Chiwopsezo mu chrony

Π’ chrony, kukhazikitsidwa kwa protocol ya NTP yomwe imagwiritsidwa ntchito kulumikiza nthawi yeniyeni mu magawo osiyanasiyana a Linux, kudziwika kusatetezeka (CVE-2020-14367), kukulolani kuti mulembenso fayilo iliyonse pamakina ndi mwayi wogwiritsa ntchito chrony wamba. Chiwopsezocho chikhoza kugwiritsidwa ntchito kudzera mwa wosuta chrony, zomwe zimachepetsa ngozi yake. Komabe, vutoli limasokoneza kuchuluka kwa kudzipatula mu chrony ndipo litha kugwiritsidwa ntchito ngati chiwopsezo china chadziwika mu code yomwe idachitika mwayi utakhazikitsidwanso.

Chiwopsezochi chimayamba chifukwa cha kusatetezeka kwa fayilo ya pid, yomwe idapangidwa panthawi yomwe chrony anali asanakhazikitsenso mwayi ndipo anali kuyenda ngati mizu. Pankhaniyi, chikwatu cha / run/chrony, momwe fayilo ya pid idalembedwa, idapangidwa ndi ufulu 0750 kudzera pa systemd-tmpfiles kapena pomwe chronyd idakhazikitsidwa mogwirizana ndi wogwiritsa ntchito ndi gulu "chrony". Chifukwa chake, ngati muli ndi mwayi wogwiritsa ntchito chrony, ndizotheka kusintha fayilo ya pid /run/chrony/chronyd.pid ndi ulalo wophiphiritsa. Ulalo wophiphiritsa ukhoza kuloza ku fayilo iliyonse yamakina yomwe idzalembedwenso chronyd ikakhazikitsidwa.

root# systemctl siyani chronyd.service
mizu # sudo -u chrony /bin/bash

chrony$ cd /run/chrony
chrony$ ln -s /etc/shadow chronyd.pid
chrony$ kuchoka

mizu # /usr/sbin/chronyd -n
^C
# m'malo mwa zomwe zili mu /etc/shadow ID ya ndondomeko ya chronyd idzasungidwa
mizu # mphaka /etc/shadow
15287

Chiwopsezo kuthetsedwa mu nkhani chrony 3.5.1. Zosintha zamaphukusi zomwe zimakonza chiwopsezo zilipo Fedora. Pokonzekera zosintha za RHEL, Debian ΠΈ Ubuntu.

SUSE ndi vuto la OpenSUSE osatengeka, popeza ulalo wophiphiritsa wa chrony umapangidwa mwachindunji mu /run directory, osagwiritsa ntchito ma subdirectories ena.

Source: opennet.ru

Kuwonjezera ndemanga