Tso tawm Pacman 5.2 tus thawj tswj pob

Muaj pob tus thawj tswj tso tawm Pacman 5.2, siv hauv Arch Linux faib. Los ntawm kev hloov yuav txawv:

  • Kev them nyiaj yug rau delta hloov tshiab tau raug tshem tawm tag nrho, tso cai rau tsuas yog hloov pauv mus rub tawm. Lub feature tau raug tshem tawm vim muaj qhov tsis zoo raug txheeb xyuas (CVE-2019-18183), uas tso cai rau koj los khiav arbitrary commands nyob rau hauv lub system thaum siv unsigned databases. Rau kev tawm tsam, nws yog qhov tsim nyog rau tus neeg siv rub tawm cov ntaub ntawv npaj los ntawm tus neeg tawm tsam nrog cov ntaub ntawv thiab cov hloov tshiab delta. Kev them nyiaj yug rau delta hloov tshiab tau raug cuam tshuam los ntawm lub neej ntawd thiab tsis tau siv dav. Nyob rau hauv lub neej yav tom ntej, nws yog npaj los sau tag nrho cov kev siv ntawm delta hloov tshiab;
  • Ib qhov tsis zoo tau raug kho nyob rau hauv XferCommand hais kom ua handler (CVE-2019-18182), tso cai, thaum muaj kev tawm tsam MITM thiab cov ntaub ntawv tsis tau kos npe, kom ua tiav nws cov lus txib hauv qhov system;
  • Makepkg tau ntxiv lub peev xwm los txuas cov neeg ua haujlwm rau rub tawm cov pob khoom thiab kuaj xyuas los ntawm kos npe digital. Ntxiv kev txhawb nqa rau pob ntawv compression siv lub lzip, lz4 thiab zstd algorithms. Ntxiv kev txhawb nqa rau database compression siv zstd rau repo-ntxiv. Yuav los sai sai rau Arch Linux cia siab tias yuav hloov mus rau kev siv zstd los ntawm lub neej ntawd, uas, piv rau "xz" algorithm, yuav ua kom ceev cov kev khiav hauj lwm ntawm compressing thiab decompressing pob ntawv, thaum tswj cov qib compression;
  • Nws muaj peev xwm sib sau ua ke siv Meson system hloov Autotools. Hauv kev tso tawm tom ntej, Meson yuav hloov tag nrho Autotools;
  • Ntxiv kev txhawb nqa rau kev thauj khoom PGP yuam sij siv lub Web Key Directory (WKD), qhov tseem ceeb ntawm qhov uas yog muab cov yuam sij rau pej xeem hauv lub vev xaib nrog qhov txuas mus rau lub npe sau tseg hauv qhov chaw xa ntawv. Piv txwv li, rau qhov chaw nyob "[email tiv thaiv]"Tus yuam sij tuaj yeem rub tawm ntawm qhov txuas "https://example.com/.well-known/openpgpkey/hu/183d7d5ab73cfc5ece9a5f94e6039d5a". Kev thauj cov yuam sij ntawm WKD yog qhib los ntawm lub neej ntawd hauv pacman, pacman-key thiab makepkg;
  • Qhov kev xaiv "--force" tau raug tshem tawm, tsis yog qhov kev xaiv "--overwrite", uas qhia meej dua qhov tseem ceeb ntawm kev ua haujlwm, tau thov ntau tshaj ib xyoos dhau los;
  • Cov ntaub ntawv tshawb fawb tau siv qhov kev xaiv -F muab cov ntaub ntawv nthuav dav xws li pawg pob thiab kev teeb tsa.

Tau qhov twg los: opennet.ru

Ntxiv ib saib