Te whakaraerae i te whare pukapuka libjpeg-turbo

В libjpeg-turbo, he whare pukapuka mo te whakawaehere me te wetewete whakaahua JPEG, kua tautuhia whakaraeraetanga (CVE-2019-2201), ka arai ki te puhaketanga tauoti me te pirau o nga ihirangi puranga i te wa e tukatuka ana i nga konae JPEG i tetahi huarahi. Ka taea, kaore te whakaraerae e whakakore i te waahi ki te hanga i tetahi painga ki te whakarite i nga mahi waehere i runga i te punaha (me mahi te whakaeke i tetahi ahua tino nui me te taumira o 26755 x 26755).

He raruraru me te kore korero nui whakaritea i roto i te tuku 2.0.3, engari ko te ahua kua whakakorehia e kore rawa ka noho tonu etahi atu vector whakaeke. I nga tohatoha ka noho tonu te raru kaore i te whakatika (Debian, SUSE/openSUSE, RHEL, Fedora, Ubuntu).

Source: opennet.ru

Tāpiri i te kōrero