Kusagadzikana katatu kwakagadziriswa muFreeBSD

FreeBSD inogadzirisa kusakwana kutatu kunogona kubvumira kodhi kuuraya kana uchishandisa libfetch, IPsec packet retransmission, kana kuwana kernel data. Matambudziko anogadziriswa mukuvandudza 12.1-RELEASE-p2, 12.0-RELEASE-p13 uye 11.3-RELEASE-p6.

  • CVE-2020-7450 - buffer inofashukira muraibhurari ye libfetch, inoshandiswa kurodha mafaera mukuraira kwekutora, iyo pkg package maneja uye zvimwe zvinoshandiswa. Kusagadzikana kunogona kutungamira mukutevedzwa kwekodhi paunenge uchigadzira URL yakanyatsogadzirwa. Kurwiswa kunogona kuitwa kana uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchirwisa, iyo, kuburikidza neHTTP redirect, inokwanisa kutanga kugadziridzwa kweiyo yakaipa URL;
  • CVE-2019-15875 - kusadzikama mumeshini yekugadzira core process dumps. Nekuda kwechikanganiso, anosvika makumi maviri mabhayiti edata kubva kukernel stack akarekodhwa mumarasi epakati, ayo anogona kunge aine ruzivo rwakavanzika rwakagadziriswa nekernel. Sechishandiso chekudzivirira, unogona kudzima chizvarwa chepakati mafaera kuburikidza ne sysctl kern.coredump=20;
  • CVE-2019-5613 - bug mune kodhi yekuvharira data kutumirazve muIPsec yakaita kuti zvikwanise kutumira zvekare mapaketi akatorwa. Zvichienderana neprotocol yepamusoro-soro inotapurirwa pamusoro peIPsec, dambudziko rakaonekwa rinobvumira, semuenzaniso, mirairo yakambotumirwa kuti irege kugumburwa.

Source: opennet.ru

Voeg