Nuglaanta halista ah ee Exim taas oo u oggolaanaysa fulinta kood fog oo leh mudnaanta xididka

Soosaarayaasha boostada ee Exim ogaysiis isticmaalayaasha ku saabsan aqoonsiga dayacanka daran (CVE-2019-15846), Oggolaanshaha weeraryahan maxalli ah ama fog-fog inuu ku fuliyo koodka server-ka ee leh xuquuqda xididka. Weli ma jiraan faa'iidooyin si guud oo loo heli karo dhibaatadan, laakiin cilmi-baarayaasha aqoonsaday baylahda ayaa diyaariyey nooc horudhac ah oo ka faa'iidaysiga.

Siideynta isku dubaridka ah ee cusbooneysiinta xirmada iyo daabacaadda siideynta sixitaanka ayaa loo qorsheeyay Sebtembar 6 (13:00 MSK) Exim 4.92.2. Ilaa markaas, macluumaad faahfaahsan oo ku saabsan dhibaatada looma hoggaansamo muujin. Dhammaan isticmaalayaasha Exim waa inay isu diyaariyaan rakibaadda degdegga ah ee cusbooneysiinta aan la qorsheyn.

Sannadkan waa kii saddexaad dhaliil nuglaanta ee Exim. Sida laga soo xigtay Sebtembar otomaatig ah ra'yi ururin In ka badan laba milyan oo adeegayaal boosto ah, saamiga Exim waa 57.13% (sanad ka hor 56.99%), Postfix waxa loo isticmaalaa 34.7% (34.11%) ee adeegayaasha boostada, Sendmail - 3.94% (4.24%), Microsoft Exchange - 0.53% (0.68%).

Source: opennet.ru

Add a comment