ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ Enlightenment ื‘ืึทื ื™ืฆืขืจ ืกื•ื•ื™ื•ื•ืข ืึทื– ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื‘ืึทืงื•ืžืขืŸ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜

ื ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2022-37706) ืื™ื– ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ ื“ื™ ื”ืฉื›ืœื” ื‘ืึทื ื™ืฆืขืจ ืกื•ื•ื™ื•ื•ืข ื•ื•ืึธืก ืึทืœืึทื•ื– ืึทืŸ ืึทื ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉื“ ื”ื™ื’ืข ื‘ืึทื ื™ืฆืขืจ ืฆื• ื•ื™ืกืคื™ืจืŸ ืงืึธื“ ืžื™ื˜ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื ืึธืš ื ื™ืฉื˜ ืคืึทืจืคืขืกื˜ื™ืงื˜ (0-ื˜ืึธื’), ืึธื‘ืขืจ ืขืก ืื™ื– ืฉื•ื™ืŸ ืึทืŸ ืขืงืกืคึผืœื•ื™ื˜ ื‘ื ื™ืžืฆื ืื™ืŸ ื“ืขื ืฆื™ื‘ื•ืจ ืคืขืœื“, ื˜ืขืกื˜ืขื“ ืื™ืŸ Ubuntu 22.04.

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ืื™ืŸ ื“ื™ Enlightenment_sys ืขืงืกืขืงื•ื˜ืึทื‘ืœืข, ื•ื•ืึธืก ืฉื™ืคึผืก ืžื™ื˜ ื“ื™ ืกื•ื™ื“ ื•ื•ืึธืจืฆืœ ืคืึธืŸ ืื•ืŸ ืคึผืขืจืคืึธืจืžื– ื–ื™ื›ืขืจ ื“ืขืจืœื•ื™ื‘ื˜ ืงืึทืžืึทื ื“ื–, ืึทื–ืึท ื•ื•ื™ ืžืึทื•ื ื˜ื™ื ื’ ื“ื™ ืคืึธืจ ืžื™ื˜ ื“ื™ ื‘ืืจื’ ื ื•ืฆืŸ, ื“ื•ืจืš ืึท ืจื•ืคืŸ ืฆื• ืกื™ืกื˜ืขื (). ืจืขื›ื˜ ืฆื• ื“ืขืจ ืคืึทืœืฉ ืึธืคึผืขืจืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ื“ื™ ืคึฟื•ื ืงืฆื™ืข ื•ื•ืึธืก ื“ื–ืฉืขื ืขืจื™ื™ืฅ ื“ื™ ืฉื˜ืจื™ืงืœ ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ืฆื• ื“ื™ ืกื™ืกื˜ืขื () ืจื•ืคืŸ, ืงื•ื•ืึธื˜ืขืก ื–ืขื ืขืŸ ืฉื ื™ื™ึทื“ืŸ ืคื•ืŸ ื“ื™ ืึทืจื’ื•ืžืขื ื˜ืŸ ืคื•ืŸ ื“ื™ ื‘ืึทืคึฟืขืœืŸ ืœืึธื ื˜ืฉื˜, ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ืœื•ื™ืคืŸ ื“ื™ื™ืŸ ืื™ื™ื’ืขื ืข ืงืึธื“. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื•ื•ืขืŸ ืคืœื™ืกื ื“ื™ืง mkdir -p /tmp/net mkdir -p "/tmp/;/tmp/exploit" echo "/bin/sh"> /tmp/exploit chmod a+x /tmp/exploit enlightenment_sys /bin/mount - o noexec,nosuid,utf8,nodev,iocharset=utf8,utf8=0,utf8=1,uid=$(id -u), โ€œ/dev/../tmp/;/tmp/exploitโ€ /tmp// / ื ืขืฅ

ืจืขื›ื˜ ืฆื• ื“ืขืจ ื‘ืึทื–ื™ื™ึทื˜ื™ืงื•ื ื’ ืคื•ืŸ ื˜ืึธืคึผืœ ืงื•ื•ืึธื˜ืขืก, ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ื‘ืึทืคึฟืขืœ '/bin/mount ... "/dev/../tmp/;/tmp/exploit" /tmp///net' ืึท ืฉื˜ืจื™ืงืœ ืึธืŸ ื˜ืึธืคึผืœ ืงื•ื•ืึธื˜ืขืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ืฆื• ื“ื™ ืกื™ืกื˜ืขื () ืคึฟื•ื ืงืฆื™ืข ' /bin/mount โ€ฆ /dev/../tmp/;/tmp/exploit /tmp///net', ื•ื•ืึธืก ื•ื•ืขื˜ ืคืึทืจืฉืึทืคืŸ ื“ื™ ื‘ืึทืคึฟืขืœ '/tmp/exploit /tmp///net ' ืฆื• ื–ื™ื™ืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“ ืกืขืคึผืขืจืึทื˜ืœื™ ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ืคึผืจืึทืกืขืกื˜ ื•ื•ื™ ืึท ื˜ื™ื™ืœ ืคื•ืŸ ื“ื™ ื•ื•ืขื’ ืฆื• ืžื™ื˜ืœ. ื“ื™ ืฉื•ืจื•ืช "/dev/../tmp/" ืื•ืŸ "/tmp///net" ื–ืขื ืขืŸ ืื•ื™ืกื“ืขืจื•ื•ื™ื™ืœื˜ ืฆื• ื‘ื™ื™ืคึผืึทืก ืึทืจื’ื•ืžืขื ื˜ ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ืคึฟืึทืจ ื“ื™ ื‘ืืจื’ ื‘ืึทืคึฟืขืœ ืื™ืŸ enlightenment_sys (ื“ื™ ื‘ืืจื’ ืžื™ื˜ืœ ืžื•ื–ืŸ ืึธื ื”ื™ื™ื‘ืŸ ืžื™ื˜ /dev/ ืื•ืŸ ืคื•ื ื˜ ืฆื• ืึท ื™ื’ื–ื™ืกื˜ื™ื ื’ ื˜ืขืงืข, ืื•ืŸ ื“ื™ ื“ืจื™ื™ "/" ืื•ืชื™ื•ืช ืื™ืŸ ื“ื™ ื‘ืืจื’ ืคื•ื ื˜ ื–ืขื ืขืŸ ืกืคึผืขืกื™ืคื™ืขื“ ืฆื• ื“ืขืจื’ืจื™ื™ื›ืŸ ื“ื™ ืคืืจืœืื ื’ื˜ ื•ื•ืขื’ ื’ืจื™ื™ืก).

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’