Apache OpenOffice 4.1.11 ืฉื•ื—ืจืจ

ืœืื—ืจ ื—ืžื™ืฉื” ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื— ื•ืฉื‘ืข ืฉื ื™ื ื•ื—ืฆื™ ืžืื– ื”ืฉื—ืจื•ืจ ื”ืžืฉืžืขื•ืชื™ ื”ืื—ืจื•ืŸ, ื ื•ืฆืจื” ืžื”ื“ื•ืจื” ืžืชืงื ืช ืฉืœ ื—ื‘ื™ืœืช ื”ืžืฉืจื“ Apache OpenOffice 4.1.11, ืฉื”ืฆื™ืขื” 12 ืชื™ืงื•ื ื™ื. ื—ื‘ื™ืœื•ืช ืžื•ื›ื ื•ืช ืžื•ื›ื ื•ืช ืขื‘ื•ืจ Linux, Windows ื•-macOS.

ื”ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื” ืžืชืงื ืช ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื”:

  • CVE-2021-33035 - ืžืืคืฉืจ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืคืชื™ื—ืช ืงื•ื‘ืฅ DBF ื‘ืขืœ ืžื‘ื ื” ืžื™ื•ื—ื“. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืžื›ืš ืฉ-OpenOffice ืžืกืชืžื›ืช ืขืœ ืขืจื›ื™ fieldLength ื•-fieldType ื‘ื›ื•ืชืจืช ืฉืœ ืงื‘ืฆื™ DBF ื›ื“ื™ ืœื”ืงืฆื•ืช ื–ื™ื›ืจื•ืŸ, ืžื‘ืœื™ ืœื‘ื“ื•ืง ืฉืกื•ื’ ื”ื ืชื•ื ื™ื ื‘ืคื•ืขืœ ื‘ืฉื“ื•ืช ืชื•ืื. ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื”, ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืกื•ื’ INTEGER ื‘ืขืจืš fieldType, ืืš ืœืžืงื ื ืชื•ื ื™ื ื’ื“ื•ืœื™ื ื™ื•ืชืจ ื•ืœืฆื™ื™ืŸ ืขืจืš fieldLength ืฉืื™ื ื• ืžืชืื™ื ืœื’ื•ื“ืœ ื”ื ืชื•ื ื™ื ืขื ืกื•ื’ INTEGER, ืžื” ืฉื™ื•ื‘ื™ืœ ืœื–ื ื‘ ื”ื ืชื•ื ื™ื ืžื”ืฉื“ื” ืฉื ื›ืชื‘ ืžืขื‘ืจ ืœืžืื’ืจ ืฉื”ื•ืงืฆื”. ื›ืชื•ืฆืื” ืžื’ืœื™ืฉื” ืžื‘ื•ืงืจืช ืฉืœ ืžืื’ืจ, ืืชื” ื™ื›ื•ืœ ืœื”ื’ื“ื™ืจ ืžื—ื“ืฉ ืืช ืžืฆื‘ื™ืข ื”ื”ื—ื–ืจื” ืžื”ืคื•ื ืงืฆื™ื” ื•ื‘ืืžืฆืขื•ืช ื˜ื›ื ื™ืงื•ืช ืชื›ื ื•ืช ืžื•ื›ื•ื•ื ื•ืช ื”ื—ื–ืจื” (ROP - Return-Oriented Programming), ืœื”ืฉื™ื’ ืืช ื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœืš.
  • CVE-2021-40439 ื”ื™ื ืžืชืงืคืช DoS ืฉืœ "ืžื™ืœื™ืืจื“ ืฆื—ื•ืงื™ื" (ืคืฆืฆืช XML), ืืฉืจ ืžื•ื‘ื™ืœื” ืœืžื™ืฆื•ื™ ืžืฉืื‘ื™ ื”ืžืขืจื›ืช ื”ื–ืžื™ื ื™ื ื‘ืขืช ืขื™ื‘ื•ื“ ืžืกืžืš ืฉืชื•ื›ื ืŸ ื‘ืžื™ื•ื—ื“.
  • CVE-2021-28129 โ€“ ื”ืชื•ื›ืŸ ืฉืœ ื—ื‘ื™ืœืช DEB ื”ื•ืชืงืŸ ื‘ืžืขืจื›ืช ื›ืžืฉืชืžืฉ ืฉืื™ื ื• ืฉื•ืจืฉ.

ืฉื™ื ื•ื™ื™ื ืฉืื™ื ื ื‘ื™ื˜ื—ื•ื ื™ื™ื:

  • ื’ื•ื“ืœ ื”ื’ื•ืคืŸ ื‘ื˜ืงืกื˜ื™ื ืฉืœ ืžื“ื•ืจ ื”ืขื–ืจื” ื”ื•ื’ื“ืœ.
  • ืคืจื™ื˜ ื ื•ืกืฃ ืœืชืคืจื™ื˜ ื”ื•ืกืคื” ื›ื“ื™ ืœืฉืœื•ื˜ ื‘ื”ืฉืคืขื•ืช ืฉืœ ื’ื•ืคื ื™ Fontwork.
  • ื ื•ืกืฃ ืกืžืœ ื—ืกืจ ืœืชืคืจื™ื˜ ืงื•ื‘ืฅ ืขื‘ื•ืจ ืคื•ื ืงืฆื™ื™ืช ื™ื™ืฆื•ื PDF.
  • ื”ื‘ืขื™ื” ืขื ืื•ื‘ื“ืŸ ื“ื™ืื’ืจืžื•ืช ื‘ืขืช ืฉืžื™ืจื” ื‘ืคื•ืจืžื˜ ODS ื ืคืชืจื”.
  • ื‘ืขื™ื” ืขื ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉื™ืžื•ืฉื™ืช ื›ืœืฉื”ื™ ืฉื ื—ืกืžื” ืขืœ ื™ื“ื™ ืชื™ื‘ืช ื”ื“ื•-ืฉื™ื— ืœืื™ืฉื•ืจ ื”ืคืขื•ืœื” ืฉื ื•ืกืคื” ื‘ืžื”ื“ื•ืจื” ื”ืงื•ื“ืžืช ื ืคืชืจื” (ืœื“ื•ื’ืžื”, ืชื™ื‘ืช ื”ื“ื•-ืฉื™ื— ื”ื•ืฆื’ื” ื›ืฉื”ืคื ื™ื” ืœืงื˜ืข ื‘ืื•ืชื• ืžืกืžืš).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”