ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืคึฟืึทืจ Java SE, MySQL, VirtualBox ืื•ืŸ ืื ื“ืขืจืข ืึธืจืึทืงืœืข ืคึผืจืึธื“ื•ืงื˜ืŸ ืžื™ื˜ ืคืึทืจืคืขืกื˜ื™ืงื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–

ืึธืจืึทืงืœืข ืคึฟื™ืจืžืข ืืจื•ื™ืก ืคึผืœืึทื ื ืขื“ ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืฆื• ื–ื™ื™ึทืŸ ืคึผืจืึธื“ื•ืงื˜ืŸ (ืงืจื™ื˜ื™ืฉ ืคึผืึทื˜ืฉ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ), ืึทื™ืžืขื“ ืฆื• ืขืœื™ืžื™ื ื™ืจืŸ ืงืจื™ื˜ื™ืฉ ืคึผืจืึธื‘ืœืขืžืก ืื•ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–. ืื™ืŸ ื“ื™ ื™ื•ืœื™ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ, ืึท ื’ืึทื ืฅ ืคื•ืŸ 443 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–.

ื™ืฉื•ื– Java SE 14.0.2, 11.0.8 ืื•ืŸ 8u261 ื™ืœื™ืžืึทื ื™ื™ื˜ืึทื“ 11 ื–ื™ื›ืขืจื”ื™ื™ึทื˜ ื™ืฉื•ื–. ืึทืœืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืงืขื ืขืŸ ื–ื™ื™ืŸ ืขืงืกืคึผืœื•ื™ื˜ืึทื“ ืจื™ืžืึธื•ื˜ืœื™ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ. ื“ื™ ื”ืขื›ืกื˜ืŸ ืฉื˜ืจืขื ื’ืงื™ื™ึทื˜ ืžื“ืจื’ื” 8.3 ืื™ื– ืึทืกื™ื™ื ื“ ืฆื• ืคึผืจืึธื‘ืœืขืžืก ืื™ืŸ JavaFX ืื•ืŸ ืœื™ื™ื‘ืจืขืจื™ื– (CVE-2020-14664, CVE-2020-14583).
ื“ื™ ื“ืจื™ื˜ ืžืขืจืกื˜ ื’ืขืคืขืจืœืขืš ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVSS 7.4) ืื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื“ื™ 2D ื’ืจืึทืคื™ืงืก ืคึผืจืึทืกืขืกื™ื ื’ ืกืึทื‘ืกื™ืกื˜ืึทื. 5 ืคึผืจืึธื‘ืœืขืžืก ื“ืขืจืฉื™ื™ึทื ืขืŸ ื‘ืœื•ื™ื– ืื•ื™ืฃ ืงืœื™ืขื ื˜ ืกื™ืกื˜ืขืžืขืŸ (ืคืœื™ืกื ื“ื™ืง ืื™ืŸ ื“ื™ Java Web Start ื‘ืœืขื˜ืขืจืขืจ ืื•ืŸ Java ืึทืคึผืคึผืœืขืฅ) ืื•ืŸ 6 ื•ื•ื™ืจืงืŸ ื‘ื™ื™ื“ืข ืงืœื™ืขื ื˜ ืื•ืŸ ืกืขืจื•ื•ืขืจ Java ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทื ื–.

ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• ื™ืฉื•ื– ืื™ืŸ Java SE, ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ื’ืขืžืื›ื˜ ืขืคื ื˜ืœืขืš ืื™ืŸ ืื ื“ืขืจืข ืึธืจืึทืงืœืข ืคึผืจืึธื“ื•ืงื˜ืŸ, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜:

  • 32 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ MySQL ืกืขืจื•ื•ืขืจ ืื•ืŸ
    3 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ MySQL ืงืœื™ืขื ื˜ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ (C API) ืื•ืŸ ืงืึทื ืขืงื˜ืขืจื– (C ++ ืื•ืŸ ODBC). ื“ื™ ื”ืขื›ืกื˜ืŸ ืฉื˜ืจืขื ื’ืงื™ื™ึทื˜ ืžื“ืจื’ื” ืคื•ืŸ 7.5 ืื™ื– ืึทืกื™ื™ื ื“ ืฆื• ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ CVE-2020-1967, ื•ื•ืึธืก ืื™ื– ืฉื™ื™ึทื›ื•ืช ืฆื• ื“ื™ ืฉื˜ืึทืจืงื™ื™ื˜ ืคื•ืŸ ืขื ืงืจื™ืคึผืฉืึทืŸ ืื•ืŸ ืื™ื– ืืจื•ื™ืก ื•ื•ืขืŸ ืงืึทืžืคึผื™ื™ืœื“ ืžื™ื˜ OpenSSL ืฉื˜ื™ืฆืŸ. ื™ืฉื•ื– ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ืจื™ืœื™ืกื™ื– MySQL Community Server 8.0.21, 5.7.31 ืื•ืŸ 5.6.49.
  • 25 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ VirtualBox. ื“ื™ ืžืขืจืกื˜ ื’ืขืคืขืจืœืขืš ืคึผืจืึธื‘ืœืขื ืื™ื– ืึทืกื™ื™ื ื“ ืึท ื’ืขืคืึทืจ ืžื“ืจื’ื” ืคื•ืŸ 8.2. ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ื•ื•ื™ืจื˜ื•ืึทืœื‘ืึธืงืก 6.1.6, 6.0.20 ืื•ืŸ 5.2.40.
  • 6 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ืกืึธืœืึทืจื™ืก. ืžืึทืงืกื™ืžื•ื ืฉื˜ืจืขื ื’ืงื™ื™ึทื˜ ืžื“ืจื’ื” 7.3 - ืœืึธื•ืงืึทืœื™ ืขืงืกืคึผืœื•ื™ื˜ืึทื‘ืึทืœ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ื•ื•ื™ื™ืก ื“ืจื™ื™ื•ื•ืขืจ ื™ื•ื˜ื™ืœื™ื˜ื™. ื™ืฉื•ื– ื–ืขื ืขืŸ ืื•ื™ืš ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื“ื™ ืงืขืจืŸ, ืคึผืขืงืœ ืกืงืจื™ืคึผืก ืื•ืŸ ืœื™ื‘ืกื•ืจื™. ื™ืฉื•ื– ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื ืขื›ื˜ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ Solaris 11.4 SRU23.

ืžืงื•ืจ: opennet.ru