ืคื’ื™ืขื•ืช ื‘ืขืจื™ืžืช ืจืฉืช ืœื™ื‘ืช ืœื™ื ื•ืงืก

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช ื‘ืงื•ื“ ืฉืœ ื”ืžื˜ืคืœ ื‘ืคืจื•ื˜ื•ืงื•ืœ RDS ืžื‘ื•ืกืก TCP (Reliable Datagram Socket, net/rds/tcp.c) (CVE-2019-11815), ืžื” ืฉืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœื’ื™ืฉื” ืœืื–ื•ืจ ื–ื™ื›ืจื•ืŸ ืžืฉื•ื—ืจืจ ื•ื“ื—ื™ื™ืช ืฉื™ืจื•ืช (ืขืœื•ืœื” ืœื”ื•ื‘ื™ืœ ืœื ื™ืฆื•ืœ ื”ื‘ืขื™ื” ืœืืจื’ื•ืŸ ื‘ื™ืฆื•ืข ืงื•ื“). ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžืžืฆื‘ ืžื™ืจื•ืฅ ืฉื™ื›ื•ืœ ืœื”ืชืจื—ืฉ ื‘ืขืช ื‘ื™ืฆื•ืข ื”ืคื•ื ืงืฆื™ื” rds_tcp_kill_sock ืชื•ืš ื ื™ืงื•ื™ ืฉืงืขื™ื ืขื‘ื•ืจ ืžืจื—ื‘ ื”ืฉืžื•ืช ืฉืœ ื”ืจืฉืช.

ืžึดืคืจึธื˜ NDV ื”ื‘ืขื™ื” ืžืกื•ืžื ืช ื›ื ื™ืชื ืช ืœื ื™ืฆื•ืœ ืžืจื—ื•ืง ื“ืจืš ื”ืจืฉืช, ืืš ืื ืœืฉืคื•ื˜ ืœืคื™ ื”ืชื™ืื•ืจ ืชื™ืงื•ื ื™ื, ืœืœื ื ื•ื›ื—ื•ืช ืžืงื•ืžื™ืช ื‘ืžืขืจื›ืช ื•ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืžืจื—ื‘ื™ ืฉืžื•ืช, ืœื ื ื™ืชืŸ ื™ื”ื™ื” ืœืืจื’ืŸ ื”ืชืงืคื” ืžืจื—ื•ืง. ื‘ืคืจื˜, ืœืคื™ ื“ืขื” ืžืคืชื—ื™ SUSE, ื”ืคื’ื™ืขื•ืช ืžื ื•ืฆืœืช ืจืง ื‘ืื•ืคืŸ ืžืงื•ืžื™; ืืจื’ื•ืŸ ื”ืชืงืคื” ืžื•ืจื›ื‘ ืœืžื“ื™ ื•ื“ื•ืจืฉ ื”ืจืฉืื•ืช ื ื•ืกืคื•ืช ื‘ืžืขืจื›ืช. ืื ื‘-NVD ืจืžืช ื”ืกื›ื ื” ืžื•ืขืจื›ืช ื‘-9.3 (CVSS v2) ื•-8.1 (CVSS v2), ืื– ืœืคื™ ื“ื™ืจื•ื’ SUSE, ื”ืกื›ื ื” ืžื•ืขืจื›ืช ื‘-6.4 ื ืงื•ื“ื•ืช ืžืชื•ืš 10.

ื’ื ื ืฆื™ื’ื™ ืื•ื‘ื•ื ื˜ื• ะพั†ะตะฝะธะปะธ ื”ืกื›ื ื” ืฉืœ ื”ื‘ืขื™ื” ื ื—ืฉื‘ืช ื‘ื™ื ื•ื ื™ืช. ื™ื—ื“ ืขื ื–ืืช, ื‘ื”ืชืื ืœืžืคืจื˜ CVSS v3.0, ืœื‘ืขื™ื” ืžื™ื•ื—ืกืช ืจืžืช ืžื•ืจื›ื‘ื•ืช ืชืงื™ืคื” ื’ื‘ื•ื”ื” ื•ืœื™ื›ื•ืœืช ื”ื ื™ืฆื•ืœ ืžื•ืงืฆื•ืช ืจืง 2.2 ื ืงื•ื“ื•ืช ืžืชื•ืš 10.

ืื ืœืฉืคื•ื˜ ืœืคื™ ืœื”ื’ื™ืฉ ืชืœื•ื ื” ืž-Cisco, ื”ืคื’ื™ืขื•ืช ืžื ื•ืฆืœืช ืžืจื—ื•ืง ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืžื ื•ืช TCP ืœืฉื™ืจื•ืชื™ ืจืฉืช ืขื•ื‘ื“ื™ื RDS ื•ื›ื‘ืจ ื™ืฉ ืื‘ ื˜ื™ืคื•ืก ืฉืœ ื”ื ื™ืฆื•ืœ. ืขื“ ื›ืžื” ื”ืžื™ื“ืข ื”ื–ื” ืชื•ืื ืืช ื”ืžืฆื™ืื•ืช ืขื“ื™ื™ืŸ ืœื ื‘ืจื•ืจื”; ืื•ืœื™ ื”ื“ื•"ื— ืจืง ืžืกื’ืจ ื‘ืื•ืคืŸ ืืžื ื•ืชื™ ืืช ื”ื ื—ื•ืช ื”ื™ืกื•ื“ ืฉืœ NVD. ืขืœ ื™ื“ื™ ืžึตื™ื“ึธืข ื ื™ืฆื•ืœ VulDB ืขื“ื™ื™ืŸ ืœื ื ื•ืฆืจ ื•ื”ื‘ืขื™ื” ืžื ื•ืฆืœืช ืจืง ืžืงื•ืžื™ืช.

ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ื‘ืงืจื ืœื™ื ืœืคื ื™ 5.0.8 ื•ื ื—ืกืžืช ืขืœ ื™ื“ื™ ื—ื•ื“ืฉ ืžืจืฅ ืชื™ืงื•ืŸ, ื›ืœื•ืœ ื‘ืงืจื ืœ 5.0.8. ื‘ืจื•ื‘ ื”ื”ืคืฆื•ืช ื”ื‘ืขื™ื” ืœื ื ืคืชืจื” (ื“ื‘ื™ืืŸ, ืจื”ืœ, ืื•ื‘ื•ื ื˜ื•, SUSE). ื”ืชื™ืงื•ืŸ ืฉื•ื—ืจืจ ืขื‘ื•ืจ SLE12 SP3, openSUSE 42.3 ื• ืคื“ื•ืจื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”