Memcached 1.6.2 gadziriso ine njodzi kugadzirisa

Yakabudiswa pa kuvandudza iyo data caching system mu RAM Memcached 1.6.2, umo inobviswa vulnerability, iyo inokutendera iwe kuti utange kuparara kwekufamba kwebasa nekutumira chikumbiro chakagadzirwa. Kusagadzikana kunoratidzika kutanga kubva pakuburitswa 1.6.0. Senzira yekuchengetedza, unogona kudzima iyo binary protocol kune zvekunze zvikumbiro nekumhanya ne "-B ascii" sarudzo.

Dambudziko rinokonzerwa nebug in code kupatsanurwa kwebhinari protocol musoro, wakabatana nesarudzo isiriyo yehukuru hwe data yakakopwa kune buffer pakudaidza memcpy basa (saizi inotarwa zvichienderana neparameter inotsanangurwa mumusoro wekukumbira). Nekugadzirisa kukosha kweparameter mumusoro webhinari protocol, munhu anorwisa ane simba rekubatanidza kuMemcached network port anogona kutanga buffer mafashama, zvichiita kuti kuparara kwekushanda kwevashandi.

Source: opennet.ru

Voeg