ื“ืจื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ FreeBSD

FreeBSD ืึทื“ืจืขืกื– ื“ืจื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื•ื•ืึธืก ืงืขืŸ ืœืึธื–ืŸ ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ื•ื•ืขืŸ ื ื™ืฆืŸ ืœื™ื‘ืคืขื˜ื˜ืฉ, IPsec ืคึผืึทืงืึทื˜ ืจื™ื˜ืจืึทื ืกืžื™ืกืกื™ืึธืŸ ืึธื“ืขืจ ืึทืงืกืขืก ืฆื• ืงืขืจืŸ ื“ืึทื˜ืŸ. ื“ื™ ืคึผืจืึธื‘ืœืขืžืก ื–ืขื ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ 12.1-RELEASE-p2, 12.0-RELEASE-p13 ืื•ืŸ 11.3-RELEASE-p6.

  • CVE-2020-7450 - ืึท ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ืื™ืŸ ื“ื™ libfetch ื‘ื™ื‘ืœื™ืึธื˜ืขืง, ื’ืขื ื™ืฆื˜ ืฆื• ืœืึธื“ืŸ ื˜ืขืงืขืก ืื™ืŸ ื“ื™ ืคืขื˜ืฉ ื‘ืึทืคึฟืขืœ, ื“ื™ pkg ืคึผืขืงืœ ืคืึทืจื•ื•ืึทืœื˜ืขืจ ืื•ืŸ ืื ื“ืขืจืข ื™ื•ื˜ื™ืœืึทื˜ื™ื–. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขืŸ ืคื™ืจืŸ ืฆื• ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืึท ืกืคึผืขืฆื™ืขืœ ืงืจืึทืคื˜ืขื“ URL. ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ื•ื•ืขืŸ ืึทืงืกืขืกื™ื ื’ ืึท ืคึผืœืึทืฅ ืงืึทื ื˜ืจืึธื•ืœื“ ื“ื•ืจืš ื“ื™ ืึทื˜ืึทืงืขืจ, ื•ื•ืึธืก, ื“ื•ืจืš ืึท ื”ื˜ื˜ืคึผ ืจื™ื“ืขืจืขืงื˜, ืื™ื– ื‘ื™ื›ื•ืœืช ืฆื• ืึธื ื”ื™ื™ื‘ืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืคื•ืŸ ืึท ื‘ื™ื™ื–ืข URL;
  • CVE-2019-15875 - ืึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ ืžืขืงืึทื ื™ื–ืึทื ืคึฟืึทืจ ื“ื–ืฉืขื ืขืจื™ื™ื˜ื™ื ื’ ื”ืึทืจืฅ ืคึผืจืึธืฆืขืก ื“ืึทืžืคึผืก. ืจืขื›ื˜ ืฆื• ืึท ื˜ืขื•ืช, ืึทืจื•ื™ืฃ ืฆื• 20 ื‘ื™ื˜ืขืก ืคื•ืŸ ื“ืึทื˜ืŸ ืคื•ืŸ ื“ื™ ืงืขืจืŸ ืกื˜ืึทืง ื–ืขื ืขืŸ ืจืขืงืึธืจื“ืขื“ ืื™ืŸ ื”ืึทืจืฅ ื“ืึทืžืคึผืก, ื•ื•ืึธืก ืงืขืŸ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืึทื ื˜ื”ืึทืœื˜ืŸ ืงืึทื ืคืึทื“ืขื ืฉืึทืœ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืคึผืจืึทืกืขืกื˜ ื“ื•ืจืš ื“ื™ ืงืขืจืŸ. ื•ื•ื™ ืึท ื•ื•ืึธืจืงืึทืจืึธื•ื ื“ ืคึฟืึทืจ ืฉื•ืฅ, ืื™ืจ ืงืขื ืขืŸ ื“ื™ืกื™ื™ื‘ืึทืœ ื“ื™ ื“ื•ืจ ืคื•ืŸ ื”ืึทืจืฅ ื˜ืขืงืขืก ื“ื•ืจืš sysctl kern.coredump=0;
  • CVE-2019-5613 - ืึท ื–ืฉื•ืง ืื™ืŸ ื“ื™ ืงืึธื“ ืคึฟืึทืจ ื‘ืœืึทืงื™ื ื’ ื“ืึทื˜ืŸ ืฉื™ื™ึทืขืš-ืฉื™ืงื˜ ืื™ืŸ IPsec ื’ืขืžืื›ื˜ ืขืก ืžืขื’ืœืขืš ืฆื• ืจืขืกืขื ื“ ืคืจื™ืขืจ ืงืึทืคึผื˜ืฉืขืจื“ ืคึผืึทืงื™ืฅ. ื“ืขืคึผืขื ื“ื™ื ื’ ืื•ื™ืฃ ื“ื™ ื”ื•ื™ืš-ืžื“ืจื’ื” ืคึผืจืึธื˜ืึธืงืึธืœ ื˜ืจืึทื ืกืžื™ื˜ื˜ืขื“ ืื™ื‘ืขืจ IPsec, ื“ื™ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืคึผืจืึธื‘ืœืขื ืึทืœืึทื•ื–, ืœืžืฉืœ, ืคืจื™ืขืจ ื˜ืจืึทื ืกืžื™ื˜ื˜ืขื“ ืงืึทืžืึทื ื“ื– ืฆื• ืคืึทืจื“ืจื™ืกืŸ.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’