Qhov teeb meem tseem ceeb hauv Dovecot IMAP server

Π’ kho qhov tso tawm POP3/IMAP4 servers Dovecot 2.3.7.2 thiab 2.2.36.4, ntxiv rau hauv cov ntxiv Pigeonhole 0.5.7.2 thiab 0.4.24.2 , tshem tawm tseem ceeb heev vulnerability (CVE-2019-11500), uas tso cai rau koj sau cov ntaub ntawv dhau qhov kev faib tsis pub dhau los ntawm kev xa daim ntawv thov tsim tshwj xeeb ntawm IMAP lossis ManageSieve raws tu qauv.

Qhov teeb meem tuaj yeem siv tau ntawm theem ua ntej kev lees paub. Kev siv nyiaj ua haujlwm tseem tsis tau npaj, tab sis Dovecot cov neeg tsim khoom tsis txiav txim siab qhov muaj peev xwm ntawm kev siv qhov tsis zoo los teeb tsa cov chaw taws teeb tswj kev tawm tsam ntawm lub kaw lus lossis cov ntaub ntawv tsis pub lwm tus paub. Txhua tus neeg siv tau pom zoo kom nruab qhov hloov tshiab tam sim ntawd (Debian, Fedora, Arch Linux, Ubuntu, SUSE, RHEL, FreeBSD).

Qhov tsis zoo muaj nyob rau hauv IMAP thiab ManageSieve raws tu qauv parsers thiab yog tshwm sim los ntawm kev ua tsis raug ntawm cov cim tsis raug thaum txheeb xyuas cov ntaub ntawv hauv cov kab lus hais. Qhov teeb meem yog ua tiav los ntawm kev sau cov ntaub ntawv tsis txaus ntseeg rau cov khoom khaws cia sab nraud ntawm qhov tsis sib faib (txog 8 KB tuaj yeem sau dhau ntawm theem ua ntej kev lees paub, thiab txog 64 KB tom qab kev lees paub).

Los ntawm lub tswv yim Raws li cov engineers los ntawm Red Hat, siv qhov teeb meem rau kev tawm tsam tiag tiag yog qhov nyuaj vim tias tus neeg tawm tsam tsis tuaj yeem tswj hwm txoj haujlwm ntawm cov ntaub ntawv tsis txaus ntseeg overwrite nyob rau hauv heap. Hauv kev teb, cov kev xav tau nthuav tawm tias qhov tshwj xeeb no tsuas yog cuam tshuam qhov kev tawm tsam, tab sis tsis suav nrog nws qhov kev siv - tus neeg tawm tsam tuaj yeem rov ua qhov kev sim siv ntau zaus kom txog thaum nws nkag mus rau hauv thaj chaw ua haujlwm hauv heap.

Tau qhov twg los: opennet.ru

Ntxiv ib saib