Gadzirisa Tor 0.3.5.10, 0.4.1.9 uye 0.4.2.7 nekubvisa kusagadzikana kweDoS

Presented inogadzirisa kuburitswa kweTor toolkit (0.3.5.10, 0.4.1.9, 0.4.2.7, 0.4.3.3-alpha), inoshandiswa kuronga basa reTor network isingazivikanwe. Iwo mavhezheni matsva anogadzirisa kusakwana kuviri:

  • CVE-2020-10592 - inogona kushandiswa nechero anorwisa kuti atange kuramba sevhisi kune relay. Kurwiswa uku kunogonawo kuitwa neTor directory maseva kurwisa vatengi uye masevhisi akavanzika. Anorwisa anogona kugadzira mamiriro anotungamira kune yakawandisa mutoro paCPU, ichikanganisa yakajairika mashandiro kwemasekonzi akati wandei kana maminetsi (nekudzokorora kurwiswa, iyo DoS inogona kuwedzerwa kwenguva yakareba). Dambudziko rinoonekwa kubva pakaburitswa 0.2.1.5-alpha.
  • CVE-2020-10593 -kure kure kwakatangwa ndangariro kuvuza kunoitika kana dunhu padding rakapetwa kaviri kune imwechete ketani.

Zvinogonawo kucherechedzwa kuti in Tor Browser 9.0.6 kusagadzikana mune yekuwedzera inoramba isina kugadziriswa NoScript, iyo inokutendera kuti umhanye JavaScript kodhi mune Yakachengeteka Modhi yekudzivirira. Kune avo vanorambidza kuurayiwa kweJavaScript kwakakosha, zvinokurudzirwa kudzima kwechinguva kushandiswa kweJavaScript mubrowser mune about:config nekushandura javascript.enabled parameter in about:config.

Vakaedza kubvisa chirema mukati NoScript 11.0.17, asi sezvazvakazoitika, kugadzirisa kwakarongwa hakugadzirise zvachose dambudziko. Tichifunga nezve shanduko mune inotevera yakaburitswa kuburitswa NoScript 11.0.18, dambudziko zvakare harigadziriswe. Tor Browser inosanganisira otomatiki NoScript inogadziridza, saka kana gadziriso yavepo, inounzwa otomatiki.

Source: opennet.ru

Voeg