37 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ืคืึทืจืฉื™ื“ืŸ VNC ื™ืžืคึผืœืึทืžืึทื ืฅ

ืคึผืึทื•ื•ืขืœ ื˜ืฉืขืจืขืžื•ืฉืงื™ืŸ ืคื•ืŸ ืงืึทืกืคึผืขืจืกืงื™ ืœืึทื‘ ืึทื ืึทืœื™ื–ื™ืจื˜ ืคืึทืจืฉื™ื“ืŸ ื™ืžืคึผืœืึทืžืึทื ืฅ ืคื•ืŸ ื“ื™ VNC (ื•ื•ื™ืจื˜ื•ืึทืœ ื ืขื˜ื•ื•ืึธืจืง ืงืึทืžืคึผื™ื•ื˜ื™ื ื’) ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก ืกื™ืกื˜ืขื ืื•ืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“ 37 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืคึผืจืึธื‘ืœืขืžืก ื•ื•ืขืŸ ืืจื‘ืขื˜ืŸ ืžื™ื˜ ื–ื›ึผืจื•ืŸ. ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ VNC ืกืขืจื•ื•ืขืจ ื™ืžืคึผืœืึทืžืึทื ืฅ ืงืขื ืขืŸ ื‘ืœื•ื™ื– ื–ื™ื™ืŸ ืขืงืกืคึผืœื•ื™ื˜ืึทื“ ื“ื•ืจืš ืึท ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“ ื‘ืึทื ื™ืฆืขืจ, ืื•ืŸ ืื ืคืืœืŸ ืื•ื™ืฃ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ืงืœื™ืขื ื˜ ืงืึธื“ ื–ืขื ืขืŸ ืžืขื’ืœืขืš ื•ื•ืขืŸ ืึท ื‘ืึทื ื™ืฆืขืจ ืงืึทื ืขืงืฅ ืฆื• ืึท ืกืขืจื•ื•ืขืจ ืงืึทื ื˜ืจืึธื•ืœื“ ื“ื•ืจืš ืึท ืึทื˜ืึทืงืขืจ.

ื“ื™ ื’ืจืขืกื˜ืข ื ื•ืžืขืจ ืคื•ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื’ืขืคึฟื•ื ืขืŸ ืื™ืŸ ื“ืขื ืคึผืขืงืœ ื•ืœื˜ืจืึทื•ื•ื ืง, ื‘ื ื™ืžืฆื ื‘ืœื•ื™ื– ืคึฟืึทืจ ื“ื™ Windows ืคึผืœืึทื˜ืคืึธืจืžืข. ื ื’ืึทื ืฅ ืคื•ืŸ 22 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ UltraVNC. 13 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืงืขืŸ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืคื™ืจืŸ ืฆื• ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืื•ื™ืฃ ื“ื™ ืกื™ืกื˜ืขื, 5 ืฆื• ื–ื›ึผืจื•ืŸ ืœื™ืงืก ืื•ืŸ 4 ืฆื• ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜.
ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ืžืขืœื“ื•ื ื’ 1.2.3.0.

ืื™ ืŸ ื“ืข ืจ ืืคืขื ืข ืจ ื‘ื™ื‘ืœื™ืื˜ืข ืง LibVNC (LibVNCServer ืื•ืŸ LibVNCClient), ื•ื•ืึธืก ื’ืขื•ื•ื™ื™ื ื˜ ื“ื•ืจืš ืื™ืŸ VirtualBox, 10 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“.
5 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2018-20020, CVE-2018-20019, CVE-2018-15127, CVE-2018-15126, CVE-2018-6307) ื–ืขื ืขืŸ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืึท ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ืื•ืŸ ืงืขื ืขืŸ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืคื™ืจืŸ ืฆื• ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’. 3 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืงืขื ืขืŸ ืคื™ืจืŸ ืฆื• ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืœื™ืงืึทื“ื–ืฉ, 2 ืฆื• ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜.
ืึทืœืข ืคึผืจืึธื‘ืœืขืžืก ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ื“ื•ืจืš ื“ื™ ื“ืขื•ื•ืขืœืึธืคึผืขืจืก, ืึธื‘ืขืจ ื“ื™ ืขื ื“ืขืจื•ื ื’ืขืŸ ื–ืขื ืขืŸ ื ืึธืš ืฉืคื™ื’ืœื˜ ื–ื™ืš ื‘ืœื•ื™ื– ืื™ืŸ ื“ื™ ื‘ืขืœ ืฆื•ื•ื™ื™ึทื’.

ะ’ ื˜ื™ื™ื˜ื•ื•ื ืง (ื˜ืขืกื˜ืขื“ ืงืจื™ื™ึทื–-ืคึผืœืึทื˜ืคืึธืจืžืข ืœืขื’ืึทื˜ ืฆื•ื•ื™ื™ึทื’ 1.3, ื–ื™ื ื˜ ื“ื™ ืงืจืึทื ื˜ ื•ื•ืขืจืกื™ืข 2.x ืื™ื– ื‘ืืคืจื™ื™ื˜ ื‘ืœื•ื™ื– ืคึฟืึทืจ Windows), 4 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ื“ื™ืกืงืึทื•ื•ืขืจื“. ื“ืจื™ื™ ืคืจืื‘ืœืขืžืขืŸ (CVE-2019-15679, CVE-2019-15678, CVE-2019-8287) ื–ืขื ืขืŸ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื•ื– ืื™ืŸ ื“ื™ InitialiseRFBConnection, rfbServerCutText ืื•ืŸ HandleCoRREBBP ืคืึทื ื’ืงืฉืึทื ื–, ืื•ืŸ ืงืขื ืขืŸ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืคื™ืจืŸ ืฆื• ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’. ืื™ื™ืŸ ืคืจืื‘ืœืขื (CVE-2019-15680) ืคื™ืจื˜ ืฆื• ืึท ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜. ืืคื™ืœื• ื“ื™ TightVNC ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ื–ืขื ืขืŸ ื’ืขื•ื•ืขืŸ ื ืึธื•ื˜ืึทืคื™ื™ื“ ื•ื•ืขื’ืŸ ื“ื™ ืคืจืื‘ืœืขืžืขืŸ ืœืขืฆื˜ืข ื™ืึธืจ, ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื‘ืœื™ื™ื‘ืŸ ืึทื ืงืขืจืขืงื˜ื™ื“.

ืื™ืŸ ืึท ืงืจื™ื™ึทื–-ืคึผืœืึทื˜ืคืึธืจืžืข ืคึผืขืงืœ ื˜ื•ืจื‘ืึธื•ื•ื ืง (ืึท ื’ืึธืคึผืœ ืคื•ืŸ TightVNC 1.3 ื•ื•ืึธืก ื ื™ืฆื˜ ื“ื™ libjpeg-turbo ื‘ื™ื‘ืœื™ืึธื˜ืขืง), ื‘ืœื•ื™ื– ืื™ื™ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื’ืขืคึฟื•ื ืขืŸ (CVE-2019-15683), ืึธื‘ืขืจ ืขืก ืื™ื– ื’ืขืคืขืจืœืขืš ืื•ืŸ ืื•ื™ื‘ ืื™ืจ ื”ืึธื‘ืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“ ืึทืงืกืขืก ืฆื• ื“ื™ ืกืขืจื•ื•ืขืจ, ืขืก ืžืื›ื˜ ืขืก ืžืขื’ืœืขืš ืฆื• ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ื“ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื“ื™ื™ืŸ ืงืึธื“, ื•ื•ื™ื™ึทืœ ืื•ื™ื‘ ื“ื™ ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื•ื–, ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืฆื•ืจื™ืงืงื•ืžืขืŸ ืึทื“ืจืขืก. ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ืกืึทืœื•ื•ื“ ืงืกื ื•ืžืงืก ืื•ื™ื’ื•ืกื˜ ืื•ืŸ ื˜ื•ื˜ ื ื™ืฉื˜ ื“ืขืจืฉื™ื™ึทื ืขืŸ ืื™ืŸ ื“ื™ ืงืจืึทื ื˜ ืžืขืœื“ื•ื ื’ 2.2.3.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’