Kunetseka kwakanyanya CVE-2019-12815 muProFTPd

Kusagadzikana kwakakomba (CVE-2019-12815) kwaonekwa muProFTPd (yakakurumbira ftp-server). Kushanda kunokubvumidza kukopa mafaera mukati mesevha pasina humbowo uchishandisa "saiti cpfr" uye "saiti cpto" mirairo, kusanganisira pamaseva ane asingazivikanwi kuwana.

Kusagadzikana kunokonzerwa nekutarisisa kusiriko kwezvirambidzo zvekuwana kuverenga nekunyora data (Limit READ uye Limit WRITE) mune mod_copy module, iyo inoshandiswa nekusarudzika uye inogoneswa muproftpd mapakeji ekugovera kwakawanda.

Ese mavhezheni azvino pane ese kugoverwa kunze kweFedora anokanganisa. Iyo gadziriso iripo ikozvino se chigamba. Semhinduro yenguva pfupi, zvinokurudzirwa kudzima mod_copy.

Source: linux.org.ru

Voeg