Qhov tsis zoo hauv Timeshift uas tso cai rau koj los txhawb koj cov cai hauv lub cev

П Π»Ρ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠΈ TimeShift txheeb xyuas yooj yim (CVE-2020-10174), tso cai rau tus neeg siv hauv zos los ua cov cai raws li hauv paus. Timeshift yog cov txheej txheem thaub qab uas siv rsync nrog hardlinks lossis Btrfs snapshots los muab kev ua haujlwm zoo ib yam li System Restore ntawm Windows thiab Lub Sijhawm Tshuab ntawm macOS. Qhov kev zov me nyuam suav nrog hauv cov chaw khaws khoom ntawm ntau qhov kev faib tawm thiab siv los ntawm lub neej ntawd hauv PCLinuxOS thiab Linux Mint. Vulnerability kho nyob rau hauv kev tso tawm Sijhawm Sijhawm 20.03.

Qhov teeb meem yog tshwm sim los ntawm kev tuav tsis raug ntawm /tmp public directory. Thaum tsim ib qho thaub qab, qhov kev pab cuam tsim cov npe / tmp / timeshift, nyob rau hauv uas ib tug subdirectory nrog ib tug random lub npe yog tsim muaj ib tug plhaub ntawv nrog commands, launched nrog lub hauv paus txoj cai. Lub subdirectory nrog tsab ntawv muaj lub npe tsis paub tseeb, tab sis /tmp/timeshift nws tus kheej yog kwv yees tau thiab tsis raug tshuaj xyuas rau kev hloov pauv lossis tsim cov cim txuas ntxiv. Tus neeg tawm tsam tuaj yeem tsim cov npe / tmp / timeshift ntawm nws tus kheej, tom qab ntawd taug qab cov tsos ntawm subdirectory thiab hloov cov subdirectory thiab cov ntaub ntawv hauv nws. Thaum lub sijhawm ua haujlwm, Timeshift yuav ua tiav, nrog cov cai hauv paus, tsis yog tsab ntawv tsim los ntawm qhov program, tab sis cov ntaub ntawv hloov los ntawm tus neeg tawm tsam.

Tau qhov twg los: opennet.ru

Ntxiv ib saib