Kusagadzikana muSQLite DBMS

MUSQLite DBMS kuzivikanwa vulnerability (CVE-2019-5018), iyo inokutendera kuti uite kodhi yako pane system kana zvichikwanisika kuita mubvunzo weSQL wakagadzirirwa neanorwisa. Dambudziko rinokonzerwa nekukanganisa mukushandiswa kwemabasa ehwindo uye rinoratidzika kutanga kubva kubazi SQLite 3.26. Kusagadzikana kubviswa mumagazini yaApril SQLite 3.28 pasina kutaurwa kwakajeka kwekugadzirisa nyaya dzekuchengetedza.

Yakanyatso gadzirwa SQL SELECT query inogona kuunza kushandiswa-mushure-kwemahara ndangariro yekuwana, iyo inogona kushandiswa kugadzira kubiridzira kuita kodhi mumamiriro ekushandisa uchishandisa SQLite. Kusagadzikana kunogona kushandiswa kana application ichibvumira SQL inovaka ichibva kunze kuti ipfuure muSQLite.

Semuenzaniso, kurwiswa kunogona kuitwa paChrome browser uye maapplication achishandisa injini yeChromium, sezvo WebSQL API inoitwa pamusoro peSQLite uye inowana iyi DBMS kugadzirisa mibvunzo yeSQL kubva kumawebhusaiti. Kuti urwise, zvakakwana kugadzira peji ine yakaipa JavaScript kodhi uye kumanikidza mushandisi kuivhura mubrowser zvinoenderana neChromium injini.

Source: opennet.ru

Voeg