ืคื’ื™ืขื•ืช ื”ืฆืคืช ืžืื’ืจ ื‘ืกืžื‘ื” ื•ื‘-MIT/Heimdal Kerberos

ืžื”ื“ื•ืจื•ืช ืžืชืงื ื•ืช ืฉืœ Samba 4.17.3, 4.16.7 ื•-4.15.12 ืคื•ืจืกืžื• ืขื ื‘ื™ื˜ื•ืœ ืคื’ื™ืขื•ืช (CVE-2022-42898) ื‘ืกืคืจื™ื•ืช Kerberos ืฉืžื•ื‘ื™ืœื” ืœื’ืœื™ืฉื” ืฉืœ ืžืกืคืจื™ื ืฉืœืžื™ื ื•ื›ืชื™ื‘ืช ื ืชื•ื ื™ื ืžื—ื•ืฅ ืœืชื—ื•ื ื‘ืขืช ืขื™ื‘ื•ื“ PAC ืคืจืžื˜ืจื™ื (ืื™ืฉื•ืจ ืชื›ื•ื ื” ืžื•ืจืฉื™ื) ืฉื ืฉืœื—ื• ืขืœ ื™ื“ื™ ืžืฉืชืžืฉ ืžืื•ืžืช. ื ื™ืชืŸ ืœืขืงื•ื‘ ืื—ืจ ืคืจืกื•ื ืขื“ื›ื•ื ื™ ื”ื—ื‘ื™ืœื•ืช ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ื: Debian, Ubuntu, Gentoo, RHEL, SUSE, Arch, FreeBSD.

ื‘ื ื•ืกืฃ ืœืกืžื‘ื”, ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ื’ื ื‘ื—ื‘ื™ืœื•ืช ืขื MIT Kerberos ื•-Heimdal Kerberos. ื“ื•ื— ื”ืคื’ื™ืขื•ืช ืžืคืจื•ื™ืงื˜ Samba ืื™ื ื• ืžืคืจื˜ ืืช ื”ืื™ื•ื, ืืš ื“ื•ื— MIT Kerberos ืงื•ื‘ืข ืฉื”ืคื’ื™ืขื•ืช ืขืœื•ืœื” ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง. ื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช ืืคืฉืจื™ ืจืง ื‘ืžืขืจื›ื•ืช 32 ืกื™ื‘ื™ื•ืช.

ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืขืœ ืชืฆื•ืจื•ืช ืขื KDC (Key Distribution Centeror) ืื• kadmind. ื‘ืชืฆื•ืจื•ืช ืœืœื Active Directory, ื”ืคื’ื™ืขื•ืช ืžื•ืคื™ืขื” ื’ื ื‘ืฉืจืชื™ ืงื‘ืฆื™ื ืฉืœ Samba ื‘ืืžืฆืขื•ืช Kerberos. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื‘ืื’ ื‘ืคื•ื ืงืฆื™ื” krb5_parse_pac(), ืฉื‘ื’ืœืœื” ื—ื•ืฉื‘ ืฉื’ื•ื™ ื’ื•ื“ืœ ื”ืžืื’ืจ ื”ืžืฉืžืฉ ื‘ืขืช ื ื™ืชื•ื— ืฉื“ื•ืช PAC. ื‘ืžืขืจื›ื•ืช 32 ืกื™ื‘ื™ื•ืช, ื‘ืขืช ืขื™ื‘ื•ื“ PACs ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“, ืฉื’ื™ืื” ืขืœื•ืœื” ืœื”ื•ื‘ื™ืœ ืœืžื™ืงื•ื ืฉืœ ื‘ืœื•ืง ืฉืœ 16 ื‘ืชื™ื ืฉื ืฉืœื— ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ ืžื—ื•ืฅ ืœืžืื’ืจ ื”ืžื•ืงืฆื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”