ืคื’ื™ืขื•ื™ื•ืช ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก, Glibc, GStreamer, Ghostscript, BIND ื•-CUPS

ืžืกืคืจ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื–ื•ื”ื• ืœืื—ืจื•ื ื”:

  • CVE-2023-39191 ื”ื™ื ืคื’ื™ืขื•ืช ื‘ืชืช-ืžืขืจื›ืช eBPF ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœื”ืกืœื™ื ืืช ื”ื”ืจืฉืื•ืช ืฉืœื• ื•ืœื”ืคืขื™ืœ ืงื•ื“ ื‘ืจืžืช ืœื™ื‘ืช ืœื™ื ื•ืงืก. ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืขืœ ื™ื“ื™ ืื™ืžื•ืช ืฉื’ื•ื™ ืฉืœ ืชื•ื›ื ื™ื•ืช eBPF ืฉื ืฉืœื—ื• ืขืœ ื™ื“ื™ ื”ืžืฉืชืžืฉ ืœื‘ื™ืฆื•ืข. ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื”, ื”ืžืฉืชืžืฉ ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืžืกื•ื’ืœ ืœื˜ืขื•ืŸ ืชื•ื›ื ื™ืช BPF ืžืฉืœื• (ืื ื”ืคืจืžื˜ืจ kernel.unprivileged_bpf_disabled ืžื•ื’ื“ืจ ืœ-0, ืœืžืฉืœ, ื›ืžื• ื‘ืื•ื‘ื•ื ื˜ื• 20.04). ืžื™ื“ืข ืขืœ ื”ืคื’ื™ืขื•ืช ื”ื•ืขื‘ืจ ืœืžืคืชื—ื™ ื”ืœื™ื‘ื” ื‘ื“ืฆืžื‘ืจ ืืฉืชืงื“, ื•ื”ืชื™ืงื•ืŸ ื”ื•ืฆื’ ื‘ืฉืงื˜ ื‘ื™ื ื•ืืจ.
  • CVE-2023-42753 ื‘ืขื™ื” ื‘ืื™ื ื“ืงืกื™ื ืฉืœ ืžืขืจื›ื™ื ื‘ืžื™ืžื•ืฉ ipset ื‘ืชืช-ืžืขืจื›ืช ืœื™ื‘ืช netfilter, ืืฉืจ ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ื ื›ื“ื™ ืœื”ื’ื“ื™ืœ/ืœื”ืงื˜ื™ืŸ ืžืฆื‘ื™ืขื™ื ื•ืœื™ืฆื•ืจ ืชื ืื™ื ืœื›ืชื™ื‘ื” ืื• ืงืจื™ืื” ืœืžื™ืงื•ื ื–ื™ื›ืจื•ืŸ ืžื—ื•ืฅ ืœืžืื’ืจ ื”ืžื•ืงืฆื”. ื›ื“ื™ ืœื‘ื“ื•ืง ื ื•ื›ื—ื•ืช ืฉืœ ืคื’ื™ืขื•ืช, ื”ื•ื›ืŸ ืื‘ ื˜ื™ืคื•ืก ืฉืœ ื ื™ืฆื•ืœ ืฉื’ื•ืจื ืœืกื™ื•ื ื—ืจื™ื’ (ืœื ื ื™ืชืŸ ืœืฉืœื•ืœ ืชืจื—ื™ืฉื™ ื ื™ืฆื•ืœ ืžืกื•ื›ื ื™ื ื™ื•ืชืจ). ื”ืชื™ืงื•ืŸ ื›ืœื•ืœ ื‘ืžื”ื“ื•ืจื•ืช ืœื™ื‘ื” 5.4.257, 6.5.3, 6.4.16, 6.1.53, 5.10.195, 5.15.132.
  • CVE-2023-39192, CVE-2023-39193, CVE-2023-39193 - ืžืกืคืจ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืœื™ื‘ืช ื”ืœื™ื ื•ืงืก ื”ืžื•ื‘ื™ืœื•ืช ืœื“ืœื™ืคื” ืฉืœ ืชื•ื›ืŸ ื–ื™ื›ืจื•ืŸ ื”ืœื™ื‘ื” ืขืงื‘ ื”ื™ื›ื•ืœืช ืœืงืจื•ื ืžืื–ื•ืจื™ื ืžื—ื•ืฅ ืœืžืื’ืจ ื”ืžื•ืงืฆื” ื‘ืคื•ื ืงืฆื™ื•ืช match_flags ื•-u32_match_it ืฉืœ ืชืช-ื”ืžืขืจื›ืช Netfilter, ื›ืžื• ื’ื ื‘ืงื•ื“ ืขื™ื‘ื•ื“ ืžืกื ืŸ ื”ืžืฆื‘. ื”ืคื’ื™ืขื•ืช ืชื•ืงื ื• ื‘ืื•ื’ื•ืกื˜ (1, 2) ื•ื‘ื™ื•ื ื™.
  • CVE-2023-42755 ื”ื™ื ืคื’ื™ืขื•ืช ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœืœื ื”ืจืฉืื•ืช ืœื’ืจื•ื ืœืงืจื™ืกืช ืœื™ื‘ื” ืขืงื‘ ืฉื’ื™ืื” ื‘ืขืช ืขื‘ื•ื“ื” ืขื ืžืฆื‘ื™ืขื™ื ื‘ืžืกื•ื•ื’ ื”ืชืขื‘ื•ืจื” rsvp. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ื‘ืœื™ื‘ืช LTS 6.1, 5.15, 5.10, 5.4, 4.19 ื•-4.14. ื”ื•ื›ืŸ ืื‘ ื˜ื™ืคื•ืก ืœื ื™ืฆื•ืœ. ื”ืชื™ืงื•ืŸ ืขื“ื™ื™ืŸ ืœื ื”ืชืงื‘ืœ ืœืงืจื ืœ ื•ื”ื•ื ื–ืžื™ืŸ ื›ืชื™ืงื•ืŸ.
  • CVE-2023-42756 ื”ื•ื ืžืฆื‘ ืžื™ืจื•ืฅ ื‘ืชืช-ืžืขืจื›ืช ืœื™ื‘ืช NetFilter ืฉื ื™ืชืŸ ืœื ืฆืœ ื›ื“ื™ ืœื’ืจื•ื ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœื”ืคืขื™ืœ ืžืฆื‘ ืคืื ื™ืงื”. ื–ืžื™ืŸ ืื‘ ื˜ื™ืคื•ืก ืœื ื™ืฆื•ืœ ืฉืขื•ื‘ื“ ืœืคื—ื•ืช ื‘ืงืจื ืœื™ื 6.5.rc7, 6.1 ื•-5.10. ื”ืชื™ืงื•ืŸ ืขื“ื™ื™ืŸ ืœื ื”ืชืงื‘ืœ ืœืงืจื ืœ ื•ื”ื•ื ื–ืžื™ืŸ ื›ืชื™ืงื•ืŸ.
  • CVE-2023-4527 ื”ืฆืคืช ืžื—ืกื ื™ืช ื‘ืกืคืจื™ื™ืช Glibc ืžืชืจื—ืฉืช ื‘ืคื•ื ืงืฆื™ื™ืช getaddriinfo ื‘ืขืช ืขื™ื‘ื•ื“ ืชื’ื•ื‘ืช DNS ื’ื“ื•ืœื” ืž-2048 ื‘ืชื™ื. ื”ืคื’ื™ืขื•ืช ืขืœื•ืœื” ืœื”ื•ื‘ื™ืœ ืœื“ืœื™ืคืช ื ืชื•ื ื™ื ืžื—ืกื ื™ืช ืื• ืœืงืจื™ืกื”. ื”ืคื’ื™ืขื•ืช ืžื•ืคื™ืขื” ืจืง ื‘ื’ืจืกืื•ืช Glibc ื—ื“ืฉื•ืช ืž-2.36 ื›ืืฉืจ ืžืฉืชืžืฉื™ื ื‘ืืคืฉืจื•ืช "no-aaaa" ื‘-/etc/resolv.conf.
  • CVE-2023-40474, CVE-2023-40475 ื”ืŸ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืžืกื’ืจืช ื”ืžื•ืœื˜ื™ืžื“ื™ื” ืฉืœ GStreamer ื”ื ื’ืจืžื•ืช ืขืœ ื™ื“ื™ ื”ืฆืคืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘ืžื˜ืคืœื™ ืงื‘ืฆื™ ื•ื™ื“ืื• MXF. ื”ืคื’ื™ืขื•ื™ื•ืช ืขืœื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“ ืชื•ืงืฃ ื‘ืขืช ืขื™ื‘ื•ื“ ืงื‘ืฆื™ MXF ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“ ื‘ื™ื™ืฉื•ื ื”ืžืฉืชืžืฉ ื‘-GStreamer. ื”ื‘ืขื™ื” ืชื•ืงื ื” ื‘ื—ื‘ื™ืœืช gst-plugins-bad 1.22.6.
  • CVE-2023-40476 - ื”ืฆืคืช ื—ื•ืฆืฅ ื‘ืžืขื‘ื“ ื”ื•ื•ื™ื“ืื• H.265 ื”ืžื•ืฆืข ื‘-GStreamer, ื”ืžืืคืฉืจ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืขื™ื‘ื•ื“ ื•ื™ื“ืื• ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“. ื”ืคื’ื™ืขื•ืช ืชื•ืงื ื” ื‘ื—ื‘ื™ืœืช gst-plugins-bad 1.22.6.
  • ื ื™ืชื•ื— - ื ื™ืชื•ื— ื ื™ืฆื•ืœ ื”ืžืฉืชืžืฉ ื‘ืคื’ื™ืขื•ืช CVE-2023-36664 ื‘ื—ื‘ื™ืœืช Ghostscript ื›ื“ื™ ืœื‘ืฆืข ืืช ื”ืงื•ื“ ืฉืœื• ื‘ืขืช ืคืชื™ื—ืช ืžืกืžื›ื™ PostScript ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžืขื™ื‘ื•ื“ ืฉื’ื•ื™ ืฉืœ ืฉืžื•ืช ืงื‘ืฆื™ื ืฉืžืชื—ื™ืœื™ื ื‘ืชื• "|". ืื• ื”ืงื™ื“ื•ืžืช %pipe%. ื”ืคื’ื™ืขื•ืช ืชื•ืงื ื” ื‘ืžื”ื“ื•ืจืช Ghostscript 10.01.2.
  • CVE-2023-3341, CVE-2023-4236 - ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืฉืจืช BIND 9 DNS ืฉืžื•ื‘ื™ืœื•ืช ืœืงืจื™ืกืช ื”ืชื”ืœื™ืš ื”ื ืงื•ื‘ ื‘ืขืช ืขื™ื‘ื•ื“ ื”ื•ื“ืขื•ืช ื‘ืงืจื” ืฉืชื•ื›ื ื ื• ื‘ืžื™ื•ื—ื“ (ืžืกืคื™ืงื” ื’ื™ืฉื” ืœื™ืฆื™ืืช ื”-TCP ืฉื“ืจื›ื” ืžื ื•ื”ืœ ื‘ืฉื (ืคืชื•ื— ืจืง ื›ื‘ืจื™ืจืช ืžื—ื“ืœ). ืขื‘ื•ืจ ืžืžืฉืง loopback), ืื™ืŸ ืฆื•ืจืš ื‘ื™ื“ืข ืฉืœ ืžืคืชื— RNDC) ืื• ื™ืฆื™ืจืช ืขื•ืžืก ื’ื‘ื•ื” ืžืกื•ื™ื ื‘ืžืฆื‘ DNS-over-TLS. ื”ืคื’ื™ืขื•ื™ื•ืช ื ืคืชืจื• ื‘ืžื”ื“ื•ืจื•ืช BIND 9.16.44, 9.18.19 ื•-9.19.17.
  • CVE-2023-4504 ื”ื™ื ืคื’ื™ืขื•ืช ื‘ืฉืจืช ื”ื”ื“ืคืกื” ืฉืœ CUPS ื•ื‘ืกืคืจื™ื™ืช libppd ืฉืžื•ื‘ื™ืœื” ืœื’ืœื™ืฉื” ื‘ืžืื’ืจ ื‘ืขืช ื ื™ืชื•ื— ืžืกืžื›ื™ Postscript ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“. ื™ื™ืชื›ืŸ ืฉื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ื›ื“ื™ ืœืืจื’ืŸ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœ ื”ืื“ื ื‘ืžืขืจื›ืช. ื”ื‘ืขื™ื” ื ืคืชืจื” ื‘ืžื”ื“ื•ืจื•ืช ืฉืœ CUPS 2.4.7 (ืชื™ืงื•ืŸ) ื•-libppd 2.0.0 (ืชื™ืงื•ืŸ).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”