ืžืกื•ื’ EAPT_MD5CHAP, ื›ื•ืœืœ ืฉื ืžืืจื— ืืจื•ืš ืžืื•ื“ ืฉืื™ื ื• ืžืชืื™ื ืœืžืื’ืจ ื”ืžื•ืงืฆื”. ืขืงื‘ ื‘ืื’ ื‘ืงื•ื“ ืœื‘ื“ื™ืงืช ื’ื•ื“ืœ ืฉื“ื” rhostname, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื“ืจื•ืก ื ืชื•ื ื™ื ืžื—ื•ืฅ ืœืžืื’ืจ ื‘ืžื—ืกื ื™ืช ื•ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืžืจื—ื•ืง ืฉืœ ื”ืงื•ื“ ืฉืœื• ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ. ื”ืคื’ื™ืขื•ืช ืžืชื‘ื˜ืืช ื‘ืฆื“ ื”ืฉืจืช ื•ื”ืœืงื•ื—, ื›ืœื•ืžืจ. ืœื ืจืง ื”ืฉืจืช ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžื•ืชืงืฃ, ืืœื ื’ื ืœืงื•ื— ืฉืžื ืกื” ืœื”ืชื—ื‘ืจ ืœืฉืจืช ื”ื ืฉืœื˜ ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ (ืœื“ื•ื’ืžื”, ืชื•ืงืฃ ื™ื›ื•ืœ ืœืคืจื•ืฅ ืชื—ื™ืœื” ืœืฉืจืช ื“ืจืš ื ืงื•ื“ืช ืชื•ืจืคื”, ื•ืื– ืœื”ืชื—ื™ืœ ืœืชืงื•ืฃ ืœืงื•ื—ื•ืช ืžืชื—ื‘ืจื™ื).

ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืขืœ ื’ืจืกืื•ืช pppd ืž-2.4.2 ืขื“ 2.4.8 ื›ื•ืœืœ ื•ืžื‘ื•ื˜ืœ ื‘ื˜ื•ืคืก ืชื™ืงื•ืŸ. ื’ื ืคื’ื™ืขื•ืช ืžืฉืคื™ืข ืœึทืขึฒืจื•ึนื lwIP, ืืš ืชืฆื•ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื‘-lwIP ืื™ื ื” ืžืืคืฉืจืช ืชืžื™ื›ื” ื‘-EAP.

ื ื™ืชืŸ ืœืจืื•ืช ืืช ื”ืกื˜ื˜ื•ืก ืฉืœ ืชื™ืงื•ืŸ ื”ื‘ืขื™ื” ื‘ืขืจื›ื•ืช ื”ืคืฆื” ื‘ื“ืคื™ื ื”ื‘ืื™ื: ื“ื‘ื™ืืŸ, ืื•ื‘ื•ื ื˜ื•, ืจื”ืœ, ืคื“ื•ืจื”, SUSE, OpenWRT, ืงืฉืช, NetBSD. ื‘-RHEL, OpenWRT ื•-SUSE, ื—ื‘ื™ืœืช pppd ื‘ื ื•ื™ื” ืขื ื”ื’ื ืช "Stack Smashing Protection" ืžื•ืคืขืœืช (ืžืฆื‘ "-fstack-protector" ื‘-gcc), ืžื” ืฉืžื’ื‘ื™ืœ ืืช ื”ื ื™ืฆื•ืœ ืœื›ื™ืฉืœื•ืŸ. ื‘ื ื•ืกืฃ ืœื”ืคืฆื•ืช, ื”ืคื’ื™ืขื•ืช ืื•ืฉืจื” ื’ื ื‘ื—ืœืง ืžื”ืžื•ืฆืจื™ื ืกื™ืกืงื• (ืžื ื”ืœ ืฉื™ื—ื•ืช) TP-LINK ื•-Synology (DiskStation Manager, VisualStation VS960HD ื•-Router Manager) ื‘ืืžืฆืขื•ืช ืงื•ื“ pppd ืื• lwIP.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”