Rashin lahani a cikin kullun

В tarihi, aiwatar da ka'idar NTP da aka yi amfani da ita don daidaita daidaitaccen lokaci a cikin rarraba Linux daban-daban, gano rauni (CVE-2020-14367), ba ka damar sake rubuta kowane fayil akan tsarin tare da samun dama ga mara amfani mai amfani na gida. Za a iya yin amfani da raunin kawai ta hanyar mai amfani, wanda ke rage haɗarinsa. Koyaya, batun yana lalata matakin keɓancewa na zamani kuma ana iya yin amfani da shi idan an gano wata lahani a lambar da aka aiwatar bayan an sake saita gata.

Rashin lafiyar yana faruwa ne sakamakon rashin aminci na pid fayil, wanda aka ƙirƙira a wani mataki lokacin da chrony bai sake saita gata ba kuma yana gudana azaman tushen. A wannan yanayin, littafin /run / chrony directory, wanda aka rubuta pid file, an ƙirƙira shi tare da haƙƙin 0750 ta hanyar systemd-tmpfiles ko lokacin da aka ƙaddamar da chronyd a cikin haɗin gwiwa tare da mai amfani da rukuni "chrony". Don haka, idan kuna da damar yin amfani da tarihin mai amfani, yana yiwuwa a maye gurbin pid file /run/chrony/chronyd.pid tare da hanyar haɗi ta alama. Hanya ta alama na iya nuna kowane fayil ɗin tsarin da za a sake rubutawa lokacin da aka ƙaddamar da chronyd.

tushen# systemctl dakatar chronyd.service
tushen# sudo -u chrony /bin/bash

chrony$ cd /run/chrony
chrony$ ln -s /etc/shadow chronyd.pid
fita na tsawon lokaci $

tushen# /usr/sbin/chronyd -n
^C
# maimakon abubuwan da ke cikin /etc/shadow za a adana ID na tsari na chronyd
tushen# cat /etc/shadow
15287

Varfafawa shafe cikin fitowar 3.5.1. Sabunta fakitin da ke gyara raunin suna samuwa don Fedora. A cikin aiwatar da shirya sabuntawa don RHEL, Debian и Ubuntu.

SUSE da matsalar budeSUSE ba mai saukin kamuwa ba, tun da alamar haɗin yanar gizo don chrony an ƙirƙira shi kai tsaye a cikin /run directory, ba tare da yin amfani da ƙarin kundin adireshi ba.

source: budenet.ru

Add a comment