Kusagadzikana kwakanyanya muProFTPd

MuProFTPD ftp server kuzivikanwa ngozi ine ngozi (CVE-2019-12815), iyo inokubvumira kukopa mafaira mukati mevhavha pasina kuvimbiswa uchishandisa "saiti cpfr" uye "saiti cpto" mirairo. dambudziko kupiwa Njodzi nhanho 9.8 kubva pagumi, sezvo ichigona kushandiswa kuronga kureba kodhi kuuraya uku ichipa kusazivikanwa kupinda kuFTP.

Kunetseka zvakakonzera cheki isiriyo yezvirambidzo zvekuwana kuverenga nekunyora data (Limit VERENGA uye Limit WRITE) mune mod_copy module, iyo inoshandiswa neyakagadzika uye inogoneswa muproftpd mapakeji ekugovera kwakawanda. Zvinokosha kuziva kuti kusadzivirirwa uku kunokonzerwa nedambudziko rakafanana iro risati ranyatsogadziriswa, kuzivikanwa muna 2015, izvo zvitsva zvekurwisa zvakaonekwa zvino. Uyezve, dambudziko rakataurwa kune vanogadzira kumashure munaGunyana gore rapfuura, asi chigamba chaive gadzirira mazuva mashoma apfuura.

Dambudziko rinoonekwawo mune zvichangobva kubuda zveProFTPd 1.3.6 uye 1.3.5d. Iyo yekugadzirisa inowanikwa se chigamba. Sekuchengetedza workaround, zvinokurudzirwa kudzima mod_copy mukugadzirisa. Kusagadzikana kwacho kusvika parizvino kwakagadziriswa chete mukati Fedora uye anoramba asina kururamiswa Debian, SUSE/openSUSE, Ubuntu, FreeBSD, EPEL-7 (ProFTPD haina kupihwa mune chikuru RHEL repository, uye pasuru kubva kuEPEL-6 haina kukanganiswa nedambudziko nekuti haisanganisi mod_copy).

Source: opennet.ru

Voeg