FreeBSD inogadzirisa kure kure kushandiswa kwekusagadzikana mu ipfw

Mune ipfw packet filter kubviswa kusakwana kuviri muTCP sarudzo parsing kodhi, yakakonzerwa neiyo isiriyo data verification mumagadzirirwo etiweki mapaketi. Kusagadzikana kwekutanga (CVE-2019-5614) kana kugadzirisa TCP mapaketi neimwe nzira kunogona kutungamira kusvika kune ndangariro kunze kweiyo yakagoverwa mbuf buffer, uye yechipiri (CVE-2019-15874) inogona kutungamira mukuwana nzvimbo dzakatosunungurwa dzendangariro. shandisa-mushure-yemahara).

Ongororo yekukodzera kwenyaya dzakaonekwa dzekushandiswa kunokwanisa kukonzeresa kuurayiwa kweanorwisa kodhi haisati yaitwa, asi zvinogoneka kuti kusasimba kungangogumira pakukonzera kuparara kwekernel. Matambudziko akagadziriswa muFreeBSD 11.3-RELEASE-p8 uye 12.1-RELEASE-p4 zvigadziriso (zvigadziriso zvakaitwa kumapazi akatsiga kumashure muna Zvita gore rapfuura, asi chokwadi chekuti zvigadziriso izvi zvine chekuita nekubvisa kusagadzikana kwakazozivikanwa izvozvi) .

Source: opennet.ru

Voeg