ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ ืฉืœ NTFS-3G ื”ืžืืคืฉืจื•ืช ื’ื™ืฉืช ืฉื•ืจืฉ ืœืžืขืจื›ืช

ืฉื—ืจื•ืจื• ืฉืœ ืคืจื•ื™ืงื˜ NTFS-3G 2022.5.17, ื”ืžืคืชื— ื“ืจื™ื™ื‘ืจ ื•ืขืจื›ืช ื›ืœื™ ืขื–ืจ ืœืขื‘ื•ื“ื” ืขื ืžืขืจื›ืช ื”ืงื‘ืฆื™ื NTFS ื‘ืžืจื—ื‘ ื”ืžืฉืชืžืฉ, ื‘ื™ื˜ืœื• 8 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื”ืžืืคืฉืจื•ืช ืœืš ืœื”ืขืœื•ืช ืืช ื”ื”ืจืฉืื•ืช ืฉืœืš ื‘ืžืขืจื›ืช. ื”ื‘ืขื™ื•ืช ื ื’ืจืžื•ืช ืžื”ื™ืขื“ืจ ื‘ื“ื™ืงื•ืช ืžืชืื™ืžื•ืช ื‘ืขืช ืขื™ื‘ื•ื“ ืืคืฉืจื•ื™ื•ืช ืฉื•ืจืช ื”ืคืงื•ื“ื” ื•ื‘ืขื‘ื•ื“ื” ืขื ืžื˜ื ื ืชื•ื ื™ื ืขืœ ืžื—ื™ืฆื•ืช NTFS.

  • CVE-2022-30783, CVE-2022-30785, CVE-2022-30787 - ืคื’ื™ืขื•ื™ื•ืช ื‘ืžื ื”ืœ ื”ื”ืชืงืŸ NTFS-3G ื”ื™ื“ื•ืจ ืขื ืกืคืจื™ื™ืช libfuse ื”ืžื•ื‘ื ื™ืช (libfuse-lite) ืื• ืขื ืกืคืจื™ื™ืช ื”ืžืขืจื›ืช libfuse2. ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืคืขื™ืœ ืงื•ื“ ืฉืจื™ืจื•ืชื™ ืขื ื”ืจืฉืื•ืช ืฉื•ืจืฉ ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืืคืฉืจื•ื™ื•ืช ืฉื•ืจืช ื”ืคืงื•ื“ื” ืื ื™ืฉ ืœื• ื’ื™ืฉื” ืœืงื•ื‘ืฅ ื”ื”ืคืขืœื” ntfs-3g ื”ืžืกื•ืคืง ืขื ื“ื’ืœ ื”ืฉื•ืจืฉ suid. ื”ื•ื›ื— ืื‘ ื˜ื™ืคื•ืก ืขื•ื‘ื“ ืฉืœ ื”ื ื™ืฆื•ืœ ืขื‘ื•ืจ ื”ืคื’ื™ืขื•ื™ื•ืช.
  • CVE-2021-46790, CVE-2022-30784, CVE-2022-30786, CVE-2022-30788, CVE-2022-30789 - ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืงื•ื“ ื ื™ืชื•ื— ื”ืžื˜ื-ื ืชื•ื ื™ื ื‘ืžื—ื™ืฆื•ืช NTFS, ืžื” ืฉืžื•ื‘ื™ืœ ืœื”ืฆืคืช ืžืื’ืจ ืฉืœ ื—ื•ืกืจ ื™ืฆื™ื‘ื•ืช. ื”ืžื—ืื•ืช . ื”ื”ืชืงืคื” ื™ื›ื•ืœื” ืœื”ืชื‘ืฆืข ื‘ืขืช ืขื™ื‘ื•ื“ ืžื—ื™ืฆืช NTFS-3G ืฉื”ื•ื›ื ื” ืขืœ ื™ื“ื™ ืชื•ืงืฃ. ืœื“ื•ื’ืžื”, ื›ืืฉืจ ืžืฉืชืžืฉ ืžืขืœื” ื›ื•ื ืŸ ืฉื”ื•ื›ืŸ ืขืœ ื™ื“ื™ ืชื•ืงืฃ, ืื• ื›ืืฉืจ ืœืชื•ืงืฃ ื™ืฉ ื’ื™ืฉื” ืžืงื•ืžื™ืช ืœืœื ื”ืจืฉืื•ืช ืœืžืขืจื›ืช. ืื ื”ืžืขืจื›ืช ืžื•ื’ื“ืจืช ืœืขืœื•ืช ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ืžื—ื™ืฆื•ืช NTFS ืขืœ ื›ื•ื ื ื™ื ื—ื™ืฆื•ื ื™ื™ื, ื›ืœ ืžื” ืฉืฆืจื™ืš ื›ื“ื™ ืœืชืงื•ืฃ ื”ื•ื ืœื—ื‘ืจ ืœืžื—ืฉื‘ ืคืœืืฉ USB ืขื ืžื—ื™ืฆื” ืฉืชื•ื›ื ื ื” ื‘ืžื™ื•ื—ื“. ื ื™ืฆื•ืœ ืขื‘ื•ื“ื” ืขื‘ื•ืจ ืคื’ื™ืขื•ื™ื•ืช ืืœื” ื˜ืจื ื”ื•ื›ื—.

    ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”