Sabunta fakitin riga-kafi kyauta ClamAV 0.102.2 tare da kawar da lahani

An kafa sakin kunshin riga-kafi na kyauta Kira 0.102.2, wanda ke gyara raunin CVE-2020-3123 a cikin aiwatar da tsarin DLP (haɓaka-asara-bayanai) da nufin toshe leaks na lambobin katin kiredit. Saboda kuskure a cikin rajistan iyakoki, yana yiwuwa a ƙirƙiri yanayi don karanta bayanai daga wani yanki a waje da buffer ɗin da aka keɓe, wanda za'a iya amfani da shi don aiwatar da harin DoS da fara faɗuwar aiki. Bugu da ƙari, an ƙara gyara don raunin CVE-0.102-2019, wanda aka rasa a cikin reshe na 1785, wanda ke ba da damar rubuta bayanai zuwa yankin FS a waje da kundin adireshi da aka yi amfani da shi don cirewa lokacin da aka tsara musamman na RAR archives.

Sabuwar sakin kuma tana gyara batutuwan da ba na tsaro da yawa ba, yana gyara ɓarna tare da loda sabon juzu'in bayanan a cikin freshclam, yana gyara ƙwanƙwasa ƙwaƙwalwar ajiya a cikin parser ɗin imel, yana haɓaka aikin bincika fayilolin PDF akan dandamalin Windows, yana ƙarfafa bincikar ARJ. rumbun adana bayanai, kuma yana haɓaka sarrafa fayilolin PDF da ba daidai ba, ƙarin tallafi don autoconf 2.69 da sarrafa atomatik 1.15.

source: budenet.ru

Add a comment