Fa'asa'olotoina o le GNU inetutils 2.5 fa'atasi ai ma le fa'aleleia mo le fa'aletonu i talosaga suid

Ina ua maeʻa le 14 masina o le atinaʻe, na faʻasaʻolotoina le GNU inetutils 2.5 suite ma se aofaʻiga o polokalame fesoʻotaʻiga, o le tele o ia mea na faʻafeiloaʻi mai faiga BSD. Aemaise lava, e aofia ai inetd ma syslogd, 'auʻaunaga ma tagata faʻatau mo ftp, telnet, rsh, rlogin, tftp ma tautala, faʻapea foʻi ma faʻaoga masani e pei o ping, ping6, traceroute, whois, hostname, dnsdomainname, ifconfig, logger, ma isi. .P.

O le lomiga fou e faʻaumatia ai se faʻafitauli (CVE-2023-40303) i polokalame suid ftpd, rcp, rlogin, rsh, rshd ma uucpd, mafua mai i le leai o se faʻamaoniga o tau na toe faʻafoʻi mai e le setuid (), setgid (), seteuid() ma setguid() galuega . O le fa'aletonu e mafai ona fa'aogaina e fa'atupu ai tulaga e le toe fa'afo'i ai fa'amanuiaga le vala'au set*id() ma o le a fa'aauau pea ona galue le talosaga ma fa'aeaea maualuga ma fa'atino galuega i lalo o ia mea na muai fuafuaina e galulue ai ma aia tatau a se tagata fa'aoga le lelei. Mo se faʻataʻitaʻiga, ftpd, uucpd, ma rshd faagasologa o loʻo faʻagaioia e pei o aʻa o le a faʻaauau pea ona taʻavale e pei o aʻa pe a uma le faʻaogaina o vasega pe a le seti * id() le manuia.

I le faʻaopoopoga i le faʻaumatiaina o faʻafitauli ma nai mea sese, o le lomiga fou e faʻaopoopoina le lagolago mo feʻau ICMPv6 faʻatasi ai ma faʻamatalaga e uiga i le le mafai ona oʻo atu i ai le 'au faʻamoemoe ("destination unreachable", RFC 6) i le aoga ping4443.

puna: opennet.ru

Faaopoopo i ai se faamatalaga