Exim 4.92.3 yakaburitswa nekubviswa kwechina chekusagadzikana kwakakomba mugore

rakabudiswa mail server yakakosha kuburitswa Exim 4.92.3 nekubviswa kweumwe kukanganiswa kwakanyanya (CVE-2019-16928), zvinogona kukubvumidza kuti utore kodhi yako uri kure paserver nekupfuura tambo yakanyatso kurongwa mumurairo weEHLO. Kusagadzikana kunoonekwa padanho mushure mekunge ropafadzo dzagadziridzwa uye inogumira pakuita kodhi nekodzero dzemushandisi asina rusaruro, pasi payo mushandisi wemeseji anouya anourayiwa.

Dambudziko rinoonekwa chete mubazi reExim 4.92 (4.92.0, 4.92.1 uye 4.92.2) uye haripindire nekusagadzikana kwakagadziriswa kutanga kwemwedzi. CVE-2019-15846. Kusagadzikana kunokonzerwa nekufashukira kwebhafa mune chimwe chinhu string_vformat(), inotsanangurwa mufaira retambo.c. Zvakaratidzwa exploit inokubvumira kukonzera kuparara nekupfuura tambo yakareba (makirobytes akawanda) mumurairo weEHLO, asi kusagadzikana kunogona kushandiswa kuburikidza nemimwe mirairo, uye inogonawo kushandiswa kuronga kushandiswa kwekodhi.

Iko hakuna maworkaround ekuvharira kusagadzikana, saka vese vashandisi vanokurudzirwa kuti nekuchimbidza kuisa iyo update, shandisa. chigamba kana kuti ita chokwadi chekushandisa mapakeji anopihwa nekugovera ane zvigadziriso zvekusagadzikana kwazvino. Hotfix yakaburitswa Ubuntu (inobata chete bazi 19.04), Arch Linux, FreeBSD, Debian (inobata chete Debian 10 Buster) uye Fedora. RHEL neCentOS haina kukanganiswa nedambudziko, sezvo Exim isingabatanidzwe mune yavo yakajairwa pasuru repository (mu. EPEL7 update for now asipo) MuSUSE/openSUSE kusazvibata hakuratidzike nekuda kwekushandiswa kwebazi reExim 4.88.

Source: opennet.ru

Voeg