Samba 4.10.8 ndi 4.9.13 zosintha zokhala ndi chiopsezo

Zokonzekera kutulutsidwa kwa phukusi la Samba 4.10.8 ndi 4.9.13, lomwe linathetsedwa kusatetezeka (CVE-2019-10197), kulola wosuta kuti alowe muzolemba zomwe gawo la Samba network lili. Vuto limachitika pamene njira ya 'wide links = inde' yafotokozedwa muzokonda kuphatikiza ndi 'unix extensions = no' kapena 'lolani maulalo osatetezeka ambiri = inde'. Kufikira mafayilo omwe ali kunja kwa magawo omwe akugawidwa pano akuchepa ndi ufulu wa wogwiritsa ntchito, i.e. wowukirayo amatha kuwerenga ndi kulemba mafayilo malinga ndi uid/gid yawo.

Vutoli limayamba chifukwa cha pempho loyamba la muzu wa magawo omwe adagawana nawo, cholakwika chofikira chimabwezeredwa kwa kasitomala, koma smbd imasunga chikwatu cholowera ndipo sichichotsa posungira pakagwa vuto. Chifukwa chake, mutatumiza pempho la SMB mobwerezabwereza, limakonzedwa bwino potengera zomwe zasungidwa popanda chilolezo chobwerezabwereza.

Source: opennet.ru

Kuwonjezera ndemanga