ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ Ruby 2.6.5, 2.5.7 ืื•ืŸ 2.4.8 ืžื™ื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜

ืงืขืจืขืงื˜ื™ื•ื• ืจื™ืœื™ืกื™ื– ืคื•ืŸ ื“ื™ Ruby ืคึผืจืึธื’ืจืึทืžืžื™ื ื’ ืฉืคึผืจืึทืš ื–ืขื ืขืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ 2.6.5, 2.5.7 ะธ 2.4.8, ื•ื•ืึธืก ืคืึทืจืคืขืกื˜ื™ืงื˜ ืคื™ืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–. ื“ื™ ืžืขืจืกื˜ ื’ืขืคืขืจืœืขืš ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2019-16255) ืื™ืŸ ื“ืขืจ ื ืึธืจืžืึทืœ ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืฉืึธืœ (lib/shell.rb), ื•ื•ืึธืก ืขืก ืึทืœืึทื•ื– ื“ื•ืจื›ืคื™ืจืŸ ืงืึธื“ ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ. ืื•ื™ื‘ ื“ืึทื˜ืŸ ื‘ืืงื•ืžืขืŸ ืคื•ืŸ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ื–ืขื ืขืŸ ืคึผืจืึทืกืขืกื˜ ืื™ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ืึทืจื’ื•ืžืขื ื˜ ืคื•ืŸ ื“ื™ Shell#[] ืึธื“ืขืจ Shell# ื˜ืขืกื˜ ืžืขื˜ื”ืึธื“ืก ื’ืขื ื™ืฆื˜ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ืขื ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ืึท ื˜ืขืงืข, ืึท ืึทื˜ืึทืงืขืจ ืงืขื ืขืŸ ืึธื ืžืึทื›ืŸ ืึท ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ืจื•ื‘ื™ ืื•ืคึฟืŸ.

ืื ื“ืขืจืข ืคืจืื‘ืœืขืžืขืŸ:

  • CVE-2019-16254 - ื•ื™ืกืฉื˜ืขืœืŸ ืฆื• ื“ื™ ื’ืขื‘ื•ื™ื˜-ืื™ืŸ ื”ื˜ื˜ืคึผ ืกืขืจื•ื•ืขืจ ื•ื•ืขื‘ืจื™ืง ื”ื˜ื˜ืคึผ ืขื ื˜ืคืขืจ ืกืคึผืœื™ื˜ื™ื ื’ ื‘ืึทืคืึทืœืŸ (ืื•ื™ื‘ ืึท ืคึผืจืึธื’ืจืึทื ื™ื ืกืขืจืฅ ืึทื ื•ื•ืขืจืึทืคื™ื™ื“ ื“ืึทื˜ืŸ ืื™ืŸ ื“ื™ ื”ื˜ื˜ืคึผ ืขื ื˜ืคืขืจ ื›ืขื“ืขืจ, ื“ื™ ื›ืขื“ืขืจ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืฉืคึผืึทืœื˜ืŸ ื“ื•ืจืš ื™ื ืกืขืจื˜ื™ื ื’ ืึท ื ืขื•ื•ืœื™ื™ืŸ ื›ืึทืจืึทืงื˜ืขืจ);
  • CVE-2019-15845 ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ืคื•ืŸ ื“ื™ ื ืึทืœ ื›ืึทืจืึทืงื˜ืขืจ (\0) ืื™ืŸ ื“ื™ ืึธืคึผื’ืขืฉื˜ืขืœื˜ ื“ื•ืจืš ื“ื™ "File.fnmatch" ืื•ืŸ "File.fnmatch?" ืžืขื˜ื”ืึธื“ืก. ื˜ืขืงืข ืคึผืึทื˜ืก ืงืขื ืขืŸ ื•ื•ืขืจืŸ ื’ืขื ื•ืฆื˜ ืฆื• ืคืึทืœืฉ ืฆื™ื ื’ืœ ื“ื™ ื˜ืฉืขืง;
  • CVE-2019-16201 - ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ ืื™ืŸ ื“ื™ ื“ื™ื’ืขืก ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืžืึธื“ื•ืœืข ืคึฟืึทืจ WEBrick.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’