Melite Tor 0.3.5.10, 0.4.1.9 na 0.4.2.7 na mkpochapụ nke adịghị ike DoS

Enyere ya Mwepụta mmezi nke ngwa ngwa Tor (0.3.5.10, 0.4.1.9, 0.4.2.7, 0.4.3.3-alpha), eji ahazi ọrụ nke netwọk Tor amaghị aha. Ụdị ọhụrụ a na-edozi adịghị ike abụọ:

  • CVE-2020-10592 - enwere ike iji onye ọ bụla na-awakpo wee malite ịgọnarị ọrụ relays. Ndị sava Tor nwekwara ike ime mwakpo ahụ iji wakpo ndị ahịa na ọrụ zoro ezo. Onye na-awakpo nwere ike ịmepụta ọnọdụ ndị na-eduga n'ibu ibu na CPU, na-akpaghasị ọrụ nkịtị maka ọtụtụ sekọnd ma ọ bụ nkeji (site n'ịmeghachi mwakpo ahụ, enwere ike ịgbatị DoS ogologo oge). Nsogbu a na-apụta kemgbe ewepụtara 0.2.1.5-alpha.
  • CVE-2020-10593 - mgbanaka ebe nchekwa ewepụtara nke na-eme mgbe padding sekit jikọtara okpukpu abụọ maka otu agbụ.

Enwere ike ịhụ na n'ime 9.0.6 nchọgharị nyocha adịghị ike na mgbakwunye na-anọgide na-edozighị ya NoScript, nke na-enye gị ohere ịme koodu Javascript na ọnọdụ nchekwa kacha mma. Maka ndị machibido ogbugbu JavaScript dị mkpa maka ya, a na-atụ aro ka ị gbanyụọ Javascript nwa oge na ihe nchọgharị ihe: config site n'ịgbanwe paramita javascript.enabled na ihe dị ka: config.

Ha gbalịrị ikpochapụ ntụpọ ahụ Akwụkwọ ọ bụla 11.0.17, ma dị ka ọ tụgharịrị, ihe a na-atụ aro adịghị edozi nsogbu ahụ kpamkpam. Na-ekpe ikpe site na mgbanwe na ntọhapụ ewepụtara na-esote Akwụkwọ ọ bụla 11.0.18, a naghị edozikwa nsogbu ahụ. Tor Browser gụnyere mmelite NoScript akpaka, yabụ ozugbo enwere ndozi, a ga-ebunye ya na akpaghị aka.

isi: opennet.ru

Tinye a comment