ืžืขืœื“ื•ื ื’ ืคื•ืŸ ืึทืคึผืึทื˜ืฉื™ ื”ื˜ื˜ืคึผ ืกืขืจื•ื•ืขืจ 2.4.43

ืืจื•ื™ืก ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ื™ ืึทืคึผืึทื˜ืฉื™ ื”ื˜ื˜ืคึผ ืกืขืจื•ื•ืขืจ 2.4.43 (ืžืขืœื“ื•ื ื’ 2.4.42 ืื™ื– ืกืงื™ืคึผื˜), ื•ื•ืึธืก ื™ื ื˜ืจืึธื•ื“ื•ืกื˜ 34 ืขื ื“ืขืจื•ื ื’ืขืŸ ืื•ืŸ ื™ืœื™ืžืึทื ื™ื™ื˜ืึทื“ 3 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–:

  • CVE-2020-1927: ืึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ืžืึธื“_ืจืขื•ื•ืจื™ื˜ืข ื•ื•ืึธืก ืึทืœืึทื•ื– ื“ื™ ืกืขืจื•ื•ืขืจ ืฆื• ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ืคืึธืจื•ื•ืขืจื“ื™ื“ ืจื™ืงื•ื•ืขืก ืฆื• ืื ื“ืขืจืข ืจืขืกื•ืจืกืŸ (ืขืคืขื ืขืŸ ืจื™ื“ืขืจืขืงื˜). ืขื˜ืœืขื›ืข ืžืึธื“_ืจืขื•ื•ืจื™ื˜ืข ืกืขื˜ื˜ื™ื ื’ืก ืงืขืŸ ืคื™ืจืŸ ืฆื• ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืคืึธืจื•ื•ืขืจื“ื™ื“ ืฆื• ืืŸ ืื ื“ืขืจ ืœื™ื ืง, ืขื ืงืึธื•ื“ื™ื“ ืžื™ื˜ ืึท ื ืขื•ื•ืœื™ื™ืŸ ื›ืึทืจืึทืงื˜ืขืจ ืื™ืŸ ืึท ืคึผืึทืจืึทืžืขื˜ืขืจ ื’ืขื ื™ืฆื˜ ืื™ืŸ ืึท ื™ื’ื–ื™ืกื˜ื™ื ื’ ืจื™ื“ืขืจืขืงื˜.
  • CVE-2020-1934: ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ mod_proxy_ftp. ื ื™ืฆืŸ ืึทื ื™ื ื™ืฉื™ืึทืœื™ื™ื–ื“ ื•ื•ืึทืœื•ืขืก ืงืขื ืขืŸ ืคื™ืจืŸ ืฆื• ื–ื›ึผืจื•ืŸ ืœื™ืงืก ื•ื•ืขืŸ ืคึผืจืึทืงืกื™ื™ื ื’ ืจื™ืงื•ื•ืขืก ืฆื• ืึท ืึทื˜ืึทืงืขืจ-ืงืึทื ื˜ืจืึธื•ืœื“ FTP ืกืขืจื•ื•ืขืจ.
  • ื–ื›ึผืจื•ืŸ ืจื™ื ืขืŸ ืื™ืŸ mod_ssl ื•ื•ืึธืก ืึทืงืขืจื– ื•ื•ืขืŸ ื˜ืฉืึทื™ื ื™ื ื’ OCSP ืจื™ืงื•ื•ืขืก.

ื“ื™ ืžืขืจืกื˜ ื ืึธื•ื˜ืึทื‘ืึทืœ ื ื™ื˜-ื–ื™ื›ืขืจื”ื™ื™ื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ ื–ืขื ืขืŸ:

  • ื ื™ื™ึท ืžืึธื“ื•ืœืข ืฆื•ื’ืขื’ืขื‘ืŸ mod_systemd, ื•ื•ืึธืก ื’ื™ื˜ ื™ื ื˜ืึทื’ืจื™ื™ืฉืึทืŸ ืžื™ื˜ ื“ื™ ืกื™ืกื˜ืขื ืคืึทืจื•ื•ืึทืœื˜ืขืจ. ื“ืขืจ ืžืึธื“ื•ืœืข ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื ื•ืฆืŸ httpd ืื™ืŸ ืกืขืจื•ื•ื™ืกืขืก ืžื™ื˜ ื“ื™ ื˜ื™ืคึผ "ื˜ื™ืคึผ = ื’ืขื‘ื  ืฆื• ื•ื•ื™ืกืŸ".
  • ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืงืจื™ื™ึทื– ื–ืึทืžืœื•ื ื’ ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ืึทืคึผืงืกืก.
  • ื“ื™ ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื– ืคื•ืŸ ื“ื™ mod_md ืžืึธื“ื•ืœืข, ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื“ื•ืจืš ื“ื™ Let's Encrypt ืคึผืจื•ื™ืขืงื˜ ืฆื• ืึธื˜ืึทืžื™ื™ื˜ ื“ื™ ืงืึทื‘ืึธืœืข ืื•ืŸ ื•ื™ืฉืึทืœื˜ ืคื•ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื ื™ืฆืŸ ื“ื™ ACME (Automatic Certificate Management Environment) ืคึผืจืึธื˜ืึธืงืึธืœ, ื–ืขื ืขืŸ ื™ืงืกืคึผืึทื ื“ื™ื“:
    • ืฆื•ื’ืขื’ืขื‘ืŸ ื“ื™ MDContactEmail ื“ื™ืจืขืงื˜ื™ื•ื•, ื“ื•ืจืš ื•ื•ืึธืก ืื™ืจ ืงืขื ืขืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึท ืงืึธื ื˜ืึทืงื˜ E- ื‘ืจื™ื•ื• ื•ื•ืึธืก ืื™ื– ื ื™ืฉื˜ ืึธื•ื•ื•ืขืจืœืึทืคึผ ืžื™ื˜ ื“ื™ ื“ืึทื˜ืŸ ืคื•ืŸ ื“ื™ ServerAdmin ื“ื™ืจืขืงื˜ื™ื•ื•.
    • ืคึฟืึทืจ ืึทืœืข ื•ื•ื™ืจื˜ื•ืขืœ ืžื—ื ื•ืช, ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื“ื™ ืคึผืจืึธื˜ืึธืงืึธืœ ื’ืขื ื™ืฆื˜ ื•ื•ืขืŸ ื ื™ื’ืึธื•ืฉื™ื™ื™ื˜ื™ื ื’ ืึท ื–ื™ื›ืขืจ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ืงืึทื ืึทืœ ("tls-alpn-01") ืื™ื– ื•ื•ืขืจืึทืคื™ื™ื“.
    • ืœืึธื–ืŸ mod_md ื“ื™ื™ืจืขืงื˜ื™ื•ื•ื– ืฆื• ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืื™ืŸ ื‘ืœืึทืงืก ืื•ืŸ .
    • ื™ื ืฉื•ืจื– ืึทื– ืคืึทืจื’ืึทื ื’ืขื ื”ื™ื™ื˜ ืกืขื˜ื˜ื™ื ื’ืก ื–ืขื ืขืŸ ืึธื•ื•ื•ืขืจืจื™ื˜ืึทืŸ ื•ื•ืขืŸ ืจื™ื•ื–ื™ื ื’ MDCAChallenges.
    • ืฆื•ื’ืขื’ืขื‘ืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ ื“ื™ URL ืคึฟืึทืจ CTLog ืžืึธื ื™ื˜ืึธืจ.
    • ืคึฟืึทืจ ืงืึทืžืึทื ื“ื– ื“ื™ืคื™ื™ื ื“ ืื™ืŸ ื“ื™ MDMessageCmd ื“ื™ืจืขืงื˜ื™ื•ื•, ืึท ืจื•ืฃ ืžื™ื˜ ื“ื™ "ืื™ื ืกื˜ืึทืœื™ืจืŸ" ืึทืจื’ื•ืžืขื ื˜ ืื™ื– ืฆื•ื’ืขืฉื˜ืขืœื˜ ื•ื•ืขืŸ ืึทืงื˜ืึทื•ื•ื™ื™ื˜ื™ื ื’ ืึท ื ื™ื™ึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื ืึธืš ืึท ืกืขืจื•ื•ืขืจ ืจื™ืกื˜ืึทืจื˜ (ืœืžืฉืœ, ืขืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ื ืึธื›ืžืึทื›ืŸ ืึธื“ืขืจ ื’ืขืจ ืึท ื ื™ื™ึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืคึฟืึทืจ ืื ื“ืขืจืข ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–).
  • mod_proxy_hcheck ืฆื•ื’ืขื’ืขื‘ืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื“ื™ % {Content-Type} ืžืึทืกืงืข ืื™ืŸ ื˜ืฉืขืง ืื•ื™ืกื“ืจื•ืงืŸ.
  • CookieSameSite, CookieHTTOnly ืื•ืŸ CookieSecure ืžืึธื“ืขืก ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• mod_usertrack ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ Usertrack ืงื™ื›ืœ ืคึผืจืึทืกืขืกื™ื ื’.
  • mod_proxy_ajp ื™ืžืคึผืœืึทืžืึทื ืฅ ืึท "ืกื•ื“" ืึธืคึผืฆื™ืข ืคึฟืึทืจ ืคึผืจืึทืงืกื™ ื”ืึทื ื“ืœืขืจืก ืฆื• ืฉื˜ื™ืฆืŸ ื“ื™ ืœืขื’ืึทื˜ AJP13 ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึผืจืึธื˜ืึธืงืึธืœ.
  • ืึทื“ื“ืขื“ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืฉื˜ืขืœืŸ ืคึฟืึทืจ OpenWRT.
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฉื˜ื™ืฆืŸ ืฆื• mod_ssl ืคึฟืึทืจ ื ื™ืฆืŸ ืคึผืจื™ื•ื•ืึทื˜ ืฉืœื™ืกืœืขืŸ ืื•ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืคื•ืŸ OpenSSL ENGINE ื“ื•ืจืš ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ PKCS #11 URI ืื™ืŸ SSLCertificateFile/KeyFile.
  • ื™ืžืคึผืœืึทืžืขื ืึทื“ ื˜ืขืกื˜ื™ื ื’ ืžื™ื˜ ื“ื™ ืงืขืกื™ื™ื“ืขืจื“ื™ืง ื™ื ื˜ืึทื’ืจื™ื™ืฉืึทืŸ ืกื™ืกื˜ืขื Travis CI.
  • ืคึผืึทืจืกื™ื ื’ ืคื•ืŸ ืึทืจื™ื‘ืขืจืคื™ืจืŸ-ืขื ืงืึธื“ื™ื ื’ ื›ืขื“ืขืจื– ืื™ื– ื˜ื™ื™ื˜ืึทื ื“.
  • mod_ssl ื’ื™ื˜ TLS ืคึผืจืึธื˜ืึธืงืึธืœ ืคืึทืจื”ืึทื ื“ืœื•ื ื’ ืื™ืŸ ื‘ืึทืฆื™ื•ื ื’ ืฆื• ื•ื•ื™ืจื˜ื•ืึทืœ ืžื—ื ื•ืช (ื’ืขืฉื˜ื™ืฆื˜ ื•ื•ืขืŸ ื’ืขื‘ื•ื™ื˜ ืžื™ื˜ OpenSSL-1.1.1+.
  • ื ื™ืฆืŸ ื›ืึทืฉื™ื ื’ ืคึฟืึทืจ ื‘ืึทืคึฟืขืœืŸ ื˜ื™ืฉืŸ, ืจื™ืกื˜ืึทืจื˜ืŸ ืื™ืŸ "ื’ืจืึทืฆื™ืขื–" ืžืึธื“ืข ื–ืขื ืขืŸ ืึทืงืกืขืœืขืจื™ื™ื˜ื™ื“ (ืึธืŸ ื™ื ื˜ืขืจืึทืคึผื˜ื™ื ื’ ืคืœื™ืกื ื“ื™ืง ืึธื ืคึฟืจืขื’ ืคึผืจืึทืกืขืกืขืจื–).
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ืœื™ื™ื ืขืŸ-ื‘ืœื•ื™ื– ื˜ื™ืฉืŸ ืจ: ื”ืขืึทื“ืขืจืก_ืื™ืŸ_ื˜ืึทื‘ืœืข, ืจ: ื”ืขืึทื“ืขืจืก_ืึธื•ื˜_ื˜ืึทื‘ืœืข, ืจ: ืขืจืจ_ื”ืขืึทื“ืขืจืก_ืึธื•ื˜_ื˜ืึทื‘ืœืข, ืจ: ื”ืขืจื•ืช_ื˜ืึทื‘ืœืข ืื•ืŸ ืจ: ืกื•ื‘ืคึผืจืึธืกืขืกืก_ืขื ื•ื•_ื˜ืึทื‘ืœืข ืฆื• ืžืึธื“_ืœื•ืึท. ืœืึธื–ืŸ ื˜ื™ืฉืŸ ื–ื™ื™ืŸ ืึทืกื™ื™ื ื“ ื“ื™ ื•ื•ืขืจื˜ "ื ื™ืœ".
  • ืื™ืŸ mod_authn_socache, ื“ื™ ืฉื™ืขื•ืจ ืื•ื™ืฃ ื“ื™ ื’ืจื™ื™ืก ืคื•ืŸ ืึท ืงืึทืฉื˜ ืฉื•ืจื” ืื™ื– ื’ืขื•ื•ืืงืกืŸ ืคื•ืŸ 100 ืฆื• 256.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’