Ho ba kotsing ho pppd le lwIP e lumellang ts'ebetso ea khoutu e hole ka litokelo tsa metso

Ka har'a sephutheloana pppd tsebahatsoa bofokodi (CVE-2020-8597), e o lumellang hore o phethe khoutu ea hau ka ho romella likopo tsa netefatso tse etselitsoeng ka ho khetheha lits'ebetsong tse sebelisang protocol ea PPP (Point-to-Point Protocol) kapa PPPoE (PPP over Ethernet). Liprothokholo tsena hangata li sebelisoa ke bafani ho hlophisa likhokahano ka Ethernet kapa DSL, hape li sebelisoa ho li-VPN tse ling (mohlala, pptpd le. openfortivpn). Ho hlahloba hore na litsamaiso tsa hau li angoa ke bothata itokisitse sebelisa mohlala.

Kotsi e bakoa ke ho tlala ha "buffer" ts'ebetsong ea protocol ea netefatso ea EAP (Extensible Authentication Protocol). Tlhaselo e ka etsoa mothating oa ho netefatsa pele ka ho romella pakete e nang le mofuta oa EAPT_MD5CHAP, ho kenyelletsa le lebitso le lelelele la moamoheli le sa keneleng buffer e fanoeng. Ka lebaka la bothata ba khoutu ea ho lekola boholo ba sebaka sa rhostname, mohlaseli a ka hlakola data ka ntle ho buffer ho stack mme a fihlelle ts'ebetsong ea khoutu ea hae a le hole le litokelo tsa metso. Bofokoli bo iponahatsa ho seva le mahlakoreng a bareki, ke hore. Hase feela seva e ka hlaseloang, empa hape le mofani ea lekang ho hokahanya le seva e laoloang ke mohlaseli (mohlala, mohlaseli a ka qala ho senya seva ka ho ba kotsing, ebe o qala ho hlasela bareki ba hokelang).

Bothata bo ama liphetolelo pppd ho tloha ho 2.4.2 ho ea ho 2.4.8 ho kenyeletsa le ho felisoa ka mokhoa patch. Kotsi le eona ama stack lwIP, empa tlhophiso ea kamehla ho lwIP ha e lumelle tšehetso ea EAP.

Boemo ba ho lokisa bothata ho lisebelisoa tsa kabo bo ka bonoa maqepheng ana: Debian, Botho, RHEL, Fedora, sebelisa, OpenWRT, Arch, NetBSD. Ho RHEL, OpenWRT le SUSE, sephutheloana sa pppd se hahiloe ka ts'ireletso ea "Stack Smashing Protection" e nolofalitsoeng (mokhoa oa "-fstack-protector" ho gcc), o fokotsang tšebeliso e mpe ho hloleha. Ntle le ho ajoa, ho ba kotsing ho boetse ho netefalitsoe lihlahisoa tse ling Cisco (Mookameli oa Mehala) Tl-LINK le Synology (Mookameli oa DiskStation, VisualStation VS960HD le Mookameli oa Router) o sebelisa pppd kapa lwIP khoutu.

Source: opennet.ru

Eketsa ka tlhaloso