Emebere adịghị ike atọ na FreeBSD

FreeBSD na-ekwu maka adịghị ike atọ nwere ike inye ohere igbu koodu mgbe ị na-eji libfetch, nnyefe IPsec, ma ọ bụ ịnweta data kernel. A na-edozi nsogbu ndị ahụ na mmelite 12.1-RELEASE-p2, 12.0-RELEASE-p13 na 11.3-RELEASE-p6.

  • CVE-2020-7450 - ihe nchekwa ihe na-ejupụta n'ọbá akwụkwọ libfetch, nke a na-ebunye faịlụ na iwu mbubata, onye njikwa ngwugwu pkg na akụrụngwa ndị ọzọ. Ọdịmma ahụ nwere ike bute mkpochapụ koodu mgbe ị na-ahazi URL ahaziri ahazi. Enwere ike ịme mwakpo ahụ mgbe ị na-abanye na saịtị nke onye na-awakpo ahụ na-achịkwa, nke, site na HTTP redirect, na-enwe ike ịmalite nhazi nke URL ọjọọ;
  • CVE-2019-15875 - adịghị ike na usoro maka ịmepụta isi usoro mkpofu. N'ihi mperi, ihe ruru bytes 20 nke data sitere na nchịkọta kernel ka edekọtara n'ime mkpofu isi, nke nwere ike ịnwe ozi nzuzo nke kernel mebere. Dị ka ihe nchekwa maka nchekwa, ị nwere ike gbanyụọ ọgbọ nke isi faịlụ site na sysctl kern.coredump=0;
  • CVE-2019-5613 - ahụhụ dị na koodu maka igbochi izipu data na IPsec mere ka o kwe omume iziga ngwugwu eweghara na mbụ. Dabere na protocol dị elu ebutere n'elu IPsec, nsogbu ahụ achọpụtara na-enye ohere, dịka ọmụmaatụ, iwu ndị ebufere na mbụ ka iwere ya.

isi: opennet.ru

Tinye a comment