GnuPG 2.2.23 gadziriso ine yakakosha vulnerability kugadzirisa

rakabudiswa toolkit release GnuPG 2.2.23 (GNU Privacy Guard), inoenderana neOpenPGP zviyero (RFC-4880) uye S/MIME, uye inopa zvishandiso zvekunyorera data, kushanda nemasiginecha emagetsi, kiyi manejimendi uye kuwana kune veruzhinji zvitoro. Iyo vhezheni itsva inogadzirisa njodzi yakakosha (CVE-2020-25125)

Kupinza kiyi ine rondedzero yakakura yakagadziridzwa yeAEAD algorithms inogona kutungamira mukufashukira uye kuparara kana maitiro asina kutsanangurwa. Zvinocherechedzwa kuti kugadzira kushandiswa kunotungamirira kwete kungoputsika ibasa rakaoma, asi mukana wakadaro haugoni kubviswa. Dambudziko guru mukugadzira kushandiswa kunokonzerwa nekuti munhu anorwisa anogona kungodzora yega yega yechipiri byte yekutevedzana, uye yekutanga byte inogara ichitora kukosha 0x04. Masevhisi ekugovera masisitimu ane digital kiyi verification akachengeteka nekuti anoshandisa rondedzero yakafanotaurwa yemakiyi.

Source: opennet.ru

Voeg