Kubira iyo LineageOS zvivakwa kuburikidza nenjodzi muSaltStack

Mobile platform Developers LineageOS, iyo yakatsiva CyanogenMod, yambiro nezve kuona mitsva yekubira kweiyo projekiti zvivakwa. Zvinocherechedzwa kuti na6 am (MSK) muna Chivabvu 3, murwi akakwanisa kuwana mukana weiyo main server ye centralized configuration management system. SaltStack kuburikidza nekushandiswa kwekusagadzikana kusingaverengeki. Chiitiko ichi chiri kuongororwa parizvino uye ruzivo harwusati rwawanikwa.

Yakataurwa chete kuti kurwiswa hakuna kukanganisa makiyi ekugadzira masiginecha edhijitari, hurongwa hwegungano uye kodhi yepuratifomu - makiyi. dzaivepo pane mauto akaparadzana zvachose kubva kune mainfrastructure inotungamirirwa kuburikidza neSaltStack, uye kuvaka kwakamiswa nekuda kwezvikonzero zvehunyanzvi musi wa30 Kubvumbi. Tichitarisa neruzivo rwuri papeji status.lineageos.org Vagadziri vakatodzoreredza sevha neGerrit kodhi yekuongorora system, webhusaiti uye wiki. Sevha ine maassemblies (builds.lineageos.org), iyo portal yekurodha mafaera (download.lineageos.org), maseva etsamba uye sisitimu yekubatanidza kutumira kune magirazi inoramba yakaremara.

Kurwiswa kwacho kwakagoneka nekuda kwekuti network port (4506) yekuwana SaltStack akanga asiri yakavharirwa zvikumbiro zvekunze nefirewall - murwi aifanira kumirira kusagadzikana kwakanyanya muSaltStack kuti aoneke uye ashandise iyo vatariri vasati vaisa chigadziriso chine gadziriso. Vese vashandisi veSaltStack vanorayirwa kuti vakurumidze kugadzirisa masisitimu avo uye kutarisa zviratidzo zvekubira.

Sezviri pachena, kurwiswa kuburikidza neSaltStack hakuna kungogumira pakubira LineageOS uye kwakapararira - mukati mezuva, vashandisi vakasiyana-siyana vakanga vasina nguva yekuvandudza SaltStack. kupemberera kuzivisa kukanganiswa kwezvivakwa zvavo nekuiswa kwekodhi yemugodhi kana backdoors pamaseva. Kusanganisira yakashuma nezve kubira kwakafanana kweiyo content management system infrastructure chipoko, iyo yakabata Ghost(Pro) mawebhusaiti uye kubhadhara (zvinonzi nhamba dzekadhi rechikwereti hadzina kukanganiswa, asi password hashes yevashandisi veMweya inogona kuwira mumaoko evanorwisa).

Kubvumbi 29 yaive rakabudiswa SaltStack papuratifomu inogadziridza 3000.2 ΠΈ 2019.2.4, mavakabviswa kusakwana kuviri (ruzivo nezve kusasimba kwakabudiswa muna Kubvumbi 30), iyo inopihwa danho repamusoro rengozi, sezvo vasina humbowo. bvumira kure kodhi kuuraya zvese pane yekudzora host (munyu-tenzi) uye pamaseva ese anotungamirwa kuburikidza nawo.

  • Kutanga kusagadzikana (CVE-2020-11651) inokonzerwa nekushaikwa kwekutarisa kwakakodzera pakudaidza nzira dzeClearFuncs kirasi mune yemunyu-master process. Kusagadzikana kunobvumira mushandisi ari kure kuwana dzimwe nzira pasina humbowo. Kusanganisira nenzira dzinonetsa, munhu anorwisa anogona kuwana chiratidzo chekuwana nemidzi kodzero kune master server uye omhanyisa chero mirairo pane anopihwa anopihwa iyo daemon iri kushanda. munyu-minion. Chigamba chinobvisa kusagadzikana uku chaive yakabudiswa Mazuva makumi maviri apfuura, asi mushure mekuishandisa ivo vakabuda regressive change, zvichiita kuti zvikundikane uye kuvhiringidzwa kwekuenzanisa kwefaira.
  • Kusagadzikana kwechipiri (CVE-2020-11652) inobvumira, kuburikidza nekunyengedza nekirasi yeClearFuncs, kuwana nzira kuburikidza nekupfuura neimwe nzira yakarongwa nzira, iyo inogona kushandiswa kuwana zvizere kune zvinyorwa zvisingabvumirwi muFS ye master server ine kodzero dzemidzi, asi inoda kuwanikwa kwechokwadi ( kuwana kwakadaro kunogona kuwanikwa uchishandisa yekutanga kusagadzikana uye kushandisa yechipiri kusagadzikana kukanganisa zvachose hurongwa hwese).

Source: opennet.ru

Voeg