Kama Python 3.5.8, e kesara ụdị ezighi ezi site na mmejọ

N'ihi njehie mgbe ị na-ahazi caching na sistemụ nnyefe ọdịnaya, mgbe ị na-agbalị ibudata otu n'ime ọgbakọ bipụtara ụbọchị tupu ụnyaahụ mmezi ntọhapụ Python 3.5.8 kesaa Ihe nrụpụta nhụchalụ nke enweghị ndozi niile. Nsogbu metụrụ aka Archive naanị Python-3.5.8.tar.xz, mgbakọ Python-3.5.8.tgz ekesara nke ọma.

Ndị ọrụ niile budata faịlụ “Python-3.5.8.tar.xz” n'ime awa iri na abụọ mbụ ka ahapụchara, a na-adụ ọdụ ka ha lelee izi ezi nke data ebudatara site na iji checksum (MD12 5ed4464517bca6044fc4ea78ed9c086). N'adịghị ka ntọhapụ ikpeazụ, ụdị nlele agụnyeghị mgbazi adịghị ike CVE-2019-16935 na koodu nkesa XML-RPC. Ọdịmma ahụ kwere ka ịgba ogbugba Javascript (XSS) site na ubi server_title n'ihi enweghị mgbanarị akụkụ akụkụ. Onye mwakpo nwere ike nweta ngbanwe Javascript ma ọ bụrụ na ngwa ahụ edobere aha nkesa dabere na ntinye onye ọrụ (dịka ọmụmaatụ, "server.set_server_name('test). ’)»).

isi: opennet.ru

Tinye a comment