Kusagadzikana muchrony

Π’ chrony, kushandiswa kweNTP protocol inoshandiswa kuwiriranisa nguva chaiyo mukugoverwa kwakasiyana kweLinux, kuzivikanwa kusagadzikana (CVE-2020-14367), zvichikubvumidza kuti unyore chero faira pane sisitimu nekuwana kune yemuno isina njodzi mushandisi chrony. Kusagadzikana kunogona chete kushandiswa kuburikidza nemushandisi chrony, iyo inoderedza njodzi yayo. Nekudaro, iyo nyaya inokanganisa mwero wekuzviparadzanisa nevamwe muchrony uye inogona kushandiswa kana kumwe kusagadzikana kwakaonekwa mukodhi yakaitwa mushure mekunge maropafadzo aitwa patsva.

Kusagadzikana kunokonzerwa nekugadzirwa kusina kuchengetedzeka kwepid faira, iyo yakagadzirwa padanho apo chrony yanga isati yagadzirisa ropafadzo uye yaimhanya semidzi. Muchiitiko ichi, iyo / run/chrony dhairekitori, umo iyo pid faira yakanyorwa, yakagadzirwa iine kodzero 0750 kuburikidza ne systemd-tmpfiles kana pakatangwa chronyd mukubatana nemushandisi neboka "chrony". Saka, kana iwe uchikwanisa kuwana mushandisi chrony, zvinokwanisika kutsiva pid faira /run/chrony/chronyd.pid ine chiratidzo chekubatanidza. Chinongedzo chinongedzo chinogona kunongedzera kune chero system faira inozonyorwa pamusoro kana chronyd yatangwa.

mudzi# systemctl mira chronyd.service
mudzi# sudo -u chrony /bin/bash

chrony$ cd /run/chrony
chrony$ ln -s /etc/shadow chronyd.pid
chrony$ kubuda

mudzi # /usr/sbin/chronyd -n
^C
# panzvimbo yezviri mukati /etc/shadow iyo chronyd process ID ichachengetwa
mudzi # katsi /etc/shadow
15287

Kunetseka kubviswa munyaya chrony 3.5.1. Zvigadziriso zvepakeji zvinogadzirisa kusagadzikana zviripo Fedora. Mukuita kugadzirira update ye RHEL, Debian ΠΈ Ubuntu.

SUSE uye openSUSE dambudziko kwete kubatwa, sezvo chinongedzo chechiratidzo chechrony chakagadzirwa zvakananga mu / run dhairekitori, pasina kushandisa mamwe madhairekitori.

Source: opennet.ru

Voeg