Kugadziridzwa kweyemahara antivirus package ClamAV 0.102.4

Yakagadzirwa kuburitswa kwemahara antivirus package Clam AV 0.102.4, umo zvitatu zvinobviswa vulnerabilities:

  • CVE-2020-3350 - Kunoitawo asina rusarura anorwisa munharaunda anogona kuronga kudzima kana kufamba kwemafaira asina kurongeka pane system; semuenzaniso, unogona kudzima /etc/passwd usina mvumo inodiwa. Kusagadzikana kunokonzerwa nechimiro chemujaho chinoitika kana uchitarisa mafaera ane hutsinye uye unobvumira mushandisi ane goko rekupinda pane system kutsiva dhairekitori rinotariswa kuti ritariswe nechiratidzo chinonongedza kune imwe nzira.

    Semuenzaniso, munhu anorwisa anogona kugadzira dhairekitori "/ imba / mushandisi / shandisa /" uye kurodha faira ine test virus siginicha mairi, ichipa iyi faira "passwd". Mushure mekushandisa chirongwa chekuongorora hutachiona, asi usati wadzima faira ine dambudziko, unogona kutsiva iyo "exploit" dhairekitori nechiratidzo chinonongedza kune "/etc" dhairekitori, izvo zvichaita kuti antivirus ibvise /etc/passwd faira. Kusagadzikana kunongoonekwa kana uchishandisa clamscan, clamdscan uye clamonacc ine "--move" kana "--bvisa" sarudzo.

  • CVE-2020-3327, CVE-2020-3481 injodzi mumamodule ekuisa zvinyorwa muARJ uye EGG mafomati, zvichibvumira kurambwa kwesevhisi kuburikidza nekuendeswa kwezvakagadzirwa zvakachengetwa zvakachengetwa, kugadziridzwa kwacho kunozotungamira mukupunzika kwemaitiro ekuongorora. .

Source: opennet.ru

Voeg