ืคื’ื™ืขื•ื™ื•ืช ื‘ืกืคืจื™ื™ืช Expat ื”ืžื•ื‘ื™ืœื•ืช ืœื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืขื™ื‘ื•ื“ ื ืชื•ื ื™ XML

ืกืคืจื™ื™ืช Expat 2.4.5, ื”ืžืฉืžืฉืช ืœื ื™ืชื•ื— ืคื•ืจืžื˜ XML ื‘ืคืจื•ื™ืงื˜ื™ื ืจื‘ื™ื, ื›ื•ืœืœ Apache httpd, OpenOffice, LibreOffice, Firefox, Chromium, Python ื•-Wayland, ืžื‘ื˜ืœืช ื—ืžืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืžืกื•ื›ื ื•ืช, ืืจื‘ืข ืžื”ืŸ ืขืฉื•ื™ื•ืช ืœืืคืฉืจ ืœืš ืœืืจื’ืŸ ืืช ื”ื‘ื™ืฆื•ืข ืฉืœ ื”ืงื•ื“ ืฉืœืš. ื‘ืขืช ืขื™ื‘ื•ื“ ื ืชื•ื ื™ XML ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“ ื‘ื™ื™ืฉื•ืžื™ื ื”ืžืฉืชืžืฉื™ื ื‘-libexpat. ืขื‘ื•ืจ ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื”, ืžื“ื•ื•ื—ื™ื ืขืœ ื ื™ืฆื•ืœ ืขื‘ื•ื“ื”. ืืชื” ื™ื›ื•ืœ ืœืขืงื•ื‘ ืื—ืจ ื”ืคืจืกื•ืžื™ื ืฉืœ ืขื“ื›ื•ื ื™ ื—ื‘ื™ืœื•ืช ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ื ืืœื” Debian, SUSE, Ubuntu, RHEL, Fedora, Gentoo, Arch Linux.

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื–ื•ื”ื•:

  • CVE-2022-25235 - ื”ืฆืคืช ืžืื’ืจ ืขืงื‘ ื‘ื“ื™ืงื” ืฉื’ื•ื™ื” ืฉืœ ื”ืงื™ื“ื•ื“ ืฉืœ ืชื•ื•ื™ Unicode, ืžื” ืฉืขืœื•ืœ ืœื”ื•ื‘ื™ืœ (ื™ืฉ ื ื™ืฆื•ืœ) ืœื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืขื™ื‘ื•ื“ ืจืฆืคื™ื ืžืขื•ืฆื‘ื™ื ื‘ืžื™ื•ื—ื“ ืฉืœ ืชื•ื•ื™ UTF-2 ืฉืœ 3 ื•-8 ื‘ืชื™ื ื‘-XML ืฉืžื•ืช ืชื’ื™ื.
  • CVE-2022-25236 - ืืคืฉืจื•ืช ื”ื—ืœืคื” ืฉืœ ืชื•ื•ื™ ืžืคืจื™ื“ ืžืจื—ื‘ ืฉืžื•ืช ืœืขืจื›ื™ ืชื›ื•ื ื•ืช "xmlns[:prefix]" ื‘-URI. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืš ืœืืจื’ืŸ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืขื™ื‘ื•ื“ ื ืชื•ื ื™ ืชื•ืงืฃ (ื ื™ืฆื•ืœ ื–ืžื™ืŸ).
  • CVE-2022-25313 ืžื™ืฆื•ื™ ืžื—ืกื ื™ืช ืžืชืจื—ืฉืช ื‘ืขืช ื ื™ืชื•ื— ื‘ืœื•ืง "doctype" (DTD), ื›ืคื™ ืฉื ื™ืชืŸ ืœืจืื•ืช ื‘ืงื‘ืฆื™ื ื’ื“ื•ืœื™ื ืž-2 MB ื”ื›ื•ืœืœื™ื ืžืกืคืจ ื’ื“ื•ืœ ืžืื•ื“ ืฉืœ ืกื•ื’ืจื™ื™ื ืคืชื•ื—ื™ื. ื™ื™ืชื›ืŸ ืฉื”ืคื’ื™ืขื•ืช ื™ื›ื•ืœื” ืœืฉืžืฉ ื›ื“ื™ ืœืืจื’ืŸ ืืช ื”ื‘ื™ืฆื•ืข ืฉืœ ืงื•ื“ ืžืฉืœื• ื‘ืžืขืจื›ืช.
  • CVE-2022-25315 ื”ื•ื ื”ืฆืคืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘ืคื•ื ืงืฆื™ื” storeRawNames ืฉืžืชืจื—ืฉืช ืจืง ื‘ืžืขืจื›ื•ืช 64 ืกื™ื‘ื™ื•ืช ื•ื“ื•ืจืฉืช ืขื™ื‘ื•ื“ ื’'ื™ื’ื”-ื‘ื™ื™ื˜ ืฉืœ ื ืชื•ื ื™ื. ื™ื™ืชื›ืŸ ืฉื”ืคื’ื™ืขื•ืช ื™ื›ื•ืœื” ืœืฉืžืฉ ื›ื“ื™ ืœืืจื’ืŸ ืืช ื”ื‘ื™ืฆื•ืข ืฉืœ ืงื•ื“ ืžืฉืœื• ื‘ืžืขืจื›ืช.
  • CVE-2022-25314 ื”ื•ื ื”ืฆืคืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘ืคื•ื ืงืฆื™ื™ืช copyString ืฉืžืชืจื—ืฉืช ืจืง ื‘ืžืขืจื›ื•ืช 64 ืกื™ื‘ื™ื•ืช ื•ื“ื•ืจืฉืช ืขื™ื‘ื•ื“ ื’'ื™ื’ื”-ื‘ื™ื™ื˜ ืฉืœ ื ืชื•ื ื™ื. ื”ื‘ืขื™ื” ืขืœื•ืœื” ืœื’ืจื•ื ืœืžื ื™ืขืช ืฉื™ืจื•ืช.

    ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”