Faʻamatalaga mo Java SE, MySQL, VirtualBox ma isi oloa Oracle faʻatasi ai ma faʻafitauli faʻapitoa

Kamupani Oracle lomia fuafuaina le tatalaina o faʻafouga i ana oloa (Critical Patch Update), faʻamoemoe e faʻaumatia faʻafitauli ogaoga ma faʻafitauli. I le faʻafouga o Aperila na faʻaumatia atoa 297 fa'aletonu.

Mataupu Java SE 12.0.1, 11.0.3 ma le 8u212 5 fa'afitauli tau puipuiga. O fa'aletonu uma e mafai ona fa'aogaina mamao e aunoa ma le fa'amaoni. Tasi fa'afitauli fa'apitoa ile Windows platform tofia CVSS Score 9.0 (CVE-2019-2699), lea e fetaui ma se tulaga mataʻutia o le lamatiaga ma faʻatagaina se tagata faʻaoga e le faʻamaonia i luga o le upega tafailagi e faʻafefe ai Java SE talosaga. E lua fa'afitauli i le 2D graphics processing subsystem ua tu'uina atu i le tulaga 8.1 (CVE-2019-2697, CVE-2019-2698). E le'i fa'ailoa mai fa'amatalaga.

I le faaopoopo atu i mataupu i Java SE, o faʻafitauli ua faʻaalia i isi oloa Oracle, e aofia ai:

  • 40 fa'aletonu i MySQL (tulaga maualuga maualuga 7.5). Le fa'afitauli sili ona mata'utia
    (CVE-2019-2632) e a'afia ai le subsystem fa'amautu fa'amautu. O fa'afitauli o le a fa'aleleia i fa'asalalauga MySQL Community Server 8.0.16, 5.7.26 ma le 5.6.44.

  • 12 fa'aletonu i VirtualBox, lea e 7 o loʻo i ai se tulaga ogaoga o lamatiaga (CVSS Score 8.8). O faʻafitauli e faʻamautu i faʻafouga VirtualBox 6.0.6 ma le 5.2.28 (i fa'amatalaga o le mea moni o faʻafitauli tau puipuiga na foia e leʻi faʻasalalau aʻo leʻi tatalaina). E leʻo tuʻuina atu faʻamatalaga, ae faʻamasino i le maualuga o le CVSS, o faʻafitauli ua faʻamautuina, fa'aalia i le tauvaga a le Pwn2Own 2019 ma fa'atagaina oe e fa'atino le fa'ailoga i luga o le 'au talimalo mai le si'osi'omaga fa'apitoa.

    faʻatagaina oe e osofaʻia le polokalama talimalo mai le siosiomaga malolo.

  • 3 fa'aletonu i luga o Solaris (faʻalavelave maualuga 5.3 - faʻafitauli i le pule o pusa IPS, SunSSH ma le auaunaga faʻapipiʻi loka. Faʻafitauli faʻapipiʻi i le faʻamalolo
    Solaris 11.4 SRU8, lea na toe faʻaauau ai foʻi le lagolago mo faletusi UCB (libucb, librpcsoc, libdbm, libtermcap, libcurses) ma le fc-fabric service, faʻafouina pusa lomiga
    ibus 1.5.19, NTP 4.2.8p12,
    Firefox 60.6.0esr,
    NOFOAIGA 9.11.6
    OpenSSL 1.0.2r,
    MySQL 5.6.43 & 5.7.25,
    libxml2 2.9.9,
    libxslt 1.1.33,
    Wireshark 2.6.7,
    tu'u 6.1.0.20190105,
    Apache httpd 2.4.38,
    perl 5.22.

puna: opennet.ru

Faaopoopo i ai se faamatalaga