ืกืึทืžื‘ืึท ืคืึทืจืคืขืกื˜ื™ืงื˜ 8 ื’ืขืคืขืจืœืขืš ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–

ืงืึธืจืจืขืงื˜ื™ื•ื• ืจื™ืœื™ืกื™ื– ืคื•ืŸ ื“ื™ Samba ืคึผืขืงืœ 4.15.2, 4.14.10 ืื•ืŸ 4.13.14 ื–ืขื ืขืŸ ืืจื•ื™ืก ืžื™ื˜ ื“ื™ ื™ืœื™ืžืึทื ื™ื™ืฉืึทืŸ ืคื•ืŸ 8 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–, ืจื•ื‘ึฟ ืคื•ืŸ ื•ื•ืึธืก ืงืขื ืขืŸ ืคื™ืจืŸ ืฆื• ืึท ื’ืึทื ืฅ ืงืึทืžืคึผืจืึทืžื™ื™ื– ืคื•ืŸ ื“ื™ ืึทืงื˜ื™ื•ื•ืข Directory ืคืขืœื“. ืขืก ืื™ื– ื ืึธื•ื˜ื•ื•ืขืจื“ื™ ืึทื– ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืคืจืื‘ืœืขืžืขืŸ ืื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜ ื–ื™ื ื˜ 2016, ืื•ืŸ ืคื™ื ืฃ ื–ื™ื ื˜ 2020, ืึธื‘ืขืจ, ืื™ื™ืŸ ืคืึทืจืจื™ื›ื˜ืŸ ื’ืขืžืื›ื˜ ืขืก ืื•ืžืžืขื’ืœืขืš ืฆื• ืงืึทื˜ืขืจ ื•ื•ื™ื ื‘ื™ื™ื ื“ื“ ืžื™ื˜ ื“ื™ "ืœืึธื–ืŸ ื˜ืจืึทืกื˜ื™ื“ ื“ืึธื•ืžื™ื™ื ื– = ื ื™ื˜" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ (ื“ื™ ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ื”ืึธื‘ืŸ ื‘ื“ืขื” ืฆื• ื’ืขืฉื•ื•ื™ื ื“ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืืŸ ืื ื“ืขืจ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืžื™ื˜ ืึท ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ. ืคืึทืจืจื™ื›ื˜ืŸ). ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ ืคึผืขืงืœ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืื™ืŸ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ืงืขื ืขืŸ ื–ื™ื™ืŸ ื˜ืจืึทืงื˜ ืื•ื™ืฃ ื“ื™ ื‘ืœืขื˜ืขืจ: Debian, Ubuntu, RHEL, SUSE, Fedora, Arch, FreeBSD.

ืคืึทืจืคืขืกื˜ื™ืงื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–:

  • CVE-2020-25717 - ืจืขื›ื˜ ืฆื• ืึท ืคืœืึธ ืื™ืŸ ื“ื™ ืœืึธื’ื™ืง ืคื•ืŸ ืžืึทืคึผื™ื ื’ ืคืขืœื“ ื™ื•ื–ืขืจื– ืฆื• ื”ื™ื’ืข ืกื™ืกื˜ืขื ื™ื•ื–ืขืจื–, ืึทืŸ ืึทืงื˜ื™ื•ื•ืข Directory ืคืขืœื“ ื‘ืึทื ื™ืฆืขืจ ื•ื•ืึธืก ื”ืื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฉืึทืคึฟืŸ ื ื™ื™ึทืข ืึทืงืึทื•ื ืฅ ืื•ื™ืฃ ื–ื™ื™ืŸ ืกื™ืกื˜ืขื, ื’ืขืจืื˜ืŸ ื“ื•ืจืš ms-DS-MachineAccountQuota, ืงืขืŸ ื‘ืึทืงื•ืžืขืŸ ื•ื•ืึธืจืฆืœ. ืึทืงืกืขืก ืฆื• ืื ื“ืขืจืข ืกื™ืกื˜ืขืžืขืŸ ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ื“ื™ ืคืขืœื“.
  • CVE-2021-3738 ืื™ื– ืึท ื ื•ืฆืŸ ื ืึธืš ืคืจื™ื™ ืึทืงืกืขืก ืื™ืŸ ื“ื™ Samba AD DC RPC ืกืขืจื•ื•ืขืจ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ (dsdb), ื•ื•ืึธืก ืงืขืŸ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืคื™ืจืŸ ืฆื• ืขืกืงืึทืœื™ืจื•ื ื’ ืคื•ืŸ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ื•ื•ืขืŸ ืžืึทื ื™ืคึผื™ืึทืœื™ื™ื˜ื™ื ื’ ืงืึทื ืขืงืฉืึทื ื–.
  • CVE-2016-2124 - ืงืœื™ืขื ื˜ ืงืึทื ืขืงืฉืึทื ื– ื’ืขื’ืจื™ื ื“ืขื˜ ืžื™ื˜ ื“ื™ SMB1 ืคึผืจืึธื˜ืึธืงืึธืœ ืงืขืŸ ื–ื™ื™ืŸ ืกื•ื•ื™ื˜ืฉื˜ ืฆื• ืคืึธืจืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืื™ืŸ ืงืœืึธืจ ื˜ืขืงืกื˜ ืึธื“ืขืจ ื“ื•ืจืš NTLM (ืœืžืฉืœ, ืฆื• ื‘ืึทืฉืœื™ืกืŸ ืงืจืึทื“ืขื ื˜ืฉืึทืœื– ื‘ืขืฉืึทืก MITM ืื ืคืืœืŸ), ืืคื™ืœื• ืื•ื™ื‘ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืึธื“ืขืจ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื”ืื˜ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก ืกืคึผืขืกื™ืคื™ืขื“ ืคึฟืึทืจ ืžืึทื ื“ืึทื˜ืึธืจื™ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื“ื•ืจืš Kerberos.
  • CVE-2020-25722 - ื Samba-ื‘ืื–ื™ืจื˜ ืึทืงื˜ื™ื•ื• Directory ืคืขืœื“ ืงืึธื ื˜ืจืึธืœืœืขืจ ื”ืื˜ ื ื™ืฉื˜ ื“ื•ืจื›ืคื™ืจืŸ ื’ืขื”ืขืจื™ืง ืึทืงืกืขืก ื˜ืฉืขืงืก ืื•ื™ืฃ ืกื˜ืึธืจื“ ื“ืึทื˜ืŸ, ืึทืœืึทื•ื™ื ื’ ืงื™ื™ืŸ ื‘ืึทื ื™ืฆืขืจ ืฆื• ื‘ื™ื™ืคึผืึทืก ืื•ื™ื˜ืึธืจื™ื˜ืขื˜ ื˜ืฉืขืงืก ืื•ืŸ ื’ืึธืจ ืงืึธืžืคึผืจืึธืžื™ืก ื“ื™ ืคืขืœื“.
  • CVE-2020-25718 - ื“ื™ Samba-ื‘ืื–ื™ืจื˜ ืึทืงื˜ื™ื•ื•ืข Directory ืคืขืœื“ ืงืึทื ื˜ืจืึธื•ืœืขืจ ื”ืื˜ ื ื™ืฉื˜ ืจื™ื›ื˜ื™ืง ื™ื–ืึธืœื™ืจืŸ Kerberos ื˜ื™ืงืึทืฅ ืืจื•ื™ืก ื“ื•ืจืš ื“ื™ RODC (ืœื™ื™ืขื ืขืŸ-ื‘ืœื•ื™ื– ืคืขืœื“ ืงืึธื ื˜ืจืึธืœืœืขืจ), ื•ื•ืึธืก ืงืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ื‘ืึทืงื•ืžืขืŸ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ื˜ื™ืงื™ืฅ ืคื•ืŸ ื“ื™ RODC ืึธืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืฆื• ื˜ืึธืŸ ื“ืึธืก.
  • CVE-2020-25719 - Samba-ื‘ืื–ื™ืจื˜ ืึทืงื˜ื™ื•ื• Directory ืคืขืœื“ ืงืึทื ื˜ืจืึธื•ืœืขืจ ื”ืื˜ ื ื™ื˜ ืฉื˜ืขื ื“ื™ืง ื’ืขื ื•ืžืขืŸ ืื™ืŸ ื—ืฉื‘ื•ืŸ ื“ื™ SID ืื•ืŸ PAC ืคืขืœื“ืขืจ ืื™ืŸ Kerberos ื˜ื™ืงื™ืฅ (ื•ื•ืขืŸ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ "gensec:require_pac = ืืžืช", ื ืึธืจ ื“ืขืจ ื ืึธืžืขืŸ ืื™ื– ืึธืคึผื’ืขืฉื˜ืขืœื˜ ืื•ืŸ ื“ื™ PAC ืื™ื– ื ื™ืฉื˜ ื’ืขื ื•ืžืขืŸ ืื™ืŸ ื—ืฉื‘ื•ืŸ), ื•ื•ืึธืก ื“ืขืจืœื•ื™ื‘ื˜ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ, ื•ื•ืึธืก ื”ืื˜ ื“ื™ ืจืขื›ื˜ ืฆื• ืฉืึทืคึฟืŸ ืึทืงืึทื•ื ืฅ ืื•ื™ืฃ ื“ื™ ื”ื™ื’ืข ืกื™ืกื˜ืขื, ื™ืžืคึผืขืจืกืึทื ื™ื™ื˜ ืืŸ ืื ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืื™ืŸ ื“ื™ ืคืขืœื“, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืึท ืคึผืจื™ื•ื•ืœื™ื“ื–ืฉื“ ืื™ื™ื ืขืจ.
  • CVE-2020-25721 - ืคึฟืึทืจ ื™ื•ื–ืขืจื– ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ื™ื“ ื ื™ืฆืŸ Kerberos, ืึท ื™ื™ื ืฆื™ืง ืึทืงื˜ื™ื•ื•ืข Directory ืื™ื“ืขื ื˜ื™ืคึฟื™ืงืึทืฆื™ืข (ืึธื‘ื“ื–ืฉืขืงื˜ืกื™ื“) ืื™ื– ื ื™ื˜ ืฉื˜ืขื ื“ื™ืง ืืจื•ื™ืก, ื•ื•ืึธืก ืงืขืŸ ืคื™ืจืŸ ืฆื• ื™ื ื˜ืขืจืกืขืงืฉืึทื ื– ืฆื•ื•ื™ืฉืŸ ืื™ื™ืŸ ื‘ืึทื ื™ืฆืขืจ ืื•ืŸ ืื ื“ืขืจืŸ.
  • CVE-2021-23192 - ื‘ืขืฉืึทืก ืึท MITM ื‘ืึทืคืึทืœืŸ, ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ืžืขื’ืœืขืš ืฆื• ืฉื•ื•ื™ื ื“ืœ ืคืจืึทื’ืžืึทื ืฅ ืื™ืŸ ื’ืจื•ื™ืก DCE / RPC ืจื™ืงื•ื•ืขืก ืฉืคึผืึทืœื˜ืŸ ืื™ืŸ ืขื˜ืœืขื›ืข ืคึผืึทืจืฅ.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’