ื‘-Exim ื”ืชื’ืœื• ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืงืจื™ื˜ื™ื•ืช ื”ืžืืคืฉืจื•ืช ื‘ื™ืฆื•ืข ืงื•ื“ ืฉืจื™ืจื•ืชื™ ื‘ืฉืจืช.

ZDI (Zero Day Initiative) ืคืจืกืžื” ืžื™ื“ืข ืขืœ ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืงืจื™ื˜ื™ื•ืช ืฉื ืžืฆืื• ื‘ืฉืจืช ื”ื“ื•ืืจ ืฉืœ Exim ื”ืžืืคืฉืจื•ืช ื‘ื™ืฆื•ืข ืงื•ื“ ืฉืจื™ืจื•ืชื™ ืžื˜ืขื ืชื”ืœื™ืš ื”ืฉืจืช ืฉืคื•ืชื— ืืช ืคื•ืจื˜ 25. ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื”, ืื™ืŸ ืฆื•ืจืš ื‘ืื™ืžื•ืช ื‘ืฉืจืช.

  1. CVE-2023-42115 - ืžืืคืฉืจ ืœืš ืœื›ืชื•ื‘ ืืช ื”ื ืชื•ื ื™ื ืฉืœืš ืžืขื‘ืจ ืœื’ื‘ื•ืœื•ืช ื”ืžืื’ืจ ื”ืžื•ืงืฆื”. ื ื’ืจืžืช ืขืœ ื™ื“ื™ ืฉื’ื™ืืช ืื™ืžื•ืช ื ืชื•ื ื™ ืงืœื˜ ื‘ืฉื™ืจื•ืช SMTP.
  2. CVE-2023-42116 - ื ื’ืจื ืขืœ ื™ื“ื™ ื”ืขืชืงืช ื ืชื•ื ื™ื ืžื”ืžืฉืชืžืฉ ืœืžืื’ืจ ื‘ื’ื•ื“ืœ ืงื‘ื•ืข ืžื‘ืœื™ ืœื‘ื“ื•ืง ืืช ื”ื’ื•ื“ืœ ื”ื ื“ืจืฉ.
  3. CVE-2023-42117 โ€“ ื ื’ืจื ื’ื ืžื—ื•ืกืจ ืื™ืžื•ืช ืฉืœ ื ืชื•ื ื™ ืงืœื˜ ื‘ื™ืฆื™ืื” 25 ืฉืœ ืฉื™ืจื•ืช SMTP.

ื ืงื•ื“ื•ืช ื”ืชื•ืจืคื” ืžืกื•ืžื ื•ืช ื›-0-day, ืžื” ืฉืžืขื™ื“ ืขืœ ื›ืš ืฉื”ืŸ ืื™ื ืŸ ืžื˜ื•ืคืœื•ืช, ืœืžืจื•ืช ืฉืœืคื™ ZDI, ืžืคืชื—ื™ Exim ื”ื•ื–ื”ืจื• ืžื–ื” ื–ืžืŸ ืจื‘ ืขืœ ื ื•ื›ื—ื•ืชื. ืื•ืœื™ ื”ืชื™ืงื•ืŸ ื™ื”ื™ื” ื‘ื’ืจืกื” 4.97 ืฉืœ ื”ืฉืจืช, ืื‘ืœ ื–ื” ืœื ื‘ื˜ื•ื—.

ื›ื”ื’ื ื” ืžืคื ื™ ืคื’ื™ืขื•ื™ื•ืช ืืœื•, ืžื•ืฆืข ื›ืขืช ืœื”ื’ื‘ื™ืœ ืืช ื”ื’ื™ืฉื” ืœ-SMTP ื‘ื™ืฆื™ืื” 25.

UPD. ื ืจืื” ืฉื”ื“ื‘ืจื™ื ืœื ื›ืœ ื›ืš ื’ืจื•ืขื™ื. ืคื’ื™ืขื•ืช ืืœื• ื”ืŸ ืžืงื•ืžื™ื•ืช ื‘ื˜ื‘ืขืŸ. ื”ื ืœื ืขื•ื‘ื“ื™ื ืื ื”ืฉืจืช ืื™ื ื• ืžืฉืชืžืฉ ื‘ืื™ืžื•ืช NTLM ื•-EXTERNAL, ืื™ื ื• ืกื’ื•ืจ ืžืื—ื•ืจื™ ืคืจื•ืงืกื™, ืื™ื ื• ืžืฉืชืžืฉ ื‘ืฉืจืชื™ DNS ืฉืขืœื•ืœื™ื ืœื”ื™ื•ืช ืžืกื•ื›ื ื™ื ื•ืื™ื ื• ืžืฉืชืžืฉ ื‘-spf ื‘-acl. ืงืจื ืขื•ื“ ...

ืžืงื•ืจ: linux.org.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”