ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-Git ืฉืžื•ื‘ื™ืœื•ืช ืœื“ืœื™ืคืช ื ืชื•ื ื™ื ื•ื”ื—ืœืคืช ื ืชื•ื ื™ื

ืžื”ื“ื•ืจื•ืช ืžืชืงื ื•ืช ืฉืœ ืžืขืจื›ืช ื‘ืงืจืช ื”ืžืงื•ืจื•ืช ื”ืžื‘ื•ื–ืจืช Git 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7 ื•- 2.30.8 ืคื•ืจืกืžื•, ืืฉืจ ืชื™ืงื ื• ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื”, ื”ืžืฉืคื™ืขื•ืช ืขืœ ืื•ืคื˜ื™ืžื™ื–ืฆื™ื•ืช ืขื‘ื•ืจ ืฉื™ื‘ื•ื˜ ืžืงื•ืžื™ ื•ืคืงื•ื“ืช "git application". ืืชื” ื™ื›ื•ืœ ืœืขืงื•ื‘ ืื—ืจ ืฉื—ืจื•ืจ ืขื“ื›ื•ื ื™ ื”ื—ื‘ื™ืœื•ืช ื‘ื”ืคืฆื•ืช ื‘ื“ืคื™ Debian, Ubuntu, RHEL, SUSE/openSUSE, Fedora, Arch, FreeBSD. ืื ืœื ื ื™ืชืŸ ืœื”ืชืงื™ืŸ ืืช ื”ืขื“ื›ื•ืŸ, ืžื•ืžืœืฅ ื›ืคืชืจื•ืŸ ืขื•ืงืฃ ืœื”ื™ืžื ืข ืžื‘ื™ืฆื•ืข ืคืขื•ืœืช "ื’ื™t clone" ืขื ืืคืฉืจื•ืช "--recurse-submodules" ื‘ืžืื’ืจื™ื ืœื ืžื”ื™ืžื ื™ื, ื•ืœื”ื™ืžื ืข ืžืฉื™ืžื•ืฉ ื‘-"git application" ื•-" git am" ืคืงื•ื“ื•ืช ืขืœ ืžืื’ืจื™ื ืœื ืžื”ื™ืžื ื™ื. ืงื•ื“.

  • ื”ืคื’ื™ืขื•ืช ืฉืœ CVE-2023-22490 ืžืืคืฉืจืช ืœืชื•ืงืฃ ื”ืฉื•ืœื˜ ื‘ืชื•ื›ืŸ ืฉืœ ืžืื’ืจ ืžืฉื•ื›ืคืœ ืœืงื‘ืœ ื’ื™ืฉื” ืœื ืชื•ื ื™ื ืจื’ื™ืฉื™ื ื‘ืžืขืจื›ืช ืฉืœ ื”ืžืฉืชืžืฉ. ืฉื ื™ ืคื’ืžื™ื ืชื•ืจืžื™ื ืœื”ื•ืคืขืชื” ืฉืœ ืคื’ื™ืขื•ืช:

    ื”ืคื’ื ื”ืจืืฉื•ืŸ ืžืืคืฉืจ, ื‘ืขื‘ื•ื“ื” ืขื ืžืื’ืจ ืฉืชื•ื›ื ืŸ ื‘ืžื™ื•ื—ื“, ืœื”ืฉื™ื’ ืฉื™ืžื•ืฉ ื‘ืื•ืคื˜ื™ืžื™ื–ืฆื™ื•ืช ืฉื™ื‘ื•ื˜ ืžืงื•ืžื™ื•ืช ื’ื ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ื˜ืจื ืกืคื•ืจื˜ ื”ืžืงื™ื™ื ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืžืขืจื›ื•ืช ื—ื™ืฆื•ื ื™ื•ืช.

    ื”ืคื’ื ื”ืฉื ื™ ืžืืคืฉืจ ืžื™ืงื•ื ืฉืœ ืงื™ืฉื•ืจ ืกืžืœื™ ื‘ืžืงื•ื ืกืคืจื™ื™ืช $GIT_DIR/objects, ื‘ื“ื•ืžื” ืœืคื’ื™ืขื•ืช CVE-2022-39253, ืฉื”ืชื™ืงื•ืŸ ืขื‘ื•ืจื• ื—ืกื ืืช ื”ืžื™ืงื•ื ืฉืœ ืงื™ืฉื•ืจื™ื ืกื™ืžื‘ื•ืœื™ื™ื ื‘ืกืคืจื™ื™ืช $GIT_DIR/objects, ืืš ืœื ื‘ื“ื•ืง ืืช ื”ืขื•ื‘ื“ื” ืฉืกืคืจื™ื™ืช $GIT_DIR/objects ืขืฆืžื” ืขืฉื•ื™ื” ืœื”ื™ื•ืช ืงื™ืฉื•ืจ ืกืžืœื™.

    ื‘ืžืฆื‘ ืฉื™ื‘ื•ื˜ ืžืงื•ืžื™, git ืžืขื‘ื™ืจ $GIT_DIR/objects ืœืกืคืจื™ื™ืช ื”ื™ืขื“ ืขืœ ื™ื“ื™ ื”ืจื—ืงืช ื”ืงื™ืฉื•ืจื™ื ื”ืกืžืœื™ื™ื, ืžื” ืฉื’ื•ืจื ืœื”ืขืชืงืช ื”ืงื‘ืฆื™ื ืฉื”ืคื ื™ื” ื™ืฉื™ืจื” ืืœื™ื”ื ืœืกืคืจื™ื™ืช ื”ื™ืขื“. ืžืขื‘ืจ ืœืฉื™ืžื•ืฉ ื‘ืื•ืคื˜ื™ืžื™ื–ืฆื™ื•ืช ืฉื™ื‘ื•ื˜ ืžืงื•ืžื™ ืœืชื—ื‘ื•ืจื” ืœื ืžืงื•ืžื™ืช ืžืืคืฉืจ ื ื™ืฆื•ืœ ืฉืœ ืคื’ื™ืขื•ื™ื•ืช ื‘ืขื‘ื•ื“ื” ืขื ืžืื’ืจื™ื ื—ื™ืฆื•ื ื™ื™ื (ืœื“ื•ื’ืžื”, ื”ื›ืœืœื” ืจืงื•ืจืกื™ื‘ื™ืช ืฉืœ ืชืช-ืžื•ื“ื•ืœื™ื ืขื ื”ืคืงื•ื“ื” "git clone โ€”recurse-submodules" ื™ื›ื•ืœื” ืœื”ื•ื‘ื™ืœ ืœืฉื™ื‘ื•ื˜ ืฉืœ ืžืื’ืจ ื–ื“ื•ื ื™ ืืจื•ื– ื›ืชืช-ืžื•ื“ื•ืœ ื‘ืžืื’ืจ ืื—ืจ).

  • ืคื’ื™ืขื•ืช CVE-2023-23946 ืžืืคืฉืจืช ื”ื—ืœืคืช ืชื•ื›ืŸ ืฉืœ ืงื‘ืฆื™ื ืžื—ื•ืฅ ืœืกืคืจื™ื™ืช ื”ืขื‘ื•ื“ื” ืขืœ ื™ื“ื™ ื”ืขื‘ืจืช ืงืœื˜ ื‘ืขืœ ืžื‘ื ื” ืžื™ื•ื—ื“ ืœืคืงื•ื“ื” "git application". ืœื“ื•ื’ืžื”, ื”ืชืงืคื” ื™ื›ื•ืœื” ืœื”ืชื‘ืฆืข ื‘ืžื”ืœืš ืขื™ื‘ื•ื“ ื”ืชื™ืงื•ื ื™ื ืฉื”ื•ื›ื ื• ืขืœ ื™ื“ื™ ืชื•ืงืฃ ื‘-git apply. ื›ื“ื™ ืœื—ืกื•ื ืชื™ืงื•ื ื™ื ืžื™ืฆื™ืจืช ืงื‘ืฆื™ื ืžื—ื•ืฅ ืœืขื•ืชืง ื”ืขื‘ื•ื“ื”, "git application" ื—ื•ืกื ืขื™ื‘ื•ื“ ืฉืœ ืชื™ืงื•ื ื™ื ืฉืžื ืกื™ื ืœื›ืชื•ื‘ ืงื•ื‘ืฅ ื‘ืืžืฆืขื•ืช ืกื™ืžืœื™ื ืงื™ื. ืื‘ืœ ืžืกืชื‘ืจ ืฉืืคืฉืจ ืœืขืงื•ืฃ ืืช ื”ื”ื’ื ื” ื”ื–ื• ืขืœ ื™ื“ื™ ื™ืฆื™ืจืช ืงื™ืฉื•ืจ ืกืžืœื™ ืžืœื›ืชื—ื™ืœื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”