Ọdịmma dị oke mkpa na sava Dovecot IMAP

В ntọhapụ mmezi POP3/IMAP4 sava Nduru 2.3.7.2 na 2.2.36.4, yana na mgbakwunye Nduru 0.5.7.2 na 0.4.24.2 , kpochapụrụ adịghị ike dị egwu (CVE-2019-11500), nke na-enye gị ohere ide data gafere ebe nchekwa ekenyela site na izipu arịrịọ ahaziri ahazi site na usoro IMAP ma ọ bụ JikwaaSieve.

Enwere ike iji nsogbu ahụ mee ihe n'oge nyocha mbụ. Emebebeghị nrigbu na-arụ ọrụ, mana ndị mmepe Dovecot anaghị ewepụ ohere nke iji adịghị ike iji hazie mwakpo ogbugbu koodu na sistemụ ma ọ bụ wepụta data nzuzo. A na-atụ aro ndị ọrụ niile ka ha wụnye mmelite ozugbo (Debian, Fedora, Arch Linux, Ubuntu, EBU, RHEL, FreeBSD).

Ọdịmma dị na IMAP na JikwaaSieve protocol parsers ma na-ebute ya site na nhazi ezighi ezi nke mkpụrụedemede efu mgbe ị na-atụgharị data n'ime eriri ekwuru. A na-enweta nsogbu ahụ site n'ide data aka ike na ihe echekwara na mpụga ebe nchekwa ekenyela (nwere ike idegharị ihe ruru 8 KB na ọkwa tupu nyocha, yana ruo 64 KB mgbe nyochachara ya).

Site echiche Ndị injinia sitere na Red Hat na-eme ka o sie ike iji nsogbu ahụ maka ezigbo ọgụ n'ihi na onye na-awakpo enweghị ike ijikwa ọnọdụ nke data aka ike na-edegharị na ikpo. Na nzaghachi, a na-ekwupụta echiche ahụ na njirimara a na-eme ka ọgụ ahụ dịkwuo njọ, ma ọ dịghị ewepu mmejuputa ya - onye na-awakpo ahụ nwere ike ịmegharị mgbalị nrigbu ọtụtụ ugboro ruo mgbe ọ banyere n'ebe ọrụ na ikpo.

isi: opennet.ru

Tinye a comment