Hloov tshiab ntawm pob dawb antivirus ClamAV 0.102.4

Tsim tso tawm ib pob dawb antivirus Clam AV 0.102.4, nyob rau hauv uas peb raug tshem tawm yooj yim:

  • CVE-2020-3350 - nws tso cai rau tus neeg tawm tsam hauv cheeb tsam tsis muaj cai tuaj yeem teeb tsa kev tshem tawm lossis txav ntawm cov ntaub ntawv tsis txaus ntseeg ntawm lub kaw lus; piv txwv li, koj tuaj yeem rho tawm /etc/passwd yam tsis muaj kev tso cai tsim nyog. Qhov tsis zoo yog tshwm sim los ntawm kev sib tw kis las uas tshwm sim thaum luam theej duab cov ntaub ntawv tsis zoo thiab tso cai rau tus neeg siv nrog lub plhaub nkag ntawm lub kaw lus los hloov lub hom phiaj cov npe yuav raug tshuaj xyuas nrog cov cim txuas taw qhia mus rau lwm txoj hauv kev.

    Piv txwv li, tus neeg tawm tsam tuaj yeem tsim cov npe "/home/user/exploit/" thiab xa cov ntaub ntawv nrog tus kab mob kos npe rau hauv nws, npe cov ntaub ntawv no "passwd". Tom qab khiav cov kab mob scan program, tab sis ua ntej rho tawm cov ntaub ntawv teeb meem, koj tuaj yeem hloov lub "exploit" directory nrog cov cim txuas taw qhia rau "/etc" directory, uas yuav ua rau cov antivirus rho tawm cov ntaub ntawv /etc/passwd. Qhov yooj yim tsuas yog tshwm sim thaum siv clamscan, clamdscan thiab clamonacc nrog rau "--tsav" lossis "--tshem" kev xaiv.

  • CVE-2020-3327, CVE-2020-3481 yog qhov tsis zoo hauv cov qauv rau kev txheeb xyuas cov ntaub ntawv hauv ARJ thiab EGG hom, tso cai tsis lees paub kev pabcuam los ntawm kev hloov pauv ntawm cov ntaub ntawv tshwj xeeb tsim, kev ua haujlwm uas yuav ua rau muaj kev sib tsoo ntawm cov txheej txheem scanning. .

Tau qhov twg los: opennet.ru

Ntxiv ib saib