Kusagadzikana kwakanyanya muDovecot IMAP server

Π’ kugadzirisa zvinoburitswa POP3/IMAP4 maseva Dovecot 2.3.7.2 uye 2.2.36.4, uyewo mukuwedzera Pigeonhole 0.5.7.2 uye 0.4.24.2 , kubviswa kukanganiswa kwakanyanya (CVE-2019-11500), iyo inokutendera kuti unyore data kupfuura iyo yakagoverwa buffer nekutumira yakanyatso gadzirwa chikumbiro kuburikidza neIMAP kana ManageSieve protocol.

Dambudziko rinogona kushandiswa pane pre-authentication stage. Kubiridzira kwekushanda hakusati kwagadzirwa, asi vanogadzira Dovecot havarambidze mukana wekushandisa kusagadzikana kuronga kure kure kuuraya kodhi kurwiswa pane system kana kuvuza chakavanzika data. Vese vashandisi vanokurudzirwa kuisa zvigadziriso nekukurumidza (Debian, Fedora, Arch Linux, Ubuntu, suse, RHEL, FreeBSD).

Kusagadzikana kuripo muIMAP uye ManageSieve protocol parsers uye zvinokonzereswa nekugadziriswa kwemavara asina maturo kana uchidhinda data mukati metambo dzakadzokororwa. Dambudziko rinowanikwa nekunyora dhata zvisina tsarukano kune zvinhu zvakachengetwa kunze kwebhafa yakagoverwa (kusvika ku8 KB inogona kunyorwa padanho risati rasimbiswa, uye kusvika pa64 KB mushure mekusimbiswa).

By mafungiro Sekureva kweinjiniya kubva kuRed Hat, kushandisa dambudziko rekurwiswa chaiko kwakaoma nekuti anorwisa haakwanise kudzora chinzvimbo chekupokana data overwrites mumurwi. Mukupindura, pfungwa inoratidzwa kuti chimiro ichi chinongoomesa zvakanyanya kurwiswa, asi hachisarudzi kuita kwayo - munhu anorwisa anogona kudzokorora kuedza kwekushandisa kakawanda kusvikira apinda munzvimbo yekushanda mumurwi.

Source: opennet.ru

Voeg