{"id":100086,"date":"2021-05-04T22:22:55","date_gmt":"2021-05-04T20:22:55","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej"},"modified":"2021-05-04T22:22:55","modified_gmt":"2021-05-04T20:22:55","slug":"obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej","title":{"rendered":"Aktualizimi i Exim 4.94.2 q\u00eb adreson 10 dob\u00ebsit\u00eb e eksploruara n\u00eb distanc\u00eb","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00cbsht\u00eb publikuar versioni i serverit t\u00eb post\u00ebs Exim 4.94.2 q\u00eb adreson 21 dob\u00ebsi (CVE-2020-28007-CVE-2020-28026, CVE-2021-27216), t\u00eb identifikuara nga kompania Qualys dhe t\u00eb prezantuara me emrin kodues 21Nails. 10 probleme mund t\u00eb shfryt\u00ebzohen nga distanca (p\u00ebrfshir\u00eb p\u00ebr ekzekutimin e kodit me privilegje root), p\u00ebrmes manipulimeve me komandat SMTP gjat\u00eb nd\u00ebrveprimit me serverin.     <\/p>\n<p>T\u00eb gjitha versionet e Exim jan\u00eb t\u00eb prekshme, historiku i t\u00eb cilave \u00ebsht\u00eb ndjekur n\u00eb Git q\u00eb nga viti 2004. Jan\u00eb p\u00ebrgatitur prototipa t\u00eb punuesh\u00ebm p\u00ebr 4 dob\u00ebsi lokale dhe 3 probleme t\u00eb distanc\u00ebs. Dob\u00ebsit\u00eb lokale (CVE-2020-28007, CVE-2020-28008, CVE-2020-28015, CVE-2020-28012) lejojn\u00eb rritjen e privilegjeve deri n\u00eb p\u00ebrdoruesin root. Dy problemet e distanc\u00ebs (CVE-2020-28020, CVE-2020-28018) lejojn\u00eb ekzekutimin e kodit pa autentifikim me privilegje t\u00eb p\u00ebrdoruesit exim (m\u00eb pas mund t\u00eb arrihet root duke shfryt\u00ebzuar nj\u00eb nga dob\u00ebsit\u00eb lokale).     <\/p>\n<p>Vulnerabiliteti CVE-2020-28021 lejon ekzekutimin e kodit n\u00eb distanc\u00eb me t\u00eb drejta root, por k\u00ebrkon akses t\u00eb autentikuar (p\u00ebrdoruesi duhet t\u00eb vendos\u00eb nj\u00eb sesion t\u00eb autentikuar, pas s\u00eb cil\u00ebs mund t\u00eb shfryt\u00ebzoj\u00eb vulnerabilitetin p\u00ebrmes manipulimeve me parametrin AUTH n\u00eb komand\u00ebn MAIL FROM). Problemi shkaktohet nga fakti se sulmuesi mund t\u00eb arrij\u00eb t\u00eb fus\u00eb nj\u00eb varg n\u00eb titullin e skedarit spool p\u00ebr shkak t\u00eb regjistrimit t\u00eb vler\u00ebs authenticated_sender pa e mbrojtur si\u00e7 duhet karakteret speciale (p.sh., duke kaluar komand\u00ebn \u201cMAIL FROM: AUTH=Raven+0AReyes\u201d).        <\/p>\n<p>P\u00ebrve\u00e7 k\u00ebsaj, v\u00ebrehet se ka nj\u00eb vulnerabilitet tjet\u00ebr n\u00eb distanc\u00eb, CVE-2020-28017, q\u00eb \u00ebsht\u00eb i p\u00ebrshtatsh\u00ebm p\u00ebr t\u00eb shfryt\u00ebzuar ekzekutimin e kodit me t\u00eb drejta p\u00ebrdoruesi \u2018exim\u2019 pa autentifikim, por k\u00ebrkon m\u00eb shum\u00eb se 25 GB memorie. P\u00ebr 13 vulnerabilitete t\u00eb tjera, potencialisht mund t\u00eb p\u00ebrgatiten eksploit\u00eb gjithashtu, por puna n\u00eb k\u00ebt\u00eb drejtim ende nuk ka nisur.        <\/p>\n<p>Zhvilluesit e Exim jan\u00eb njoftuar p\u00ebr problemet q\u00eb nga tetori i vitit t\u00eb kaluar dhe kan\u00eb kaluar m\u00eb shum\u00eb se 6 muaj n\u00eb zhvillimin e rregullimeve. T\u00eb gjith\u00eb administrator\u00ebt rekomandohen t\u00eb p\u00ebrdit\u00ebsojn\u00eb menj\u00ebher\u00eb Exim n\u00eb postat e tyre <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/server\/dts-gdansk\/\"   title=\"server\u00eb\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"4516\">server\u00eb<\/a> n\u00eb versionin 4.94.2. T\u00eb gjitha versionet e Exim para l\u00ebshimit 4.94.2 jan\u00eb shpallur t\u00eb vjetra (obsolete). Publikimi i versionit t\u00eb ri \u00ebsht\u00eb koordinuar me distribucionet q\u00eb n\u00eb t\u00eb nj\u00ebjt\u00ebn koh\u00eb publikuan p\u00ebrdit\u00ebsime p\u00ebr paketat: Ubuntu, Arch Linux, FreeBSD, Debian, SUSE dhe Fedora. RHEL dhe CentOS nuk preken nga problemi, pasi Exim nuk \u00ebsht\u00eb n\u00eb depozitat e tyre standarde t\u00eb paketave (n\u00eb EPEL p\u00ebrdit\u00ebsimi akoma mungon).   <\/p>\n<p>Vulnerabilitetet e larg\u00ebta:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2020-28017: Mbushje integer t\u00eb tepruar n\u00eb funksionin receive_add_recipient();\n<li class=\"l\"> CVE-2020-28020: Mbushje integer t\u00eb tepruar n\u00eb funksionin receive_msg();\n<li class=\"l\"> CVE-2020-28023: Leximi nga zona jasht\u00eb memorie t\u00eb alokuar n\u00eb funksionin smtp_setup_msg();\n<li class=\"l\"> CVE-2020-28021: Z\u00ebvend\u00ebsimi i vargut n\u00eb titullin e skedarit spool;\n<li class=\"l\"> CVE-2020-28022: Shkrimi dhe leximi n\u00eb zon\u00eb jasht\u00eb memorie t\u00eb alokuar n\u00eb funksionin extract_option();\n<li class=\"l\"> CVE-2020-28026: Shkurtesa dhe z\u00ebvend\u00ebsimi i vargut n\u00eb funksionin spool_read_header();\n<li class=\"l\"> CVE-2020-28019: D\u00ebshtimi n\u00eb rikthimin e treguesit t\u00eb funksionit pas ndodhis\u00eb s\u00eb nj\u00eb gabimi BDAT;\n<li class=\"l\"> CVE-2020-28024: Mbushje t\u00eb tepruar p\u00ebrmes kufirit t\u00eb posht\u00ebm t\u00eb memories n\u00eb funksionin smtp_ungetc();\n<li class=\"l\"> CVE-2020-28018: Qasje n\u00eb memory pas \u00e7lirimit t\u00eb saj (use-after-free) n\u00eb tls-openssl.c\n<li class=\"l\"> CVE-2020-28025: Leximi nga zona jasht\u00eb memorie t\u00eb alokuar n\u00eb funksionin pdkim_finish_bodyhash().  <\/ul>\n<p>Dob\u00ebsi lokale:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2020-28007: Sulmi n\u00ebp\u00ebrmjet nj\u00eb lidhjeje simbolike n\u00eb katalogun me logun e Exim;\n<li class=\"l\"> CVE-2020-28008: Sulme n\u00eb katalogun e spoolit;\n<li class=\"l\"> CVE-2020-28014: Krijimi i nj\u00eb skedari t\u00eb rast\u00ebsish\u00ebm;\n<li class=\"l\"> CVE-2021-27216: Fshirja e nj\u00eb skedari t\u00eb rast\u00ebsish\u00ebm;\n<li class=\"l\"> CVE-2020-28011: Mbushje mbi buffer n\u00eb funksionin queue_run();\n<li class=\"l\"> CVE-2020-28010: Shkrimi jasht\u00eb buffer-it n\u00eb funksionin main();\n<li class=\"l\"> CVE-2020-28013: Mbushje mbi buffer n\u00eb funksionin parse_fix_phrase();\n<li class=\"l\"> CVE-2020-28016: Shkrimi jasht\u00eb buffer-it n\u00eb funksionin parse_fix_phrase();\n<li class=\"l\"> CVE-2020-28015: Z\u00ebvend\u00ebsimi i vargut n\u00eb titullin e skedarit spool;\n<li class=\"l\"> CVE-2020-28012: Mungesa e flamurit close-on-exec p\u00ebr kanalin e privilegjuar t\u00eb paem\u00ebruar;\n<li class=\"l\"> CVE-2020-28009: Mbushje integer t\u00eb tepruar n\u00eb funksionin get_stdinput().  <\/ul>\n<p>          <center>  <iframe loading=\"lazy\" title=\"Exim Mail Server Dob\u00ebsi t\u00eb M\u00ebdha (21Nails)\" src=\"https:\/\/player.vimeo.com\/video\/544783362\" width=\"640\" height=\"360\"><\/iframe>  <\/center><br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55079\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim 4.94.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 21 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-28007-CVE-2020-28026, CVE-2021-27216), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Qualys \u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c 21Nails. 10 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e (\u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0434\u043b\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root), \u0447\u0435\u0440\u0435\u0437 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u0438 \u0441 SMTP-\u043a\u043e\u043c\u0430\u043d\u0434\u0430\u043c\u0438 \u043f\u0440\u0438 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0438 \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u043c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u0432\u0441\u0435 \u0432\u0435\u0440\u0441\u0438\u0438 Exim, \u0438\u0441\u0442\u043e\u0440\u0438\u044f \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0432 Git [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-100086","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim 4.94.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 21 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-28007-CVE-2020-28026, CVE-2021-27216), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Qualys \u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c 21Nails. 10 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e (\u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0434\u043b\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root), \u0447\u0435\u0440\u0435\u0437 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u0438 \u0441 SMTP-\u043a\u043e\u043c\u0430\u043d\u0434\u0430\u043c\u0438 \u043f\u0440\u0438 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0438 \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u043c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u0432\u0441\u0435 \u0432\u0435\u0440\u0441\u0438\u0438 Exim, \u0438\u0441\u0442\u043e\u0440\u0438\u044f \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0432 Git\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 Exim 4.94.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 10 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim 4.94.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 21 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-28007-CVE-2020-28026, CVE-2021-27216), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Qualys \u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c 21Nails. 10 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e (\u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0434\u043b\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root), \u0447\u0435\u0440\u0435\u0437 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u0438 \u0441 SMTP-\u043a\u043e\u043c\u0430\u043d\u0434\u0430\u043c\u0438 \u043f\u0440\u0438 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0438 \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u043c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u0432\u0441\u0435 \u0432\u0435\u0440\u0441\u0438\u0438 Exim, \u0438\u0441\u0442\u043e\u0440\u0438\u044f \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0432 Git\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-05-04T20:22:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-05-04T20:22:55+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 P\u00ebrdit\u00ebsimi i Exim 4.94.2 q\u00eb adreson 10 dob\u00ebsi t\u00eb shfryt\u00ebzuara nga distanca | ProHoster","description":"\u00cbsht\u00eb publikuar versioni i serverit t\u00eb post\u00ebs Exim 4.94.2 q\u00eb adreson 21 dob\u00ebsi (CVE-2020-28007-CVE-2020-28026, CVE-2021-27216), t\u00eb identifikuara nga kompania Qualys dhe t\u00eb prezantuara me emrin kodues 21Nails. 10 probleme mund t\u00eb shfryt\u00ebzohen nga distanca (p\u00ebrfshir\u00eb p\u00ebr ekzekutimin e kodit me privilegje root), p\u00ebrmes manipulimeve me komandat SMTP gjat\u00eb nd\u00ebrveprimit me serverin. T\u00eb gjitha versionet e Exim jan\u00eb t\u00eb prekshme, historia e t\u00eb cilave \u00ebsht\u00eb ndjekur n\u00eb Git","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 Exim 4.94.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 10 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0432\u044b\u043f\u0443\u0441\u043a \u043f\u043e\u0447\u0442\u043e\u0432\u043e\u0433\u043e \u0441\u0435\u0440\u0432\u0435\u0440\u0430 Exim 4.94.2 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c 21 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-28007-CVE-2020-28026, CVE-2021-27216), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Qualys \u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u044b \u043f\u043e\u0434 \u043a\u043e\u0434\u043e\u0432\u044b\u043c \u0438\u043c\u0435\u043d\u0435\u043c 21Nails. 10 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e (\u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0434\u043b\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root), \u0447\u0435\u0440\u0435\u0437 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u0438 \u0441 SMTP-\u043a\u043e\u043c\u0430\u043d\u0434\u0430\u043c\u0438 \u043f\u0440\u0438 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0438 \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u043c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u0432\u0441\u0435 \u0432\u0435\u0440\u0441\u0438\u0438 Exim, \u0438\u0441\u0442\u043e\u0440\u0438\u044f \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0432 Git","og:url":"https:\/\/prohoster.info\/sq\/blog\/novosti-interneta\/obnovlenie-exim-4-94-2-s-ustraneniem-10-udalyonno-ekspluatiruemyh-uyazvimostej","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-05-04T20:22:55+00:00","article:modified_time":"2021-05-04T20:22:55+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"100086","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-05-04 20:41:07","updated":"2022-10-05 17:52:30","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/100086","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=100086"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/100086\/revisions"}],"predecessor-version":[{"id":164394,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/100086\/revisions\/164394"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=100086"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=100086"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=100086"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}