Adịghị ike na Timeshift na-enye gị ohere ibuli ihe ùgwù gị na sistemụ

Na ngwa Timeshift mara adịghị ike (CVE-2020-10174), ikwe ka onye ọrụ mpaghara mebie koodu dị ka mgbọrọgwụ. Timeshift bụ usoro nkwado ndabere na mpaghara nke na-eji rsync na hardlinks ma ọ bụ Btrfs snapshots iji nye ọrụ dị ka System Restore na Windows na Time Machine na macOS. Agụnyere mmemme a na ebe nchekwa nke ọtụtụ nkesa ma ejiri ya na ndabara na PCLinuxOS na Linux Mint. Edobere adịghị ike na ntọhapụ Oge mgbanwe 20.03.

Ihe kpatara nsogbu a bụ ijikwa akwụkwọ ndekọ ọha /tmp na-ezighi ezi. Mgbe ị na-eke nkwado ndabere na mpaghara, mmemme ahụ na-emepụta ndekọ / tmp/timeshift, nke a na-emepụta subdirectory nwere aha enweghị aha nwere edemede shei nwere iwu, nke ejiri ikike mgbọrọgwụ malite. Akwụkwọ ndekọ aha ya na edemede ahụ nwere aha a na-atụghị anya ya, mana /tmp/timeshift n'onwe ya bụ nke a na-ahụ anya ma enyochaghị ya maka nnọchi ma ọ bụ mepụta njikọ ihe atụ kama. Onye na-awakpo nwere ike ịmepụta ndekọ /tmp/timeshift n'aha nke ya, wee soro ọdịdị nke subdirectory wee dochie subdirectory a na faịlụ dị na ya. N'oge arụ ọrụ, Timeshift ga-eme, na ikike mgbọrọgwụ, ọ bụghị edemede nke mmemme ahụ mepụtara, kama faịlụ nke onye mwakpo ahụ nọchiri anya.

isi: opennet.ru

Tinye a comment