Ọdịmma dị oke egwu na ProFTPd

Na ihe nkesa ftp ProFTPD mara adịghị ike dị ize ndụ (CVE-2019-12815), nke na-enye gị ohere idetu faịlụ n'ime ihe nkesa na-enweghị nkwenye site na iji iwu "site cpfr" na "site cpto". nsogbu ekenyere ọkwa egwu 9.8 n'ime 10, ebe ọ bụ na enwere ike iji ya hazie ogbugbu koodu ime ebe na-enye ohere na-amaghị aha na FTP.

Mgbanwe kpatara nlele na-ezighi ezi nke mmachi ohere maka ịgụ na ide data (Limit READ and Limit WRITE) na mod_copy modul, nke a na-eji na ndabara ma nyere aka na ngwugwu proftpd maka ọtụtụ nkesa. Ọ bụ ihe kwesịrị ịrịba ama na adịghị ike ahụ bụ ihe kpatara nsogbu yiri nke a na-edozibeghị kpamkpam. mara na 2015, nke ọhụrụ ọgụ vectors ugbu a matapụtara. Ọzọkwa, a kọọrọ ndị mmepe ahụ nsogbu ahụ na Septemba afọ gara aga, mana patch ahụ bụ kwadebere nanị ụbọchị ole na ole gara aga.

Nsogbu a na-apụtakwa na mwepụta ọhụrụ nke ProFTPd 1.3.6 na 1.3.5d. Ndozi dị ka kwachie. Dịka nchekwa nchekwa, a na-atụ aro ka ị gbanyụọ mod_copy na nhazi ahụ. Edobere adịghị ike ahụ naanị na Fedora ma na-anọgide na-emezighị ya Debian, SUSE/mepeeSUSE, Ubuntu, FreeBSD, EPEL-7 (A naghị enye ProFTPD na ebe nchekwa RHEL bụ isi, nsogbu ahụ emetụtaghị ngwugwu sitere na EPEL-6 n'ihi na ọ naghị agụnye mod_copy).

isi: opennet.ru

Tinye a comment