Te whakaraerae i roto i te pppd me te lwIP e taea ai te mahi waehere mamao me nga painga pakiaka

Kei te kete pppd kua tautuhia whakaraeraetanga (CVE-2020-8597), ka taea e koe te mahi i to waehere ma te tuku tono motuhēhēnga i hangaia motuhake ki nga punaha ma te whakamahi i te kawa PPP (Point-to-Point Protocol) PPPoE ranei (PPP over Ethernet). Ko enei tikanga ka whakamahia e nga kaiwhakarato ki te whakarite hononga ma te Ethernet, DSL ranei, ka whakamahia ano hoki ki etahi VPN (hei tauira, pptpd me openfortivpn). Ki te tirohia mena kei te raru o punaha i te raru kua rite whakamahi tauira.

Ko te whakaraeraetanga ka puta mai i te puhake putunga i roto i te whakatinanatanga o te kawa motuhēhēnga EAP (Extensible Authentication Protocol). Ka taea te whakaeke i te waahi i mua i te whakamotuhēhēnga mā te tuku i tētahi pākete me te momo EAPT_MD5CHAP, tae atu ki te ingoa ope tino roa e kore e uru ki roto i te parepare kua tohaina. Na te hapa i roto i te waehere mo te tirotiro i te rahi o te mara ingoa rhost, ka taea e te kaitukino te tuhirua i nga raraunga ki waho o te parepare i runga i te puranga me te whakatutuki i te mahi mamao o tana waehere me nga mana pakiaka. Ka kitea te whakaraeraetanga i runga i te taha o te tūmau me te taha kiritaki, arā. Ehara i te mea ka taea te whakaeke i te tūmau anake, engari he kiritaki ano hoki e ngana ana ki te hono atu ki te tūmau e whakahaeretia ana e te kaitawhai (hei tauira, ka taea e te kaitukino te hack tuatahi i te tūmau na roto i te whakaraeraetanga, katahi ka timata ki te whakaeke i nga kiritaki hono).

Ka pa te raru ki nga putanga pppd mai i te 2.4.2 ki te 2.4.8 whakauru me te whakakore i te ahua papaki. Whakaraerae hoki ka pa tāpae lwIP, engari ko te whirihoranga taunoa i roto i te lwIP kaore e taea te tautoko EAP.

Ko te mana o te whakatika i te raru i roto i nga kete tohatoha ka taea te tiro ki enei wharangi: Debian, Ubuntu, RHEL, Fedora, SUSE, TuwheraWRT, kikorangi, NetBSD. I runga i te RHEL, OpenWRT me SUSE, ka hangaia te kete pppd me te whakamarumaru "Stack Smashing Protection" kua whakahohea (te aratau "-fstack-protector" i roto i te gcc), e whakawhāiti ana i te whakamahi ki te kore. I tua atu i nga tohatoha, kua whakapumautia ano te whakaraeraetanga ki etahi hua Cisco (Kaiwhakahaere Waea) TP-LINK me te Synology (Kaiwhakahaere DiskStation, VisualStation VS960HD me te Kaiwhakahaere Router) ma te whakamahi i te pppd, lwIP waehere ranei.

Source: opennet.ru

Tāpiri i te kōrero