FreeBSD ืคื™ืงืกื™ื– 6 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–

ืื•ื™ืฃ FreeBSD ื™ืœื™ืžืึทื ื™ื™ื˜ืึทื“ ื–ืขืงืก ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื•ื•ืึธืก ืœืึธื–ืŸ ืื™ืจ ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืึท ื“ืึธืก ื‘ืึทืคืึทืœืŸ, ืคืึทืจืœืึธื–ืŸ ื“ื™ ื˜ื•ืจืžืข ืกื•ื•ื™ื•ื•ืข ืึธื“ืขืจ ื‘ืึทืงื•ืžืขืŸ ืึทืงืกืขืก ืฆื• ืงืขืจืŸ ื“ืึทื˜ืŸ. ื“ื™ ืคึผืจืึธื‘ืœืขืžืก ื–ืขื ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ 12.1-RELEASE-p3 ืื•ืŸ 11.3-RELEASE-p7.

  • CVE-2020-7452 - ืจืขื›ื˜ ืฆื• ืึท ื˜ืขื•ืช ืื™ืŸ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื•ื•ื™ืจื˜ื•ืึทืœ ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–, ืึท ื‘ืึทื ื™ืฆืขืจ ืžื™ื˜ PRIV_NET_IFCREATE ืึธื“ืขืจ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜ ืคื•ืŸ ืึทืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ ื˜ื•ืจืžืข ืกื•ื•ื™ื•ื•ืข ืงืขื ืขืŸ ืคืึทืจืฉืึทืคืŸ ื“ื™ ืงืขืจืŸ ืฆื• ืงืจืึทืš ืึธื“ืขืจ ื•ื™ืกืคื™ืจืŸ ื–ื™ื™ืขืจ ืงืึธื“ ืžื™ื˜ ืงืขืจืŸ ืจืขื›ื˜.
  • CVE-2020-7453 - ืงื™ื™ืŸ ื˜ืฉืขืง ืคึฟืึทืจ ืฉื˜ืจื™ืงืœ ื˜ืขืจืžืึทื ื™ื™ืฉืึทืŸ ืžื™ื˜ ืึท ื ืึทืœ ื›ืึทืจืึทืงื˜ืขืจ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ื“ื™ "osrelease" ืึธืคึผืฆื™ืข ื“ื•ืจืš ื“ื™ ื“ื–ืฉืึทื™ืœ_ืกืขื˜ ืกื™ืกื˜ืขื ืจื•ืคืŸ, ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื‘ืึทืงื•ืžืขืŸ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ืฉื›ื™ื™ื ื™ืฉ ืงืขืจืŸ ื–ื›ึผืจื•ืŸ ืกื˜ืจืึทืงื˜ืฉืขืจื– ื•ื•ืขืŸ ื“ืขืจ ื˜ื•ืจืžืข ืกื•ื•ื™ื•ื•ืข ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืžืื›ื˜ ืึท ื“ื–ืฉืึทื™ืœ_ื’ืขื˜ ืจื•ืคืŸ, ืื•ื™ื‘ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืงืึทื˜ืขืจ ื ืขืกื˜ืขื“ ื˜ื•ืจืžืข ื™ื ื•ื•ื™ื™ืจืึทื ืžืึทื ืฅ ืื™ื– ืขื ื™ื™ื‘ืึทืœื“ ื“ื•ืจืš ื“ื™ ืงื™ื ื“ืขืจ.ืžืึทืงืก ืคึผืึทืจืึทืžืขื˜ืขืจ (ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ื“ื™ ืฉืึทืคื•ื ื’ ืคื•ืŸ ื ืขืกื˜ืขื“ ื˜ื•ืจืžืข ื™ื ื•ื•ื™ื™ืจืึทื ืžืึทื ืฅ ืื™ื– ืคึผืจืึธื•ื›ื™ื‘ืึทื˜ืึทื“).
  • CVE-2019-15877 - ืคืึทืœืฉ ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ืคื•ืŸ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ื•ื•ืขืŸ ืึทืงืกืขืก ื“ื™ ืฉืึธืคืขืจ ixl ื“ื•ืจืš ioctl ืึทืœืึทื•ื– ืึทืŸ ืึทื ืคึผืจื™ื•ื•ื™ืœื™ื“ื–ืฉื“ ื‘ืึทื ื™ืฆืขืจ ืฆื• ื™ื ืกื˜ืึทืœื™ืจืŸ ืึท ืคื™ืจืžื•ื•ืึทืจืข ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืคึฟืึทืจ NVM ื“ืขื•ื•ื™ืกืขืก.
  • CVE-2019-15876 - ืคืึทืœืฉ ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ืคื•ืŸ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ื•ื•ืขืŸ ืึทืงืกืขืก ื“ื™ ืฉืึธืคืขืจ oce ื“ื•ืจืš ioctl ืึทืœืึทื•ื– ืึทืŸ ืึทื ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉื“ ื‘ืึทื ื™ืฆืขืจ ืฆื• ืฉื™ืงืŸ ืงืึทืžืึทื ื“ื– ืฆื• ื“ื™ ืคื™ืจืžื•ื•ืึทืจืข ืคื•ืŸ โ€‹โ€‹Emulex OneConnect ื ืขืฅ ืึทื“ืึทืคึผื˜ืขืจื–.
  • CVE-2020-7451 - ื“ื•ืจืš ืฉื™ืงืŸ TCP SYN-ACK ืกืขื’ืžืึทื ืฅ ื“ื™ื–ื™ื™ื ื“ ืื™ืŸ ืึท ื–ื™ื›ืขืจ ื•ื•ืขื’ ืื™ื‘ืขืจ IPv6, ืื™ื™ืŸ ื‘ื™ื™ื˜ ืคื•ืŸ ืงืขืจืŸ ื–ื›ึผืจื•ืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืœื™ืงื˜ ืื™ื‘ืขืจ ื“ื™ ื ืขืฅ (ื“ื™ ื˜ืจืึทืคื™ืง ืงืœืึทืก ืคืขืœื“ ืื™ื– ื ื™ืฉื˜ ื™ื ื™ื˜ื™ืึทืœื™ื™ื–ื“ ืื•ืŸ ื›ึผื•ืœืœ ืจื™ื–ื™ื“ื–ืฉื•ืึทืœ ื“ืึทื˜ืŸ).
  • ื“ืจื™ื™ ื’ืจื™ื™ื–ืŸ ืื™ืŸ ื“ื™ ntpd ืฆื™ื™ื˜ ืกื™ื ื’ืงืจืึทื ืึทื–ื™ื™ืฉืึทืŸ ื“ืึทืขืžืึธืŸ ืงืขื ืขืŸ ื•ื•ืขืจืŸ ื’ืขื ื•ืฆื˜ ืฆื• ืคืึทืจืฉืึทืคืŸ ืึท ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ (ืงืึธื–ื™ื ื’ ื“ื™ ntpd ืคึผืจืึธืฆืขืก ืฆื• ืงืจืึทืš).

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’