Cholakwika mu OpenSSL chinaphwanya mapulogalamu ena otsegukaSUSE Tumbleweed atasinthidwa

Kukonzanso OpenSSL kuti ikhale 1.1.1b mu malo otsegula aSUSE Tumbleweed Led ΠΊ kuphwanya magwiridwe antchito ena okhudzana ndi libopenssl ndikugwiritsa ntchito madera aku Russia kapena ku Ukraine. Vutoli lidawonekera pambuyo powonjezera ku OpenSSL kusintha kwa chosungira uthenga wolakwika (SYS_str_reasons). Buffer imatanthauzidwa pa 4 kilobytes, koma izi sizinali zokwanira kumadera ena a Unicode.

Kutulutsa kwa strerror_r, komwe kumagwiritsidwa ntchito kudzaza buffer, ndi 6856 byte kudera la Russia, ndi 7000 kudera la Ukraine. Mu code OpenSSL, poyambirira anali fufuzani ngati zikusefukira, koma ndi pamene mchira wadulidwa anaganizira kukula kwake kunali kokulirapo kuposa mtengo weniweniwo, zomwe zidapangitsa kusefukira kwa baiti imodzi ndikuwonongeka pokweza zolemba za zolakwika zomwe zinali zazitali kwambiri.

Panopa okonzeka kale kukonza, koma sichinavomerezedwebe. Kuti mubwerere ku mtundu wakale wokhazikika (OpenSSL 1.1.0h) mutha kuyendetsa malamulo awa:

sudo zypper mu tumbleweed-cli
sudo tumbleweed init
sudo tumbleweed switch 20190514
sudo zypper ref && sudo zypper dup && sudo zypper inr

Source: opennet.ru

Kuwonjezera ndemanga