ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ libc ืื•ืŸ FreeBSD IPv6 ืึธื ืœื™ื™ื’ืŸ

FreeBSD ื”ืื˜ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืขื˜ืœืขื›ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื•ื•ืึธืก ืงืขืŸ ืœืึธื–ืŸ ืึท ื”ื™ื’ืข ื‘ืึทื ื™ืฆืขืจ ืฆื• ืขืกืงืึทืœื™ื™ื˜ ื–ื™ื™ืขืจ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืื•ื™ืฃ ื“ื™ ืกื™ืกื˜ืขื:

  • CVE-2020-7458 - ืึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ posix_spawnp ืžืขืงืึทื ื™ื–ืึทื ืฆื•ื’ืขืฉื˜ืขืœื˜ ืื™ืŸ libc ืคึฟืึทืจ ืงืจื™ื™ื™ื˜ื™ื ื’ ืคึผืจืึทืกืขืกืึทื–, ืขืงืกืคึผืœื•ื™ื˜ืึทื“ ื“ื•ืจืš ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืฆื• ื’ืจื•ื™ืก ื•ื•ืขืจื˜ ืื™ืŸ ื“ื™ PATH ืกื•ื•ื™ื•ื•ืข ื‘ื™ื™ึทื˜ืขื•ื•ื“ื™ืง. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขื ืขืŸ ืคื™ืจืŸ ืฆื• ืฉืจื™ื™ื‘ืŸ ื“ืึทื˜ืŸ ื•ื•ื™ื™ึทื˜ืขืจ ืคื•ืŸ ื“ื™ ื–ื™ืงืึธืจืŸ ื’ืขื’ื ื˜ ืึทืœืึทืงื™ื™ื˜ื™ื“ ืคึฟืึทืจ ื“ื™ ืึธื ืœื™ื™ื’ืŸ, ืื•ืŸ ืžืื›ื˜ ืขืก ืžืขื’ืœืขืš ืฆื• ืึธื•ื•ื•ืขืจืจื™ื™ื˜ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ืกืึทื‘ืกืึทืงื•ื•ืึทื ื˜ ื‘ืึทืคืขืจื– ืžื™ื˜ ืึท ืงืึทื ื˜ืจืึธื•ืœื“ ื•ื•ืขืจื˜.
  • CVE-2020-7457 - ืึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ IPv6 ืึธื ืœื™ื™ื’ืŸ ื•ื•ืึธืก ืึทืœืึทื•ื– ืึท ื”ื™ื’ืข ื‘ืึทื ื™ืฆืขืจ ืฆื• ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ื“ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื–ื™ื™ืขืจ ืงืึธื“ ืื•ื™ืฃ ื“ื™ ืงืขืจืŸ ืžื“ืจื’ื” ื“ื•ืจืš ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทืŸ ื ื™ืฆืŸ ื“ื™ IPV6_2292PKTOPTIONS ืึธืคึผืฆื™ืข ืคึฟืึทืจ ืึท ื ืขืฅ ื›ืึธืœืขืœ.
  • ื™ืœื™ืžืึทื ื™ื™ื˜ืึทื“ ืฆื•ื•ื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2020-12662, CVE-2020-12663) ืื™ืŸ ื“ื™ ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ื“ื ืก ืกืขืจื•ื•ืขืจ ื•ื ื‘ืึธื•ื ื“, ืึทืœืึทื•ื™ื ื’ ืื™ืจ ืฆื• ืคืึทืจืฉืึทืคืŸ ืึท ื•ื•ื™ื™ึทื˜ ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ ื•ื•ืขืŸ ืึทืงืกืขืกื™ื ื’ ืึท ืกืขืจื•ื•ืขืจ ืงืึทื ื˜ืจืึธื•ืœื“ ื“ื•ืจืš ืึท ืึทื˜ืึทืงืขืจ ืึธื“ืขืจ ื ื•ืฆืŸ ืึท DNS ืกืขืจื•ื•ืขืจ ื•ื•ื™ ืึท ืคืึทืจืงืขืจ ืึทืžืคึผืœืึทืคื™ื™ืขืจ ื•ื•ืขืŸ ืื™ืจ ื“ื•ืจื›ืคื™ืจืŸ DDoS ืื ืคืืœืŸ.

ืื™ืŸ ืึทื“ื™ืฉืึทืŸ, ื“ืจื™ื™ ื ื™ื˜-ื–ื™ื›ืขืจื”ื™ื™ื˜ ื™ืฉื•ื– (ืขืจืจืึทื˜ืึทืก) ื•ื•ืึธืก ืงืขืŸ ืคืึทืจืฉืึทืคืŸ ื“ื™ ืงืขืจืŸ ืฆื• ืงืจืึทืš ื‘ืฉืขืช ื ื™ืฆืŸ ื“ื™ ืฉืึธืคืขืจ ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืจื™ื–ืึทืœื•ื•ื“. mps (ื•ื•ืขืŸ ืขืงืกืึทืงื™ื•ื˜ื™ื ื’ ื“ื™ sas2ircu ื‘ืึทืคึฟืขืœ), ืกืึทื‘ืกื™ืกื˜ืึทืžื– LinuxKPI (ืžื™ื˜ X11 ืจื™ื“ืขืจืขืงืฉืึทืŸ) ืื•ืŸ ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจ ื‘ื”ื™ื™ื•ื•ืข (ื•ื•ืขืŸ ืคืึธืจื•ื•ืขืจื“ื™ื ื’ PCI ื“ืขื•ื•ื™ืกืขืก).

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’