Kusagadzikana muTimeshift iyo inokutendera iwe kusimudza ropafadzo dzako muhurongwa

Mukushandisa Timeshift kuzivikanwa vulnerability (CVE-2020-10174), zvichibvumira mushandisi wepanzvimbo kuti aite kodhi semudzi. Timeshift igadziriro yekuchengetedza inoshandisa rsync ine hardlinks kana Btrfs snapshots kuti ipe mashandiro akafanana neSystem Restore paWindows uye Time Machine pa macOS. Chirongwa ichi chinosanganisirwa mumatura ekugovera kwakawanda uye chinoshandiswa nekukasira muPCLinuxOS uye Linux Mint. Kusagadzikana kwakagadziriswa mukuburitswa Timeshift 20.03.

Dambudziko rinokonzerwa nekubata zvisirizvo kweiyo /tmp yeruzhinji dhairekitori. Paunenge uchigadzira backup, chirongwa chinogadzira dhairekitori /tmp/timeshift, umo subdirectory ine zita risingaite inogadzirwa ine shell script ine mirairo, yakatangwa nemidzi kodzero. Iyo subdirectory ine script ine zita risingafungidzike, asi /tmp/timeshift pachayo inofanotaurwa uye haina kuongororwa kuti itsive kana kusikwa kwechiratidzo chinongedzo panzvimbo. Anorwisa anogona kugadzira dhairekitori /tmp/timeshift pachinzvimbo chake, wozoteedzera kutaridzika kweiyo subdirectory uye kutsiva iyi subdirectory uye faira iri mairi. Panguva yekushanda, Timeshift ichaita, ine kodzero dzemidzi, kwete script yakagadzirwa nepurogiramu, asi faira yakatsiviwa neanorwisa.

Source: opennet.ru

Voeg