Cusbooneysii Ruby 2.6.5, 2.5.7 iyo 2.4.8 oo leh baylahdu go'an tahay

Siideynta saxda ah ee luqadda barnaamijka Ruby ayaa la sameeyay 2.6.5, 2.5.7 ΠΈ 2.4.8, kaas oo hagaajiyay afar baylahda. Nuglaanta ugu khatarta badan (CVE-2019-16255) ee maktabadda caadiga ah Shell (lib/shell.rb), kaas Waxa ay u ogolaataa samee beddelka koodka. Haddii xogta laga helo isticmaalaha lagu farsameeyo doodda ugu horreysa ee Shell#[] ama hababka tijaabada Shell# ee loo isticmaalo in lagu hubiyo joogitaanka faylka, weeraryahanku wuxuu sababi karaa habka Ruby ee aan loo baahnayn in loogu yeero.

Dhibaatooyinka kale:

  • CVE-2019-16254 - la kulanka server-ka ku dhex jira ee http WEBrick Weerar kala qaybsanaanta jawaabta HTTP (haddii barnaamijku geliyo xog aan la hubin cinwaanka jawaabta HTTP, ka dib madaxa waa la kala qaybin karaa iyadoo la geliyo xarfo cusub);
  • CVE-2019-15845 ku beddelka jilaha null (\0) ee lagu hubiyay hababka "File.fnmatch" iyo "File.fnmatch?" Wadooyinka faylka waxaa loo isticmaali karaa in si been abuur ah loo kiciyo jeegga;
  • CVE-2019-16201 - diidmada adeegga ee moduleka xaqiijinta Diges ee WEBrick.

Source: opennet.ru

Add a comment