Rashin lahani a cikin Timeshift wanda ke ba ku damar haɓaka gata a cikin tsarin

Пр приложении TimeShift gano rauni (CVE-2020-10174), kyale mai amfani na gida don aiwatar da lamba azaman tushen. Timeshift shine tsarin ajiyar kuɗi wanda ke amfani da rsync tare da hardlinks ko Btrfs hotuna don samar da ayyuka kama da System Restore akan Windows da Time Machine akan macOS. An haɗa shirin a cikin ma'ajiyar rarrabawa da yawa kuma ana amfani dashi ta tsohuwa a cikin PCLinuxOS da Linux Mint. Kafaffen rauni a cikin saki Canjin lokaci 20.03.

Matsalar tana faruwa ne ta hanyar kuskuren sarrafa littafin /tmp na jama'a. Lokacin ƙirƙirar madadin, shirin yana ƙirƙirar directory / tmp/timeshift, wanda aka ƙirƙiri babban kundin adireshi tare da sunan bazuwar mai ɗauke da rubutun harsashi tare da umarni, ƙaddamar da haƙƙin tushen. Subdirectory tare da rubutun yana da suna maras tabbas, amma /tmp/timeshift kanta ana iya tsinkaya kuma ba a bincika don musanya ko ƙirƙirar hanyar haɗin gwiwa maimakon. Mai hari zai iya ƙirƙirar kundin adireshi /tmp/timeshift a madadinsa, sannan ya bi diddigin bayyanar babban kundin adireshi kuma ya maye gurbin wannan ƙaramin directory da fayil ɗin da ke cikinsa. Yayin aiki, Timeshift zai aiwatar, tare da haƙƙin tushen, ba rubutun da shirin ya samar ba, amma fayil ɗin da maharin ya maye gurbinsa.

source: budenet.ru

Add a comment