Hloov Tor 0.3.5.10, 0.4.1.9 thiab 0.4.2.7 nrog tshem tawm DoS qhov tsis zoo

nthuav tawm kho qhov tso tawm ntawm Tor toolkit (0.3.5.10, 0.4.1.9, 0.4.2.7, 0.4.3.3-alpha), siv los npaj cov haujlwm ntawm Tor network tsis qhia npe. Cov tshiab versions kho ob qhov tsis zoo:

  • CVE-2020-10592 - tuaj yeem siv los ntawm txhua tus neeg tawm tsam los pib qhov kev tsis lees paub ntawm kev pabcuam rau relays. Kev tawm tsam kuj tuaj yeem ua los ntawm Tor cov npe servers los tua cov neeg siv khoom thiab cov kev pabcuam zais. Tus neeg tawm tsam tuaj yeem tsim cov xwm txheej uas ua rau muaj kev thauj khoom ntau dhau ntawm CPU, cuam tshuam kev ua haujlwm ib txwm ua rau ob peb feeb lossis feeb (los ntawm kev rov ua qhov kev tawm tsam, DoS tuaj yeem txuas ntxiv mus ntev). Qhov teeb meem tshwm sim txij li thaum tso tawm 0.2.1.5-alpha.
  • CVE-2020-10593 - ib qho chaw nyob deb tau pib lub cim xeeb xau uas tshwm sim thaum lub voj voog padding yog ob npaug rau tib cov saw hlau.

Nws tseem tuaj yeem sau tseg tias hauv Tor Browser 9.0.6 vulnerability nyob rau hauv lub add-on tseem unfixed NoScript, uas tso cai rau koj khiav JavaScript code hauv hom kev tiv thaiv zoo tshaj plaws. Rau cov neeg uas txwv tsis pub ua kom tiav JavaScript yog qhov tseem ceeb, nws raug nquahu kom lov tes taw kev siv JavaScript hauv browser ib ntus txog: config los ntawm kev hloov javascript.enabled parameter hauv about:config.

Lawv sim tshem tawm qhov tsis xws luag hauv NoScript 11.0.17, tab sis raws li nws muab tawm, lub tswv yim kho tsis tag daws cov teeb meem. Judging los ntawm cov kev hloov nyob rau hauv lub tom ntej no tso tawm NoScript 11.0.18, qhov teeb meem kuj tsis daws. Tor Browser suav nrog kev hloov kho NoScript tsis siv neeg, yog li thaum muaj kev txhim kho, nws yuav raug xa tuaj.

Tau qhov twg los: opennet.ru

Ntxiv ib saib