Kusagadzikana muFreeBSD libc uye IPv6 stack

FreeBSD inogadzirisa akati wandei kusagadzikana izvo zvinogona kubvumira mushandisi wemuno kusimudza maropafadzo avo pane system:

  • CVE-2020-7458 -kusagadzikana mu posix_spawnp mechanism yakapihwa mu libc yekugadzira maitirwo, inoshandisirwa nekutsanangudza kukosha kwakanyanya muPATH nharaunda inoshanduka. Kusagadzikana kunogona kuita kuti data inyorwe kunze kwenzvimbo yendangariro yakagoverwa uye inogona kubvumira zviri mukati mezvivhariso zviri pedyo kuti zvinyorwe neukoshi hunodzorwa.
  • CVE-2020-7457 -Kusagadzikana muIPv6 stack iyo inobvumira mushandisi wepano kuronga kuitwa kwekodhi yake padanho re kernel kuburikidza nekunyengedza achishandisa IPV6_2292PKTOPTIONS sarudzo yetiweki socket.
  • Yakabviswa kusakwana kuviri (CVE-2020-12662, CVE-2020-12663) pane inosanganisirwa DNS server vasina kusungwa, zvichikubvumidza kuti ukonzere kure nekuramba kwesevhisi kana uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge, shandisa sevha yeDNS sekushandisa traffic amplifier pakushandisa DDoS kurwisa.

Mukuwedzera, nyaya nhatu dzisiri dzekuchengetedza (errata) dzinogona kuita kuti kernel iparare paunenge uchishandisa mutyairi zvakagadziriswa. mps (kana uchiita iyo sas2ircu command), subsystems LinuxKPI (apo X11 inotungamirwa) uye hypervisor bhve (kana uchiendesa PCI zvishandiso).

Source: opennet.ru

Voeg