He palupalu ma Timeshift e hiki ai iā ʻoe ke hoʻokiʻekiʻe i kāu mau pono i ka ʻōnaehana

I ka palapala noi ʻO ka Timeshift ʻike ʻia palupalu (CVE-2020-10174), e ʻae ana i kahi mea hoʻohana kūloko e hoʻokō i ke code ma ke ʻano he kumu. He ʻōnaehana hoʻihoʻi ʻo Timeshift e hoʻohana ana i ka rsync me nā hardlinks a i ʻole nā ​​​​paʻi kiʻi Btrfs e hāʻawi i nā hana e like me ka System Restore ma Windows a me Time Machine ma macOS. Hoʻokomo ʻia ka papahana i loko o nā waihona o nā māhele he nui a hoʻohana ʻia e ka paʻamau ma PCLinuxOS a me Linux Mint. Hoʻopaʻa ʻia ka vulnerability i ka hoʻokuʻu ʻana Hoʻololi manawa 20.03.

Hoʻokumu ʻia ka pilikia ma muli o ka lawelawe hewa ʻana o ka papa kuhikuhi lehulehu /tmp. I ka hana ʻana i kahi hoʻihoʻi, hana ka papahana i kahi papa kuhikuhi /tmp/timeshift, kahi i hana ʻia ai kahi subdirectory me kahi inoa maʻamau i loaʻa kahi hōʻailona shell me nā kauoha, i hoʻokuʻu ʻia me nā kuleana kumu. He inoa ʻike ʻole ʻia ka subdirectory me ka palapala, akā hiki ke wānana ʻia /tmp/timeshift a ʻaʻole nānā ʻia no ka hoʻololi ʻana a i ʻole ka hana ʻana i kahi loulou hōʻailona. Hiki i ka mea hoʻouka ke hana i kahi papa kuhikuhi /tmp/timeshift nona iho, a laila e nānā i ke ʻano o kahi subdirectory a hoʻololi i kēia subdirectory a me ka faila i loko. I ka wā o ka hana, e hoʻokō ʻo Timeshift, me nā kuleana kumu, ʻaʻole kahi palapala i hana ʻia e ka papahana, akā he faila i pani ʻia e ka mea hoʻouka.

Source: opennet.ru

Pākuʻi i ka manaʻo hoʻopuka