ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-FreeBSD ื”ืžืืคืฉืจื•ืช ืœืš ืœืขืงื•ืฃ ืืช ื”ื’ื‘ืœื•ืช ื”ื›ืœื

ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื–ื•ื”ื• ื‘ืžืขืจื›ืช ื”ื›ืœื ืฉืœ ืกื‘ื™ื‘ื•ืช ืžื‘ื•ื“ื“ื•ืช ืฉืคื•ืชื—ื• ืขืœ ื™ื“ื™ ืคืจื•ื™ืงื˜ FreeBSD:

  • CVE-2020-25582 ื”ื™ื ื ืงื•ื“ืช ืชื•ืจืคื” ื‘ื™ื™ืฉื•ื ืงืจื™ืืช ืžืขืจื›ืช jail_attach, ืฉื ื•ืขื“ื” ืœืฆืจืฃ ืชื”ืœื™ื›ื™ื ื—ื™ืฆื•ื ื™ื™ื ืœืกื‘ื™ื‘ื•ืช ื›ืœื ืงื™ื™ืžื•ืช. ื”ื‘ืขื™ื” ืžืชืจื—ืฉืช ื‘ืขืช ืงืจื™ืื” ืœ-jail_attach ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื•ืช jexec ืื• killall, ื•ืžืืคืฉืจืช ืœืชื”ืœื™ืš ืžื™ื•ื—ืก ืžื‘ื•ื“ื“ ื‘ืชื•ืš ื”ื›ืœื ืœืฉื ื•ืช ืืช ืกืคืจื™ื™ืช ื”ืฉื•ืจืฉ ืฉืœื• ื•ืœืงื‘ืœ ื’ื™ืฉื” ืžืœืื” ืœื›ืœ ื”ืงื‘ืฆื™ื ื•ื”ืกืคืจื™ื•ืช ื‘ืžืขืจื›ืช.
  • CVE-2020-25581 - ืžืฆื‘ ืžื™ืจื•ืฅ ื‘ืขืช ื”ืกืจืช ืชื”ืœื™ื›ื™ื ื‘ืืžืฆืขื•ืช ืงืจื™ืืช ื”ืžืขืจื›ืช jail_remove ืžืืคืฉืจ ืชื”ืœื™ืš ืžื™ื•ื—ืก ื”ืคื•ืขืœ ื‘ืชื•ืš ื›ืœื ื›ื“ื™ ืœืžื ื•ืข ื”ืกืจื” ื›ืืฉืจ ื”ื›ืœื ื ืกื’ืจ ื•ืœืงื‘ืœ ื’ื™ืฉื” ืžืœืื” ืœืžืขืจื›ืช ื‘ืืžืฆืขื•ืช devfs ื›ืืฉืจ ื”ื›ืœื ื™ืชื—ื™ืœ ืœืื—ืจ ืžื›ืŸ ืขื ืื•ืชื” ืกืคืจื™ื™ืช ืฉื•ืจืฉ, ืชื•ืš ื ื™ืฆื•ืœ ื”ืจื’ืข ืฉื‘ื• ื”-devfs ื›ื‘ืจ ืžื•ืชืงืŸ ืœื›ืœื, ืืš ื—ื•ืงื™ ื‘ื™ื“ื•ื“ ืขื“ื™ื™ืŸ ืœื ื™ื•ืฉืžื•.

ื‘ื ื•ืกืฃ, ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืคื’ื™ืขื•ืช (CVE-2020-25580) ื‘ืžื•ื“ื•ืœ PAM pam_login_access, ืฉืื—ืจืื™ ืขืœ ืขื™ื‘ื•ื“ ืงื•ื‘ืฅ login_access, ื”ืžื’ื“ื™ืจ ืืช ื›ืœืœื™ ื”ื’ื™ืฉื” ืœืžืฉืชืžืฉื™ื ื•ืœืงื‘ื•ืฆื•ืช ื”ืžื™ื•ืฉืžื™ื ื‘ืขืช ื”ื›ื ื™ืกื” ืœืžืขืจื›ืช (ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื”ืชื—ื‘ืจื•ืช ื‘ืืžืฆืขื•ืช ื”ืžืกื•ืฃ, sshd ื•-telnetd ืžื•ืชืจื™ื). ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืš ืœืขืงื•ืฃ ืืช ื”ื’ื‘ืœื•ืช ื”ื’ื™ืฉื” ืœื›ื ื™ืกื” ื•ืœื”ืชื—ื‘ืจ ืœืžืจื•ืช ืงื™ื•ืžื ืฉืœ ื›ืœืœื™ื ืื•ืกืจื™ื.

ื”ืคื’ื™ืขื•ื™ื•ืช ืชื•ืงื ื• ื‘ืกื ื™ืคื™ 13.0-STABLE, 12.2-STABLE ื•-11.4-STABLE, ื›ืžื• ื’ื ื‘ืขื“ื›ื•ื ื™ ื”ืชื™ืงื•ืŸ ืฉืœ FreeBSD 12.2-RELEASE-p4 ื•-11.4-RELEASE-p8.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”