Vulnerabilities hauv libc thiab FreeBSD IPv6 pawg

FreeBSD tau kho ntau qhov tsis zoo uas tuaj yeem tso cai rau ib tus neeg siv hauv zos kom nce lawv cov cai ntawm lub cev:

  • CVE-2020-7458 - qhov tsis zoo nyob rau hauv posix_spawnp mechanism muab nyob rau hauv libc rau kev tsim cov txheej txheem, siv los ntawm kev qhia ntau dhau tus nqi hauv PATH ib puag ncig sib txawv. Qhov tsis zoo tuaj yeem ua rau sau cov ntaub ntawv tshaj qhov chaw nco tau faib rau pawg, thiab ua rau nws muaj peev xwm sau cov ntsiab lus ntawm cov buffers tom ntej nrog tus nqi tswj.
  • CVE-2020-7457 - qhov tsis zoo nyob rau hauv pawg IPv6 uas tso cai rau ib tus neeg siv hauv zos los teeb tsa kev ua tiav ntawm lawv cov lej ntawm qib kernel los ntawm kev tswj hwm siv IPV6_2292PKTOPTIONS kev xaiv rau lub qhov (socket) network.
  • Tshem tawm ob vulnerabilities (CVE-2020-12662, CVE-2020-12663) hauv DNS server Tsis khi, tso cai rau koj los ua qhov chaw taws teeb tsis lees paub kev pabcuam thaum nkag mus rau lub server tswj los ntawm tus neeg tawm tsam lossis siv DNS server ua lub suab nrov thaum ua DDoS tawm tsam.

Tsis tas li ntawd, peb qhov teeb meem tsis muaj kev ruaj ntseg (erratas) uas tuaj yeem ua rau lub pob tawg thaum siv tus tsav tsheb tau raug daws. mps (thaum ua tiav cov lus txib sas2ircu), subsystems LinuxKPI (nrog X11 redirection) thiab hypervisor bhyve ua (thaum xa cov khoom siv PCI).

Tau qhov twg los: opennet.ru

Ntxiv ib saib