Samba 4.10.8 uye 4.9.13 inogadziridza ine vulnerability kugadzirisa

Prepared kugadzirisa kuburitswa kweSamba package 4.10.8 uye 4.9.13, iyo yakabvisa vulnerability (CVE-2019-10197), ichibvumira mushandisi kuti awane iyo midzi dhairekitori panowanikwa Samba network partition. Dambudziko rinoitika kana iyo 'wide links = hongu' sarudzo inotsanangurwa muzvirongwa pamwe chete ne 'unix extensions = kwete' kana 'kubvumira kusachengeteka kwakafara links = hongu'. Kuwana mafaera kunze kwekugovaniswa kwazvino kunoganhurwa nekodzero yekuwana yemushandisi, i.e. anorwisa anogona kuverenga nekunyora mafaera zvinoenderana neuid/gid yavo.

Dambudziko rinokonzerwa nenyaya yekuti mushure mekukumbira kwekutanga kwemudzi wechikamu chakagovaniswa, kukanganisa kwekuwana kunodzoserwa kune mutengi, asi smbd inochengetedza dhairekitori yekuwana uye haina kujekesa cache pakaitika dambudziko rekuwana. Saizvozvo, mushure mekutumira chikumbiro cheSMB chakadzokororwa, chinogadziriswa zvichibva pane cache yekupinda pasina kudzokororwa mvumo yekutarisa.

Source: opennet.ru

Voeg