ืขืงืกื™ื 4.94.2 ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืžื™ื˜ ืคื™ืงืกื™ื– ืคึฟืึทืจ 10 ืจื™ืžืึธื•ื˜ืœื™ ืขืงืกืคึผืœื•ื™ื˜ืึทื‘ืึทืœ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–

ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ื™ ืขืงืกื™ื 4.94.2 ืคึผืึธืกื˜ ืกืขืจื•ื•ืขืจ ืื™ื– ืืจื•ื™ืก ืžื™ื˜ ื“ื™ ื™ืœื™ืžืึทื ื™ื™ืฉืึทืŸ ืคื•ืŸ 21 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2020-28007-CVE-2020-28026, CVE-2021-27216), ื•ื•ืึธืก ื–ืขื ืขืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื“ื•ืจืš Qualys ืื•ืŸ ื“ืขืจืœืื ื’ื˜ ืื•ื ื˜ืขืจ ื“ื™ ืงืึธื“ ื ืึธืžืขืŸ 21 ื ืขื’ืœ. 10 ืคึผืจืึธื‘ืœืขืžืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ืจื™ืžืึธื•ื˜ืœื™ ืขืงืกืคึผืœื•ื™ื˜ืึทื“ (ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืขืงืกืึทืงื™ื•ื˜ื™ื ื’ ืงืึธื“ ืžื™ื˜ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜) ื“ื•ืจืš ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทืŸ ืคื•ืŸ SMTP ืงืึทืžืึทื ื“ื– ื•ื•ืขืŸ ื™ื ื˜ืขืจืึทืงื˜ื™ื ื’ ืžื™ื˜ ื“ื™ ืกืขืจื•ื•ืขืจ.

ืึทืœืข ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ ืขืงืกื™ื, ื•ื•ืขืžืขื ืก ื’ืขืฉื™ื›ื˜ืข ืื™ื– ืฉืคึผื™ืจื˜ ืื™ืŸ ื’ื™ื˜ ื–ื™ื ื˜ 2004, ื–ืขื ืขืŸ ืึทืคืขืงื˜ืึทื“ ื“ื•ืจืš ื“ืขื ืคึผืจืึธื‘ืœืขื. ืืจื‘ืขื˜ืŸ ืคึผืจืึธื•ื˜ืึทื˜ื™ื™ืคึผืก ืคื•ืŸ ืขืงืกืคึผืœื•ื™ืฅ ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืฆื•ื’ืขื’ืจื™ื™ื˜ ืคึฟืึทืจ 4 ื”ื™ื’ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื•ืŸ 3 ื•ื•ื™ื™ึทื˜ ืคึผืจืึธื‘ืœืขืžืก. ืขืงืกืคึผืœืึธื™ืฅ ืคึฟืึทืจ ื”ื™ื’ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2020-28007, CVE-2020-28008, CVE-2020-28015, CVE-2020-28012) ืœืึธื–ืŸ ืื™ืจ ืฆื• ื”ืขื›ืขืจืŸ ื“ื™ื™ืŸ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืฆื• ื“ืขืจ ื•ื•ืึธืจืฆืœ ื‘ืึทื ื™ืฆืขืจ. ืฆื•ื•ื™ื™ ื•ื•ื™ื™ึทื˜ ื™ืฉื•ื– (CVE-2020-28020, CVE-2020-28018) ืœืึธื–ืŸ ืงืึธื“ ืฆื• ื–ื™ื™ืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื•ื•ื™ ื“ืขืจ ืขืงืกื™ื ื‘ืึทื ื™ืฆืขืจ (ืื™ืจ ืงืขื ื˜ ื‘ืึทืงื•ืžืขืŸ ื•ื•ืึธืจืฆืœ ืึทืงืกืขืก ื“ื•ืจืš ืขืงืกืคึผืœื•ื™ื˜ื™ื ื’ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ื”ื™ื’ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–).

ื“ื™ CVE-2020-28021 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืึทืœืึทื•ื– ื’ืœื™ื™ืš ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื•ื•ื™ื™ึทื˜ ืงืึธื“ ืžื™ื˜ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜, ืึธื‘ืขืจ ืจื™ืงื•ื•ื™ื™ืขืจื– ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“ ืึทืงืกืขืก (ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืžื•ื–ืŸ ืคืึทืจืœื™ื™ื’ืŸ ืึทืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“ ืกืขืกื™ืข, ื ืึธืš ื•ื•ืึธืก ื–ื™ื™ ืงืขื ืขืŸ ื ื•ืฆืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื“ื•ืจืš ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ AUTH ืคึผืึทืจืึทืžืขื˜ืขืจ ืื™ืŸ ื“ื™ MAIL FROM ื‘ืึทืคึฟืขืœ). ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื“ื™ ืคืึทืงื˜ ืึทื– ืึท ืึทื˜ืึทืงืขืจ ืงืขื ืขืŸ ื“ืขืจื’ืจื™ื™ื›ืŸ ืฉื˜ืจื™ืงืœ ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ืื™ืŸ ื“ื™ ื›ืขื“ืขืจ ืคื•ืŸ ืึท ืฉืคึผื•ืœืงืข ื˜ืขืงืข ื“ื•ืจืš ืฉืจื™ื™ื‘ืŸ ื“ื™ ืึทื•ื˜ื”ืขื ื˜ื™ืงืึทื˜ืขื“_ืกืขื ื“ืขืจ ื•ื•ืขืจื˜ ืึธืŸ ืจืขื›ื˜ ืึทื ื˜ืœื•ื™ืคืŸ ืกืคึผืขืฆื™ืขืœืข ืื•ืชื™ื•ืช (ืœืžืฉืœ, ื“ื•ืจืš ืคืึธืจืŸ ื“ื™ ื‘ืึทืคึฟืขืœ "MAIL FROM: <> AUTH=Raven + 0AReyes โ€).

ื“ืขืจืฆื•, ืขืก ืื™ื– ื‘ืืžืขืจืงื˜ ืึทื– ืืŸ ืื ื“ืขืจ ื•ื•ื™ื™ึทื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, CVE-2020-28017, ืื™ื– ืขืงืกืคึผืœื•ื™ื˜ืึทื‘ืึทืœ ืฆื• ื•ื™ืกืคื™ืจืŸ ืงืึธื“ ืžื™ื˜ "ืขืงืกื™ื" ื‘ืึทื ื™ืฆืขืจ ืจืขื›ื˜ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ, ืึธื‘ืขืจ ืจื™ืงื•ื•ื™ื™ืขืจื– ืžืขืจ ื•ื•ื™ 25 ื’ื™ื’ืื‘ื™ื™ื˜ ืคื•ืŸ ื–ื›ึผืจื•ืŸ. ืคึฟืึทืจ ื“ื™ ืจื•ืขืŸ 13 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–, ืขืงืกืคึผืœื•ื™ืฅ ืงืขืŸ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืื•ื™ืš ื–ื™ื™ืŸ ืฆื•ื’ืขื’ืจื™ื™ื˜, ืึธื‘ืขืจ ืึทืจื‘ืขื˜ ืื™ืŸ ื“ืขื ืจื™ื›ื˜ื•ื ื’ ืื™ื– ื ืึธืš ื ื™ืฉื˜ ื“ื•ืจื›ื’ืขืงืึธื›ื˜.

ื“ื™ ืขืงืกื™ื ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ื–ืขื ืขืŸ ื ืึธื•ื˜ืึทืคื™ื™ื“ ืคื•ืŸ ื“ื™ ืคึผืจืึธื‘ืœืขืžืก ืฆื•ืจื™ืง ืื™ืŸ ืืงื˜ืื‘ืขืจ ืœืขืฆื˜ืข ื™ืึธืจ ืื•ืŸ ืคืืจื‘ืจืื›ื˜ ืžืขืจ ื•ื•ื™ 6 ื—ื“ืฉื™ื ืฆื• ืึทื ื˜ื•ื•ื™ืงืœืขืŸ ืคื™ืงืกื™ื–. ืึทืœืข ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจืก ื–ืขื ืขืŸ ืจืขืงืึทืžืขื ื“ื™ื“ ืฆื• ืขืจื“ื–ืฉืึทื ื˜ืœื™ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืขืงืกื™ื ืื•ื™ืฃ ื–ื™ื™ืขืจ ืคึผืึธืกื˜ ืกืขืจื•ื•ืขืจืก ืฆื• ื•ื•ืขืจืกื™ืข 4.94.2. ืึทืœืข ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ ืขืงืกื™ื ืื™ื™ื“ืขืจ ืžืขืœื“ื•ื ื’ 4.94.2 ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ื“ืขืจืงืœืขืจื˜ ืคืึทืจืขืœื˜ืขืจื˜. ื“ื™ ื•ื™ืกื’ืึทื‘ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข ืื™ื– ื’ืขื•ื•ืขืŸ ืงืึธื•ืึธืจื“ืึทื ื™ื™ื˜ื™ื“ ืžื™ื˜ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ื•ื•ืึธืก ืกื™ื™ืžืึทืœื˜ื™ื™ื ื™ืึทืกืœื™ ืืจื•ื™ืก ืคึผืขืงืœ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ: ื•ื‘ื•ื ื˜ื•, ืึทืจื˜ืฉ ืœื™ื ื•ืงืก, ืคืจืขืขื‘ืกื“, ื“ืขื‘ื™ืึทืŸ, SUSE ืื•ืŸ ืคืขื“ืึธืจืึท. RHEL ืื•ืŸ CentOS ื–ืขื ืขืŸ ื ื™ืฉื˜ ืึทืคืขืงื˜ืึทื“ ื“ื•ืจืš ื“ืขื ืคึผืจืึธื‘ืœืขื, ื•ื•ื™ื™ึทืœ ืขืงืกื™ื ืื™ื– ื ื™ืฉื˜ ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ื–ื™ื™ืขืจ ื ืึธืจืžืึทืœ ืคึผืขืงืœ ืจื™ืคึผืึทื–ืึทื˜ืึธืจื™ (EPEL ื”ืื˜ ื ื™ืฉื˜ ื ืึธืš ืึท ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ).

ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–:

  • CVE-2020-28017: ื™ื ื˜ืขื’ืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ืื™ืŸ ื“ื™ receive_add_recipient () ืคึฟื•ื ืงืฆื™ืข;
  • CVE-2020-28020: ื™ื ื˜ืึทื“ื–ืฉืขืจ ืœื•ื™ืคืŸ ืื™ืŸ ื“ื™ receive_msg () ืคึฟื•ื ืงืฆื™ืข;
  • CVE-2020-28023: ืึทืจื•ื™ืก-ืคื•ืŸ-ื‘ืึทื•ื ื“ ืœื™ื™ืขื ืขืŸ ืื™ืŸ smtp_setup_msg ();
  • CVE-2020-28021: Newline ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ืื™ืŸ ืฉืคึผื•ืœืงืข ื˜ืขืงืข ื›ืขื“ืขืจ;
  • CVE-2020-28022: ืฉืจื™ื™ื‘ ืื•ืŸ ืœื™ื™ืขื ืขืŸ ืื™ืŸ ืึท ื’ืขื’ื ื˜ ืึทืจื•ื™ืก ื“ื™ ืึทืœืึทืงื™ื™ื˜ื™ื“ ื‘ืึทืคืขืจ ืื™ืŸ ื“ื™ ืขืงืกื˜ืจืึทืงื˜_ืึธืคึผื˜ื™ืึธืŸ () ืคึฟื•ื ืงืฆื™ืข;
  • CVE-2020-28026: ืฉื˜ืจื™ืงืœ ื˜ืจืึทื ื’ืงื™ื™ืฉืึทืŸ ืื•ืŸ ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ืื™ืŸ spool_read_header ();
  • CVE-2020-28019: ืงืจืึทืš ื•ื•ืขืŸ ื‘ืึทืฉื˜ืขื˜ื™ืง ืึท ืคื•ื ืงืฆื™ืข ื˜ื™ื™ึทื˜ืœ ื ืึธืš ืึท BDAT ื˜ืขื•ืช ืึทืงืขืจื–;
  • CVE-2020-28024: ื‘ืึทืคืขืจ ืึทื ื“ืขืจืคืœืึธื• ืื™ืŸ ื“ื™ smtp_ungetc() ืคึฟื•ื ืงืฆื™ืข;
  • CVE-2020-28018: ื ื™ืฆืŸ-ื ืึธืš-ืคืจื™ื™ ื‘ืึทืคืขืจ ืึทืงืกืขืก ืื™ืŸ tls-openssl.c
  • CVE-2020-28025: ืึทืŸ ืื•ื™ืก-ืคื•ืŸ-ื‘ืึทื•ื ื“ ืœื™ื™ืขื ืขืŸ ืื™ืŸ ื“ื™ pdkim_finish_bodyhash () ืคึฟื•ื ืงืฆื™ืข.

ืœืืงืืœืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–:

  • CVE-2020-28007: ืกื™ืžื‘ืึธืœื™ืฉ ืœื™ื ืง ื‘ืึทืคืึทืœืŸ ืื™ืŸ ื“ื™ ืขืงืกื™ื ืงืœืึธืฅ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ;
  • CVE-2020-28008: ืฉืคึผื•ืœืงืข ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืื ืคืืœืŸ;
  • CVE-2020-28014: ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ื˜ืขืงืข ืฉืึทืคื•ื ื’;
  • CVE-2021-27216: ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ื˜ืขืงืข ื“ื™ืœื™ืฉืึทืŸ;
  • CVE-2020-28011: ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ืื™ืŸ queue_run ();
  • CVE-2020-28010: ืึทืจื•ื™ืก-ืคื•ืŸ-ื‘ืึทื•ื ื“ ืฉืจื™ื™ึทื‘ืŸ ืื™ืŸ ื”ื•ื™ืคึผื˜ ();
  • CVE-2020-28013: ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ืื™ืŸ ืคื•ื ืงืฆื™ืข parse_fix_phrase ();
  • CVE-2020-28016: ืึทืจื•ื™ืก-ืคื•ืŸ-ื‘ืึทื•ื ื“ ืฉืจื™ื™ึทื‘ืŸ ืื™ืŸ parse_fix_phrase ();
  • CVE-2020-28015: Newline ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ืื™ืŸ ืฉืคึผื•ืœืงืข ื˜ืขืงืข ื›ืขื“ืขืจ;
  • CVE-2020-28012: ืคืขืœื ื“ื™ืง ื ืึธืขื ื˜-ืื•ื™ืฃ-ืขืงืกืขืง ืคืึธืŸ ืคึฟืึทืจ ืึท ืคึผืจื™ื•ื•ืœื™ื“ื–ืฉื“ ืึทื ื ื™ื™ืžื“ ืจืขืจ;
  • CVE-2020-28009: ื™ื ื˜ืึทื“ื–ืฉืขืจ ืœื•ื™ืคืŸ ืื™ืŸ ื“ื™ get_stdinput () ืคึฟื•ื ืงืฆื™ืข.



ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’