Samba 4.10.8 na 4.9.13 melite na adịghị ike idozi

Kwadoro Mwepụta mmezi nke ngwugwu Samba 4.10.8 na 4.9.13, nke kpochapụrụ adịghị ike (CVE-2019-10197), na-enye onye ọrụ ohere ịnweta ndekọ mgbọrọgwụ ebe akụkụ netwọk Samba dị. Nsogbu a na-eme mgbe akọwapụtara nhọrọ 'obosara njikọ = ee' na ntọala yana 'unix extensions = mba' ma ọ bụ 'kwe ka njikọ obosara enweghị nchebe = ee'. Ịnweta faịlụ na-abụghị nkebi na-ekekọrịta ugbu a bụ oke ikike ịnweta onye ọrụ, ya bụ. onye mwakpo ahụ nwere ike ịgụ na dee faịlụ dịka uid/gid ha siri dị.

Ihe kpatara nsogbu a bụ na mgbe arịrịọ mbụ maka mgbọrọgwụ nke ngalaba nkekọrịta, a na-eweghachite onye ahịa njehie ohere, mana smbd na-echekwa ohere nke ndekọ ma ghara ikpochapụ cache ahụ ma ọ bụrụ na enwere nsogbu ịnweta. N'ihi ya, mgbe izipu arịrịọ SMB ugboro ugboro, a na-ahazi ya nke ọma dabere na ntinye cache na-enweghị nlele ikike ugboro ugboro.

isi: opennet.ru

Tinye a comment