systemdãŠãŒãã£ãªãã£systemd-tmpfilesã«ãå¶åŸ¡äžèœãªååž°ãå¯èœã«ããè匱æ§ïŒCVE-2021-3997ïŒãçºèŠãããŸããããã®åé¡ã¯ã/tmpãã£ã¬ã¯ããªã«å€æ°ã®ãã¹ãããããµããã£ã¬ã¯ããªãäœæããããšã§ãã·ã¹ãã èµ·åäžã«ãµãŒãã¹æåŠãåŒãèµ·ããããã«æªçšãããå¯èœæ§ããããŸããçŸåšãããããšããŠä¿®æ£ãæäŸãããŠããŸãããã®åé¡ã«å¯ŸåŠããããã±ãŒãžæŽæ°ãææ¡ãããŠããŸãã Ubuntu SUSE ã§ã¯å©çšã§ããŸãããã DebianRHELããã³FedoraïŒä¿®æ£ã¯ãã¹ã段éïŒã
æ°åã®ãµããã£ã¬ã¯ããªãäœæãããšãã«ããsystemd-tmpfiles --removeãæäœãå®è¡ãããšãã¹ã¿ãã¯ã®æ¯æžã«ããã¯ã©ãã·ã¥ããŸãã éåžžãsystemd-tmpfiles ãŠãŒãã£ãªãã£ã¯ããã£ã¬ã¯ããªã®åé€ãšäœæã®æäœã XNUMX åã®åŒã³åºã (ãsystemd-tmpfiles âcreate âremove âboot âexclude-prefix=/devã) ã§å®è¡ããŸããæåã«åé€ãå®è¡ãããæ¬¡ã«äœæãå®è¡ãããŸãã å逿®µéã§å€±æãããšã/usr/lib/tmpfiles.d/*.conf ã§æå®ãããéèŠãªãã¡ã€ã«ãäœæãããªããªããŸãã
ããå±éºãªæ»æã·ããªãªã«ã€ããŠãèšåãããŠããã Ubuntu 21.04: systemd-tmpfiles ã®ã¯ã©ãã·ã¥ã«ãã /run/lock/subsys ãã¡ã€ã«ãäœæãããã/run/lock ãã£ã¬ã¯ããªã¯ãã¹ãŠã®ãŠãŒã¶ãŒãæžã蟌ã¿å¯èœã§ãããããæ»æè ã¯èªèº«ã®ãŠãŒã¶ãŒ ID ã§ /run/lock/subsys ãã£ã¬ã¯ããªãäœæããã·ã¹ãã ããã»ã¹ã®ãã㯠ãã¡ã€ã«ãšäº€å·®ããã·ã³ããªã㯠ãªã³ã¯ãäœæããããšã§ãã·ã¹ãã ãã¡ã€ã«ã®äžæžããçµç¹åã§ããŸãã
ããã«ãè匱æ§ãä¿®æ£ããã FlatpakãSambaãFreeRDPãClamavãããã³ Node.js ãããžã§ã¯ãã®æ°ãããªãªãŒã¹ã®å ¬éã«ã泚ç®ã§ããŸãã
- èªå·±å®çµå Flatpak ããã±ãŒãžãæ§ç¯ããããã®ããŒã«ãããã®ä¿®æ£ãªãªãŒã¹ 1.10.6 ããã³ 1.12.3 ã§ã¯ã2021 ã€ã®è匱æ§ãä¿®æ£ãããŸããã 43860 ã€ç®ã®èåŒ±æ§ (CVE-XNUMX-XNUMX) ã§ã¯ãä¿¡é Œã§ããªããªããžããªããããã±ãŒãžãããŠã³ããŒããããšãã«ãã¡ã¿ããŒã¿ã®æäœãã€ã³ã¹ããŒã« ããã»ã¹äžã«ç¹å®ã®é«åºŠãªæš©éã®è¡šç€ºãé衚瀺ã«ããŸãã XNUMX çªç®ã®èåŒ±æ§ (CVE ãªã) ã§ã¯ãã³ãã³ãã flatpak-builder âmirror-screenshots-url ãã«ãããããã±ãŒãžã®ã¢ã»ã³ããªäžã«ãã«ã ãã£ã¬ã¯ããªã®å€åŽã®ãã¡ã€ã« ã·ã¹ãã é åã«ãã£ã¬ã¯ããªãäœæãããå¯èœæ§ããããŸãã
- Samba 4.13.16ã¢ããããŒãã§ã¯ãã¯ã©ã€ã¢ã³ããSMB1ãŸãã¯NFSããŒãã£ã·ã§ã³äžã®ã·ã³ããªãã¯ãªã³ã¯ãæäœããŠã ãµãŒã ãã¡ã€ã«ã·ã¹ãã ã®ãšã¯ã¹ããŒãé åå€ã®ãã£ã¬ã¯ããªïŒãã®åé¡ã¯ç«¶åç¶æ
ã«ãã£ãŠçºçããå®éã«ã¯æªçšã¯å°é£ã§ãããçè«çã«ã¯å¯èœã§ãïŒããã®åé¡ã¯4.13.16ããåã®ããŒãžã§ã³ã«åœ±é¿ããŸãã
åæ§ã®å¥ã®èåŒ±æ§ (CVE-2021-20316) ã«é¢ããã¬ããŒããå ¬éãããŠãããèªèšŒãããã¯ã©ã€ã¢ã³ããã·ã³ããªãã¯ãªã³ã¯ãæäœããããšã§ãFS é åå ã®ãã¡ã€ã«ãŸãã¯ãã£ã¬ã¯ããªã®ã¡ã¿ããŒã¿ã®å 容ãèªã¿åã£ãã倿Žãããã§ããããã«ãªããŸãã ãµãŒã㌠ãšã¯ã¹ããŒããããããŒãã£ã·ã§ã³ã®å€åŽããã®åé¡ã¯ãªãªãŒã¹4.15.0ã§ä¿®æ£ãããŸãããã以åã®ãªãªãŒã¹ã«ã圱é¿ããããŸããå€ãSamba VFSã¢ãŒããã¯ãã£ã§ã¯ãã¡ã¿ããŒã¿æäœããã¡ã€ã«ãã¹ã«ãã€ã³ããããŠããããããã®åé¡ã«å¯ŸåŠã§ããªãããã以åã®ãªãªãŒã¹ã«å¯Ÿããä¿®æ£ã¯å ¬éãããŸããïŒVFSã¬ã€ã€ãŒã¯Samba 4.15ã§å®å šã«åèšèšãããŸããïŒããã®åé¡ã®æ·±å»åºŠã¯ãåé¡ã®è€éããšã察象ã®ãã¡ã€ã«ãŸãã¯ãã£ã¬ã¯ããªãžã®èªã¿åãããã³æžã蟌ã¿ã¢ã¯ã»ã¹ãå¿ èŠãšãããŠãŒã¶ãŒæš©éã«ãã£ãŠè»œæžãããŸãã
- ãªã¢ãŒã ãã¹ã¯ããã ãããã³ã« (RDP) ã®ç¡æå®è£ ãæäŸãã FreeRDP 2.5 ãããžã§ã¯ãã®ãªãªãŒã¹ã§ã¯ãäžæ£ãªãã±ãŒã«ã䜿çšããŠç¹å¥ã«èšèšãããã¬ãžã¹ããªãåŠçãããšãã«ãããã¡ ãªãŒããŒãããŒãåŒãèµ·ããå¯èœæ§ããã 3.0 ã€ã®ã»ãã¥ãªãã£åé¡ (CVE èå¥åãå²ãåœãŠãããŠããªã) ãä¿®æ£ãããŠããŸããèšå®ãééã£ãŠããŠã誀ã£ã圢åŒã®ã¢ããªã³åã瀺ãããŠããŸãã æ°ããããŒãžã§ã³ã®å€æŽç¹ã«ã¯ãOpenSSL XNUMX ã©ã€ãã©ãªã®ãµããŒããTcpConnectTimeout èšå®ã®å®è£ ãLibreSSL ãšã®äºææ§ã®åäžãWayland ããŒã¹ã®ç°å¢ã§ã®ã¯ãªããããŒãã®åé¡ã®è§£æ±ºçãå«ãŸããŸãã
- ç¡æã®ãŠã€ã«ã¹å¯Ÿçããã±ãŒãž ClamAV 0.103.5 ããã³ 0.104.2 ã®æ°ãããªãªãŒã¹ã§ã¯ãèåŒ±æ§ CVE-2022-20698 ãæé€ãããŠããŸãããã®è匱æ§ã¯ããã€ã³ã¿ã®èª€ã£ãèªã¿åãã«é¢é£ããŠãããããã±ãŒãžã libjson- c ã©ã€ãã©ãªãš CL_SCAN_GENERAL_COLLECT_METADATA ãªãã·ã§ã³ãèšå® (clamscan --gen-json) ã§æå¹ã«ãªã£ãŠããŸãã
- Node.js ãã©ãããã©ãŒã æŽæ°ããã°ã©ã 16.13.2ã14.18.3ã17.3.1ãããã³ 12.22.9 ã§ã¯ã2021 ã€ã®è匱æ§ãä¿®æ£ãããŠããŸããSAN (ãµããžã§ã¯ã代æ¿å) ããæåååœ¢åŒ (CVE- 44532 -2021); ä»¶åãã£ãŒã«ããšçºè¡è ãã£ãŒã«ãã®è€æ°ã®å€ã®åæã®åŠçãæ£ãããªããèšŒææžå ã®èšåããããã£ãŒã«ãã®æ€èšŒããã€ãã¹ããããã«äœ¿çšãããå¯èœæ§ããããŸã (CVE-44533-2021)ã èšŒææžã® SAN URI ã¿ã€ãã«é¢é£ããå¶éããã€ãã¹ããŸã (CVE-44531-2022)ã console.table() 颿°ã®å ¥åæ€èšŒãäžååã§ãç©ºã®æååãããžã¿ã« ããŒã«å²ãåœãŠãããã«äœ¿çšãããå¯èœæ§ããããŸãã (CVE-21824-XNUMX)ã
åºæïŒ ãªãŒãã³ããã.ru
