Tso tawm ntawm GNU inetutils 2.5 nrog kev kho rau qhov tsis zoo hauv kev siv suid

Tom qab 14 lub hlis ntawm txoj kev loj hlob, GNU inetutils 2.5 suite tau tso tawm nrog kev sau ntawm cov kev pab cuam sib tham, feem ntau tau pauv los ntawm BSD systems. Tshwj xeeb, nws suav nrog inetd thiab syslogd, servers thiab cov neeg siv khoom rau ftp, telnet, rsh, rlogin, tftp thiab tham, nrog rau cov khoom siv xws li ping, ping6, traceroute, whois, hostname, dnsdomainname, ifconfig, logger, thiab lwm yam. .P.

Tus tshiab version tshem tawm qhov tsis zoo (CVE-2023-40303) hauv suid cov kev pab cuam ftpd, rcp, rlogin, rsh, rshd thiab uucpd, tshwm sim los ntawm qhov tsis muaj pov thawj ntawm cov txiaj ntsig rov qab los ntawm setuid(), setgid(), seteuid() thiab setguid() ua haujlwm . Qhov tsis muaj zog tuaj yeem siv los tsim cov xwm txheej uas hu rau set*id() yuav tsis rov pib dua cov cai thiab daim ntawv thov yuav ua haujlwm ntxiv nrog cov cai tshwj xeeb thiab ua haujlwm raws li lawv tau tsim los ua haujlwm nrog cov cai ntawm tus neeg siv tsis muaj cai. Piv txwv li, ftpd, uucpd, thiab rshd cov txheej txheem khiav raws li hauv paus yuav txuas ntxiv mus ua hauv paus tom qab cov neeg siv zaug pib yog teeb * id() ua tsis tiav.

Ntxiv rau kev tshem tawm qhov tsis zoo thiab qhov yuam kev me me, qhov tshiab version ntxiv kev txhawb nqa rau ICMPv6 cov lus nrog cov ntaub ntawv hais txog kev nkag tsis tau ntawm lub hom phiaj tus tswv tsev ("qhov chaw tsis tuaj yeem", RFC 6) rau ping4443 qhov hluav taws xob.

Tau qhov twg los: opennet.ru

Ntxiv ib saib