Kusagadzikana muGit yeCygwin iyo inokutendera iwe kuronga kodhi kuuraya

Kusagadzikana kwakanyanya kwaonekwa muGit (CVE-2021-29468), iyo inongoonekwa kana ichivakira nharaunda yeCygwin (raibhurari yekutevedzera iyo yakakosha Linux API paWindows uye seti yeyakajairwa Linux zvirongwa zveWindows). Kusagadzikana kunobvumira anorwisa kodhi kuti iitwe kana uchidzora data ("git checkout") kubva panzvimbo inodzorwa neanorwisa. Dambudziko rakagadziriswa mugit 2.31.1-2 package yeCygwin. Muchikamu chikuru cheGit, dambudziko harisati ragadziriswa (hazvigoneki kuti mumwe munhu ari kuvaka git yeCygwin nemaoko avo, pane kushandisa purogiramu yakagadzirwa).

Kusagadzikana kunokonzerwa neCygwin kugadzirisa kwezvakatipoteredza seUnix-yakafanana system pane Windows, izvo zvinoguma nekusarambidzwa kushandiswa kweiyo '\' hunhu munzira, nepo muCygwin, senge muWindows, hunhu uhu hunogona inoshandiswa kuparadzanisa madhairekitori. Nekuda kweizvozvo, nekugadzira yakanyatso kugadziridzwa repository ine ekufananidzira links uye mafaera ane backslash hunhu, zvinokwanisika kupenengura mafaera kana uchirodha iyi repository muCygwin (kusagadzikana kwakafanana kwakagadziriswa muGit yeWindows muna 2019). Nekuwana kugona kunyora mafaera, anorwisa anogona kupfuudza hook mafoni mugit uye kukonzera kupokana kodhi kuurayiwa pane system.

Source: opennet.ru

Voeg