Hoʻohou i ka pūʻolo antivirus manuahi ClamAV 0.102.4

Hoʻokumu ʻia hoʻokuʻu i kahi pūʻolo antivirus manuahi ʻO ClamAV 0.102.4, kahi i hoopauia ai ekolu nawaliwali:

  • CVE-2020-3350 - Ua apono Hiki i ka mea hoʻouka kaua kūloko ke hoʻonohonoho i ka holoi ʻana a i ʻole ka neʻe ʻana o nā faila ma ka ʻōnaehana; no ka laʻana, hiki iā ʻoe ke holoi i /etc/passwd me ka loaʻa ʻole o nā ʻae pono. Hoʻokumu ʻia ka nāwaliwali ma muli o ke kūlana lāhui i ka wā e nānā ana i nā faila ʻino a hiki i kahi mea hoʻohana ke komo i ka pūpū ma ka ʻōnaehana e pani i ka papa kuhikuhi i hoʻopaʻa ʻia e nānā ʻia me kahi loulou hōʻailona e kuhikuhi ana i kahi ala ʻē aʻe.

    No ka laʻana, hiki i ka mea hoʻouka ke hana i kahi papa kuhikuhi "/home/user/exploit/" a hoʻouka i kahi faila me kahi hōʻailona virus hōʻoia i loko, e kapa ana i kēia faila "passwd". Ma hope o ka holo ʻana i ka polokalamu scan virus, akā ma mua o ka holoi ʻana i ka faila pilikia, hiki iā ʻoe ke hoʻololi i ka papa kuhikuhi "exploit" me kahi loulou hōʻailona e kuhikuhi ana i ka papa kuhikuhi "/ etc", kahi e hoʻopau ai ka antivirus i ka faila /etc/passwd. Hōʻike wale ʻia ka palupalu i ka wā e hoʻohana ai i ka clamscan, clamdscan a me clamonacc me ke koho "--move" a i ʻole "--remove".

  • ʻO CVE-2020-3327, CVE-2020-3481 he mau mea palupalu i nā modules no ka hoʻopaʻa ʻana i nā waihona ma nā palapala ARJ a me EGG, e ʻae ana i ka hōʻole ʻana i ka lawelawe ma o ka hoʻololi ʻana i nā waihona i hoʻolālā ʻia, ʻo ka hana ʻana e alakaʻi i ka pōʻino o ke kaʻina scan. .

Source: opennet.ru

Pākuʻi i ka manaʻo hoʻopuka