Apache OpenOffice 4.1.11 ื‘ืืคืจื™ื™ื˜

ื ืึธืš ืคื™ื ืฃ ื—ื“ืฉื™ื ืคื•ืŸ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ืื•ืŸ ื–ื™ื‘ืŸ ืื•ืŸ ืึท ื”ืึทืœื‘ ื™ืึธืจ ื–ื™ื ื˜ ื“ื™ ืœืขืฆื˜ืข ื‘ืึทื˜ื™ื™ื˜ื™ืง ืžืขืœื“ื•ื ื’, ืึท ืงืขืจืขืงื˜ื™ื•ื• ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ื™ ืึธืคื™ืก ืกื•ื•ื™ื˜ Apache OpenOffice 4.1.11 ืื™ื– ื’ืขื’ืจื™ื ื“ืขื˜, ื•ื•ืึธืก ืคืืจื’ืขืœื™ื™ื’ื˜ 12 ืคื™ืงืกื™ื–. ืคืึทืจื˜ื™ืง ืคึผืึทืงืึทื“ื–ืฉืึทื– ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืจื™ื™ื˜ ืคึฟืึทืจ ืœื™ื ื•ืงืก, ื•ื•ื™ื ื“ืึธื•ื– ืื•ืŸ ืžืึทืงืึธืก.

ื“ื™ ื ื™ื™ึทืข ืžืขืœื“ื•ื ื’ ืคื™ืงืกื™ื– ื“ืจื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–:

  • CVE-2021-33035 - ืึทืœืึทื•ื– ื“ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ืงืึธื“ ื•ื•ืขืŸ ืขืคืŸ ืึท ืกืคึผืขืฆื™ืขืœ ืงืจืึทืคื˜ืขื“ DBF ื˜ืขืงืข. ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš OpenOffice ืจื™ืœื™ื™ื™ื ื’ ืื•ื™ืฃ ื“ื™ ื•ื•ืึทืœื•ืขืก ืคื•ืŸ ืคืขืœื“ืœืขื ื’ื˜ ืื•ืŸ ืคืขืœื“ื˜ื™ืคึผ ืื™ืŸ ื“ื™ ื›ืขื“ืขืจ ืคื•ืŸ ื“ื™ DBF ื˜ืขืงืขืก ืฆื• ืึทืœืึทืงื™ื™ื˜ ื–ื™ืงืึธืจืŸ, ืึธืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืึทื– ื“ื™ ืคืึทืงื˜ื™ืฉ ื“ืึทื˜ืŸ ื˜ื™ืคึผ ืื™ืŸ ื“ื™ ืคืขืœื“ืขืจ ืฉื˜ื™ืžืขืŸ. ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืึท ื‘ืึทืคืึทืœืŸ, ืื™ืจ ืงืขื ืขืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึทืŸ INTEGER ื˜ื™ืคึผ ืื™ืŸ ื“ื™ ืคืขืœื“ ื˜ื™ืคึผ ื•ื•ืขืจื˜, ืึธื‘ืขืจ ืฉื˜ืขืœืŸ ื’ืจืขืกืขืจืข ื“ืึทื˜ืŸ ืื•ืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึท ืคืขืœื“ ืœืขื ื’ ื•ื•ืขืจื˜ ื•ื•ืึธืก ืฉื˜ื™ืžืขืŸ ื ื™ืฉื˜ ืฆื• ื“ื™ ื’ืจื™ื™ืก ืคื•ืŸ ื“ื™ ื“ืึทื˜ืŸ ืžื™ื˜ ื“ื™ INTEGER ื˜ื™ืคึผ, ื•ื•ืึธืก ื•ื•ืขื˜ ืคื™ืจืŸ ืฆื• ื“ื™ ืขืง ืคื•ืŸ ื“ื™ ื“ืึทื˜ืŸ. ืคื•ืŸ ื“ื™ ืคืขืœื“ ื•ื•ืึธืก ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ื•ื•ื™ื™ึทื˜ืขืจ ืคื•ืŸ ื“ื™ ืึทืœืึทืงื™ื™ื˜ื™ื“ ื‘ืึทืคืขืจ. ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ืงืึทื ื˜ืจืึธื•ืœื“ ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื•, ืื™ืจ ืงืขื ืขืŸ ืจื™ื“ื™ืคื™ื™ืŸ ื“ื™ ืฆื•ืจื™ืงืงืขืจ ื˜ื™ื™ึทื˜ืœ ืคื•ืŸ ื“ื™ ืคื•ื ืงืฆื™ืข ืื•ืŸ, ื ื™ืฆืŸ ืฆื•ืจื™ืงืงื•ืžืขืŸ-ืึธืจื™ืขื ื˜ื™ื“ ืคึผืจืึธื’ืจืึทืžืžื™ื ื’ ื˜ืขืงื ื™ืงืก (ROP - Return-Oriented Programming), ื“ืขืจื’ืจื™ื™ื›ืŸ ื“ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื“ื™ื™ืŸ ืงืึธื“.
  • CVE-2021-40439 ืื™ื– ืึท "ื‘ื™ืœื™ืึธืŸ ืœืึทืคืก" ื“ืึธืก ื‘ืึทืคืึทืœืŸ (ืงืกืžืœ ื‘ืึธืžื‘ืข), ื•ื•ืึธืก ืคื™ืจื˜ ืฆื• ื“ื™ ื™ื’ื–ืึธืกื˜ืฉืึทืŸ ืคื•ืŸ ืคืึทืจืึทื ืขืŸ ืกื™ืกื˜ืขื ืจืขืกื•ืจืกืŸ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืึท ืกืคึผืขืฉืœื™ ื“ื™ื–ื™ื™ื ื“ ื“ืึธืงื•ืžืขื ื˜.
  • CVE-2021-28129 - ื“ืขืจ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ื“ื™ DEB ืคึผืขืงืœ ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ ืื•ื™ืฃ ื“ื™ ืกื™ืกื˜ืขื ื•ื•ื™ ืึท ื ื™ื˜-ื•ื•ืึธืจืฆืœ ื‘ืึทื ื™ืฆืขืจ.

ื ื™ื˜-ื–ื™ื›ืขืจื”ื™ื™ื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ:

  • ื“ื™ ืฉืจื™ืคึฟื˜ ื’ืจื™ื™ืก ืื™ืŸ ื“ื™ ื”ื™ืœืฃ ืึธืคึผื˜ื™ื™ืœื•ื ื’ ื˜ืขืงืกื˜ืŸ ืื™ื– ื’ืขื•ื•ืืงืกืŸ.
  • ืึท ื ื•ืžืขืจ ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ื“ื™ ืึทืจื™ื™ึทื ืœื™ื™ื’ืŸ ืžืขื ื™ื• ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื™ืคืขืงืฅ ืคื•ืŸ ืคืึธื ื˜ื•ื•ืึธืจืง ืคืึทื ืฅ.
  • ืฆื•ื’ืขื’ืขื‘ืŸ ืึท ืคืขืœื ื“ื™ืง ื™ื™ืงืึทืŸ ืฆื• ื“ื™ ื˜ืขืงืข ืžืขื ื™ื• ืคึฟืึทืจ ื“ื™ ืคึผื“ืฃ ืขืงืกืคึผืึธืจื˜ ืคื•ื ืงืฆื™ืข.
  • ื“ื™ ืคึผืจืึธื‘ืœืขื ืžื™ื˜ ืึธื ื•ื•ืขืจ ืคื•ืŸ ื“ื™ื™ืึทื’ืจืึทืžื– ื•ื•ืขืŸ ืฉืคึผืึธืจืŸ ืื™ืŸ ODS ืคึฟืึธืจืžืึทื˜ ืื™ื– ืกืึทืœื•ื•ื“.
  • ืึทืŸ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืžื™ื˜ ืขื˜ืœืขื›ืข ื ื•ืฆื™ืง ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™ ื•ื•ืึธืก ืื™ื– ืืคื’ืขืฉื˜ืขืœื˜ ื“ื•ืจืš ื“ื™ ืึธืคึผืขืจืึทืฆื™ืข ื‘ืึทืฉื˜ืขื˜ื™ืงื•ื ื’ ื“ื™ืึทืœืึธื’ ืฆื•ื’ืขื’ืขื‘ืŸ ืื™ืŸ ื“ื™ ืคืจื™ืขืจื“ื™ืงืข ืžืขืœื“ื•ื ื’ ืื™ื– ืกืึทืœื•ื•ื“ (ืœืžืฉืœ, ื“ืขืจ ื“ื™ืึทืœืึธื’ ืื™ื– ื’ืขื•ื•ื™ื–ืŸ ื•ื•ืขืŸ ืจื™ืคืขืจื™ื ื’ ืฆื• ืึท ืึธืคึผื˜ื™ื™ืœื•ื ื’ ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ื“ืึธืงื•ืžืขื ื˜).

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’