ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ Buildroot ื•ื•ืึธืก ืœืึธื–ืŸ ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืื•ื™ืฃ ื“ื™ ื‘ื•ื™ืขืŸ ืกืขืจื•ื•ืขืจ ื“ื•ืจืš ืึท MITM ื‘ืึทืคืึทืœืŸ

ืื™ืŸ ื“ืขื ื‘ื™ืœื“ืจื•ื˜ ื‘ื™ืœื“ ืกื™ืกื˜ืขื, ื•ื•ืึธืก ืื™ื– ื’ืขืฆื™ืœื˜ ืฆื• ืฉืึทืคึฟืŸ ื‘ื•ื˜ืึทื‘ืœืขืก Linuxื–ืขืงืก ืฉื•ื•ืึทื›ืงื™ื™ื˜ืŸ ื–ืขื ืขืŸ ืื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจื˜ ื’ืขื•ื•ืึธืจืŸ ืื™ืŸ ืขืžื‘ืขื“ื™ื“ ืกื™ืกื˜ืขื ืกื‘ื™ื‘ื•ืช ื•ื•ืึธืก ืงืขื ืขืŸ ืขืจืœื•ื™ื‘ืŸ ืžืขื ื˜ืฉ-ืื™ืŸ-ื“ื™-ืžื™ื˜ืœ (MITM) ืึทื˜ืึทืงืขืก ืฆื• ืžืึธื“ื™ืคื™ืฆื™ืจืŸ ื“ื–ืฉืขื ืขืจื™ืจื˜ืข ืกื™ืกื˜ืขื ื‘ื™ืœื“ืขืจ ืึธื“ืขืจ ื“ื•ืจื›ืคื™ืจืŸ ืงืึธื“ ืื•ื™ืฃ ื“ืขืจ ื‘ื™ืœื“ ืกื™ืกื˜ืขื ืžื“ืจื’ื”. ื“ื™ ืฉื•ื•ืึทื›ืงื™ื™ื˜ืŸ ื–ืขื ืขืŸ ืคืึทืจืจื™ื›ื˜ ื’ืขื•ื•ืึธืจืŸ ืื™ืŸ Buildroot ืจื™ืœื™ืกื™ื– 2023.02.8, 2023.08.4, ืื•ืŸ 2023.11.

ื“ื™ ืขืจืฉื˜ืข ืคื™ื ืฃ ืฉื•ื•ืื›ืงื™ื™ื˜ืŸ (CVE-2023-45841, CVE-2023-45842, CVE-2023-45838, CVE-2023-45839, CVE-2023-45840) ื‘ืึทื˜ืจืึทืคึฟืŸ ื“ืขื ืงืึธื“ ืคึฟืึทืจ ื•ื•ืขืจื™ืคึฟื™ืฆื™ืจืŸ ื“ื™ ืื™ื ื˜ืขื’ืจื™ื˜ืขื˜ ืคึฟื•ืŸ ืคึผืึทืงืขื˜ืŸ ืžื™ื˜ ื”ืขืฉื™ื–. ื“ื™ ืคึผืจืึธื‘ืœืขืžืขืŸ ืงื•ืžืขืŸ ืึทืจืึธืคึผ ืฆื• ื“ืขืจ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืฆื• ื ื•ืฆืŸ HTTP ืฆื• ื“ืึทื•ื ืœืึธื•ื“ืŸ ื˜ืขืงืขืก ืื•ืŸ ื“ืขื ืžืึทื ื’ืœ ืคึฟื•ืŸ ื•ื•ืขืจื™ืคึฟื™ืงืึทืฆื™ืข ื”ืขืฉ ื˜ืขืงืขืก ืคึฟืึทืจ ืขื˜ืœืขื›ืข ืคึผืึทืงืขื˜ืŸ, ื•ื•ืึธืก ื“ืขืจืžืขื’ืœืขื›ื˜ ื“ืขื ืื™ื ื”ืึทืœื˜ ืคึฟื•ืŸ ื“ื™ ืคึผืึทืงืขื˜ืŸ ืฆื• ื•ื•ืขืจืŸ ื’ืขืคึฟื•ื™ืœื˜, ืื•ืŸ ื“ืขืจืžื™ื˜ ืึทืจืฒึทื ื’ืขืžื™ืฉื˜ ืื™ืŸ ื“ืขื ืคึฟืึทืจืงืขืจ ืคึฟื•ื ืขื ื‘ื•ื™ืขืŸ ืคึผืจืึธืฆืขืก. ืกืขืจื•ื•ื™ืจืขืจ (ืœืžืฉืœ, ื•ื•ืขืŸ ืึท ื‘ืึทื ื™ืฆืขืจ ืคึฟืึทืจื‘ื™ื ื“ื˜ ื–ื™ืš ื“ื•ืจืš ืึท ื•ื•ื™ื™ืจืœืขืก ื ืขืฅ ืงืึธื ื˜ืจืึธืœื™ืจื˜ ื“ื•ืจืš ืึทืŸ ืึทื˜ืึทืงืขืจ).

ืื™ืŸ ื‘ืึทื–ื•ื ื“ืขืจ, ื“ื™ aufs ืื•ืŸ aufs-util ืคึผืึทืงืึทื“ื–ืฉืึทื– ื–ืขื ืขืŸ ืœืึธื•ื“ื™ื“ ืื™ื‘ืขืจ ื”ื˜ื˜ืคึผ ืื•ืŸ ื–ืขื ืขืŸ ื ื™ืฉื˜ ืึธืคึผื’ืขืฉื˜ืขืœื˜ ืงืขื’ืŸ ื”ืึทืฉืขืก. ื”ืึทืฉืขืก ื–ืขื ืขืŸ ืื•ื™ืš ืคืขืœื ื“ื™ืง ืคึฟืึทืจ ื“ื™ riscv64-elf-toolchain, versal-firmware ืื•ืŸ mxsldr ืคึผืึทืงืึทื“ื–ืฉืึทื–, ื•ื•ืึธืก ืœืึธื•ื“ื™ื“ ืื™ื‘ืขืจ ื”ื˜ื˜ืคึผืก ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ืึธื‘ืขืจ ื’ืขืคืืœืŸ ืฆื•ืจื™ืง ืฆื• ืึทื ืขื ืงืจื™ืคึผื˜ื™ื“ ื“ืึทื•ื ืœืึธื•ื“ื– ืคื•ืŸ http://sources.buildroot.net ืื™ืŸ ืคืึทืœ ืคื•ืŸ ืคึผืจืึธื‘ืœืขืžืก. ืื•ื™ื‘ ืขืก ื–ืขื ืขืŸ ื’ืขื•ื•ืขืŸ ืงื™ื™ืŸ .ื”ืึทืฉ ื˜ืขืงืขืก, ื“ื™ Buildroot ื’ืขืฆื™ื™ึทื’ ื’ืขื”ืืœื˜ืŸ ื“ื™ ื˜ืฉืขืง ื’ืขืจืึธื˜ืŸ ืื•ืŸ ืคึผืจืึทืกืขืกื˜ ื“ื™ ื“ืึทื•ื ืœืึธื•ื“ื™ื“ ืคึผืึทืงืึทื“ื–ืฉืึทื–, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืึทืคึผืœื™ื™ื™ื ื’ ื“ื™ ืคึผืึทื˜ืฉืึทื– ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ื“ื™ ืคึผืึทืงืึทื“ื–ืฉืึทื– ืื•ืŸ ืคืœื™ืกื ื“ื™ืง ื‘ื•ื™ืขืŸ ืกืงืจื™ืคึผืก. ืžื™ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฉื•ื•ื™ื ื“ืœ ื“ืึทื•ื ืœืึธื•ื“ื™ื“ ืคึผืึทืงืึทื“ื–ืฉืึทื–, ื“ืขืจ ืึทื˜ืึทืงืขืจ ืงืขืŸ ืœื™ื™ื’ืŸ ื–ื™ื™ืŸ ืื™ื™ื’ืขื ืข ืคึผืึทื˜ืฉืึทื– ืึธื“ืขืจ ืžืึทืงืขืคื™ืœืขืก ืฆื• ื–ื™ื™, ื•ื•ืึธืก ื’ืขืžืื›ื˜ ืขืก ืžืขื’ืœืขืš ืฆื• ืžืึทื›ืŸ ืขื ื“ืขืจื•ื ื’ืขืŸ ืฆื• ื“ื™ ืจื™ื–ืึทืœื˜ื™ื ื’ ื‘ื™ืœื“ ืึธื“ืขืจ ื‘ื•ื™ืขืŸ ืกื™ืกื˜ืขื ืกืงืจื™ืคึผืก ืื•ืŸ ื“ืขืจื’ืจื™ื™ื›ืŸ ื“ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื–ื™ื™ืŸ ืงืึธื“.

ื“ื™ ื–ืขืงืกื˜ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2023-43608) ืื™ื– ื’ืขืคึฟื™ืจื˜ ื’ืขื•ื•ืึธืจืŸ ื“ื•ืจืš ืึท ื˜ืขื•ืช ืื™ืŸ ื“ืขืจ ืื™ืžืคึผืœืขืžืขื ื˜ืึทืฆื™ืข ืคึฟื•ืŸ ื“ืขืจ BR_NO_CHECK_HASH_FOR ืคึฟื•ื ืงืฆื™ืึธื ืึทืœื™ื˜ืขื˜, ื•ื•ืึธืก ื“ืขืจืžืขื’ืœืขื›ื˜ ื“ื™ืึทืงื˜ื™ื•ื•ื™ืจืŸ ื”ืขืฉ ืื™ื ื˜ืขื’ืจื™ื˜ืขื˜ ืงืึธื ื˜ืจืึธืœ ืคึฟืึทืจ ืื•ื™ืกื’ืขืงืœื™ื‘ืขื ืข ืคึผืึทืงืขื˜ืŸ. ืขื˜ืœืขื›ืข ืคึผืึทืงืขื˜ืŸ, ื•ื•ื™ ื“ืขืจ ืงืขืจื ืขืœ, Linux, ื™ื•-ื‘ื•ื˜, ืื•ืŸ ื•ื•ืขืจืกืึทืœ-ืคื™ืจืžื•ื•ืขืจ ื”ืื‘ืŸ ืขืจืœื•ื™ื‘ื˜ ืืจืืคืฆื•ืœืื“ืŸ ื“ื™ ืœืขืฆื˜ืข ื•ื•ืขืจืกื™ืขืก ืคืืจ ื•ื•ืขืœื›ืข ื•ื•ืขืจื™ืคื™ืงืืฆื™ืข ื”ืขืฉื™ื– ื–ืขื ืขืŸ ื ืืš ื ื™ืฉื˜ ื’ืขื ืขืจื™ืจื˜ ื’ืขื•ื•ืืจืŸ. ืคืืจ ื“ื™ ื•ื•ืขืจืกื™ืขืก, ืื™ื– ื“ื™ BR_NO_CHECK_HASH_FOR ืืคืฆื™ืข ื’ืขื ื•ืฆื˜ ื’ืขื•ื•ืืจืŸ, ื•ื•ืืก ื”ืื˜ ื“ื™ืืงื˜ื™ื•ื•ื™ืจื˜ ื”ืขืฉ ื•ื•ืขืจื™ืคื™ืงืืฆื™ืข. ื“ืื˜ื ืื™ื– ืืจืืคื’ืขืœืื“ืŸ ื’ืขื•ื•ืืจืŸ ื“ื•ืจืš HTTPS, ืื‘ืขืจ ื“ื•ืจืš ื“ื™ืคืืœื˜, ืื•ื™ื‘ ื“ืขืจ ืืจืืคื’ืขืœืื“ ืื™ื– ื“ื•ืจื›ื’ืขืคืืœืŸ, ืื™ื– ืขืก ืฆื•ืจื™ืงื’ืขืคืืœืŸ ืฆื• ืฆื•ื˜ืจื™ื˜ืŸ source.buildroot.net ืืŸ ืขื ืงืจื™ืคึผืฉืึทืŸ ื ื™ืฆื ื“ื™ื’ ื“ืขื http:// ืคืจืื˜ืืงืืœ. ืืŸ ืื˜ืืงื™ืจืขืจ ืงืขืŸ ื‘ืœืืงื™ืจืŸ ื“ื™ ืคืืจื‘ื™ื ื“ื•ื ื’ ืฆื•ื HTTPS ืกืขืจื•ื•ืขืจ ื‘ืขืช ื ืžืืŸ-ืื™ืŸ-ื“ื™-ืžื™ื˜ืœ ืื˜ืืงืข, ื•ื•ืืก ื”ืื˜ ื’ืขืคื™ืจื˜ ืฆื• ื“ืขื ืืจืืคืฆื•ืœืื“ืŸ ืฆื•ืจื™ืง ืฆื• http://sources.buildroot.net.

ืžืงื•ืจ: opennet.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster