Mummunan rauni a cikin uwar garken Dovecot IMAP

В gyara gyara POP3/IMAP4 sabobin Dovecot 2.3.7.2 da 2.2.36.4, da kuma a cikin kari Ramin tattabara 0.5.7.2 da 0.4.24.2 , shafe m rauni (CVE-2019-11500), wanda ke ba ka damar rubuta bayanai fiye da abin da aka keɓe ta hanyar aika buƙatun ƙira ta musamman ta hanyar IMAP ko Sarrafa Sieve.

Ana iya amfani da matsalar a matakin tabbatarwa. Har yanzu ba a shirya cin gajiyar aiki ba, amma masu haɓaka Dovecot ba su kawar da yuwuwar yin amfani da rauni don tsara hare-haren kisa na code a kan tsarin ko ɓoye bayanan sirri ba. Ana ba da shawarar duk masu amfani don shigar da sabuntawa nan da nan (Debian, Fedora, Arch Linux, Ubuntu, SUSE, RHEL, FreeBSD).

Rashin lahani yana wanzu a cikin IMAP da ManageSieve protocol parsers kuma yana faruwa ta hanyar sarrafa haruffa mara kyau lokacin da ake tantance bayanai a cikin igiyoyin da aka ambata. Ana samun matsalar ta hanyar rubuta bayanan sabani zuwa abubuwan da aka adana a wajen ajiyar da aka keɓe (ana iya rubuta har zuwa 8 KB a mataki kafin tantancewa, kuma har zuwa 64 KB bayan tantancewa).

By ra'ayi Injiniyoyi daga Red Hat suna da wahala a yi amfani da matsalar don kai hare-hare na gaske saboda maharin ba zai iya sarrafa matsayin bayanan sabani a cikin tudu. Dangane da martani, an bayyana ra'ayin cewa wannan yanayin yana dagula harin ne kawai, amma ba ya ware aiwatar da shi - maharin na iya maimaita ƙoƙarin yin amfani da shi sau da yawa har sai ya shiga wurin aiki a cikin tsibi.

source: budenet.ru

Add a comment