Gadzirisa Ruby 2.6.5, 2.5.7 uye 2.4.8 ine kusasimba kwakagadziriswa

Kugadzirisa kuburitswa kweRuby programming mutauro kwakagadzirwa 2.6.5, 2.5.7 ΠΈ 2.4.8, iyo yakagadzirisa zvikanganiso zvina. Kusagadzikana kwakanyanya kwengozi (CVE-2019-16255) muraibhurari yakajairwa Shell (lib/shell.rb), iyo Kunoitawo kuita code substitution. Kana data rakagamuchirwa kubva kumushandisi rikagadziriswa mukupokana kwekutanga kweShell#[] kana Shell#test nzira dzinoshandiswa kutarisa kuvepo kwefaira, anorwisa anogona kuita kuti nzira yeRuby idaidzwe.

Mamwe matambudziko:

  • CVE-2019-16254 -kuratidzwa kune yakavakirwa-mukati http server WEBrick HTTP mhinduro yekuparadzanisa kurwisa (kana chirongwa chikaisa data isina kusimbiswa muHTTP mhinduro musoro, ipapo musoro unogona kupatsanurwa nekuisa mutsara mutsva);
  • CVE-2019-15845 Kutsiviwa kwemavara asina maturo (\0) kune ayo akatariswa kuburikidza ne β€œFile.fnmatch” uye β€œFile.fnmatch?” nzira. nzira dzefaira dzinogona kushandiswa kukonzeresa nhema cheki;
  • CVE-2019-16201 -kuramba sevhisi muDiges yekusimbisa module yeWEBrick.

Source: opennet.ru

Voeg