ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ Samba 4.14.2, 4.13.7 ืื•ืŸ 4.12.14 ืžื™ื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜

ืงืขืจืขืงื˜ื™ื•ื• ืจื™ืœื™ืกื™ื– ืคื•ืŸ ื“ื™ Samba ืคึผืขืงืœ 4.14.2, 4.13.7 ืื•ืŸ 4.12.14 ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืจื™ื™ื˜, ืื™ืŸ ื•ื•ืึธืก ืฆื•ื•ื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜:

  • CVE-2020-27840 ืื™ื– ืึท ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ื•ื•ืึธืก ืึทืงืขืจื– ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืกืคึผืขืฆื™ืขืœ ืกื˜ื™ื™ืœื“ DN (ื“ื™ืกื˜ื™ื ื’ื•ื™ืฉืขื“ ื ืึธืžืขืŸ) ื ืขืžืขืŸ. ืึทืŸ ืึทื ืึธื ื™ืžืข ื‘ืึทื ื•ืฆืขืจืก ืึทื˜ืึทืงืขืจ ืงืขื ืขืŸ ืงืจืึทืš ืึท ืกืึทืžื‘ืึท-ื‘ืื–ื™ืจื˜ AD DC LDAP ืกืขืจื•ื•ืขืจ ื“ื•ืจืš ืฉื™ืงืŸ ืึท ืกืคึผืขืฆื™ืขืœ ืงืจืึทืคื˜ืขื“ ื‘ื™ื ื“ืŸ ื‘ืขื˜ืŸ. ื–ื™ื ื˜ ื‘ืขืฉืึทืก ื“ื™ ื‘ืึทืคืึทืœืŸ ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืจื™ืจื™ื™ื˜ื™ื ื’ ื’ืขื’ื ื˜, ืžืขืจ ืขืจื ืกื˜ ืงืึทื ืกืึทืงื•ื•ืขื ืกืึทื– ืงืขื ืขืŸ ื ื™ื˜ ื–ื™ื™ืŸ ืจื•ืœื“ ืื•ื™ืก, ืึทื–ืึท ื•ื•ื™ ืขืงืกืึทืงื™ื•ื˜ื™ื ื’ ื“ื™ื™ืŸ ืงืึธื“ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ, ืึธื‘ืขืจ ืขืก ืื™ื– ื ืึธืš ืงื™ื™ืŸ ืืจื‘ืขื˜ืŸ ื’ื•ื•ื•ืจืข. ื–ื™ื ื˜ ื“ื™ DN ืฉื˜ืจื™ืงืœ ืคึผืึทืจืกื™ื ื’ ืงืึธื“ ื•ื•ืึธืก ืคื™ืจื˜ ืฆื• ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืขืงืกืึทืงื™ื•ื˜ืึทื“ ืื™ืŸ ื“ืขืจ ื‘ื™ื ืข ืื™ื™ื“ืขืจ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึผืึทืจืึทืžืขื˜ืขืจืก, ื“ื™ ืคึผืจืึธื‘ืœืขื ืงืขื ืขืŸ ื–ื™ื™ืŸ ืขืงืกืคึผืœื•ื™ื˜ืึทื“ ื“ื•ืจืš ืึท ืึทื˜ืึทืงืขืจ ื•ื•ืึธืก ื˜ื•ื˜ ื ื™ืฉื˜ ื”ืึธื‘ืŸ ืึท ื—ืฉื‘ื•ืŸ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ.
  • CVE-2021-20277 ืึทืŸ ืึทืจื•ื™ืก-ืคื•ืŸ-ื‘ืึทืคืขืจ ืœื™ื™ืขื ืขืŸ ืึทืงืขืจื– ื•ื•ืขืŸ ื“ื™ AD DC LDAP ืกืขืจื•ื•ืขืจ ืคึผืจืึทืกืขืกืึทื– ืึท ืกืคึผืขืฉืœื™ ืงืจืึทืคื˜ืขื“ ื‘ืึทื ื™ืฆืขืจ-ื“ื™ืคื™ื™ื ื“ ืคื™ืœื˜ืขืจ. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืงืขืŸ ืคืึทืจืฉืึทืคืŸ ื“ื™ ืกืขืจื•ื•ืขืจ ื”ืึทื ื“ืœืขืจ ืฆื• ืงืจืึทืš ืึธื“ืขืจ ืจื™ื ืขืŸ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ืคึผืจืึธืฆืขืก ื–ื›ึผืจื•ืŸ.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’