Kadib 6 sano oo shaqo la'aan ah fetchmail 6.4.0 ayaa diyaar ah

In ka badan 6 sano laga soo bilaabo cusboonaysiintii ugu dambeysay arkay iftiinkii sii deynta barnaamijka gudbinta iyo dib u habeynta iimaylka fetchmail 6.4.0, kaas oo kuu ogolaanaya inaad soo ururiso boostada adoo isticmaalaya borotokool iyo kordhin POP2, POP3, RPOP, APOP, KPOP, IMAP, ETRN iyo ODMR, shaandheynta waraaqaha la helay, u qaybiso fariimaha hal akoon ilaa dhowr isticmaale oo u wareejiso sanduuqyada boostada maxaliga ah ama SMTP server kale (ka shaqee sidii POP/IMAP-ilaa-SMTP albaab). Xeerka mashruuca wuxuu ku qoran yahay C iyo qaybiyey shatiga ku haysta GPLv2. Fetchmail 6.3.X laantii gabi ahaanba waa la joojiyay.

Waxaa ka mid ah isbedel:

  • Taageero lagu daray TLS 1.1, 1.2 iyo 1.3 (--sslproto {tls1.1+|tls1.2+|tls1.3+}). Ku dhis OpenSSL si toos ah (ugu yaraan laanta 1.0.2 ayaa looga baahan yahay inay shaqeyso, iyo TLSv1.3 - 1.1.1). Taageerada SSLv2 waa la joojiyay. Sida caadiga ah, halkii SSLv3 iyo TLSv1.0, STLS/STARTTLS waxay ku dhawaaqaysaa TLSv1.1. Si aad u soo celiso SSLv3, waxaad u baahan tahay inaad isticmaasho OpenSSL oo leh taageerada SSLv3 bidix oo ku socodsii fetchmail leh calanka "-sslproto ssl3+".
  • Sida caadiga ah, qaabka hubinta shahaadada SSL waa la dajiyay (-sslcertck). Si aad u joojiso jeegga, waxaad hadda u baahan tahay inaad si cad u qeexdo ikhtiyaarka "--nosslcertck";
  • Taageerada isku-dubaridaha C ee aadka u da'da weyn waa la joojiyay. Dhismuhu hadda wuxuu u baahan yahay isku-dubarid taageeraya heerka 2002 SUSv3 (Single Unix Specification v3, qayb hoosaad ah POSIX.1-2001 oo leh kordhinta XSI);
  • Waxtarka UID raadinta waa la kordhiyey ("-keep UID" qaabka) marka la qaybinayo fariimaha sanduuqa boostada ee POP3;
  • Horumarin badan ayaa la sameeyay si loo taageero isku xirka sirta ah;
  • Go'an baylahnimada u horseedi karta kaydka buuxdhaafka ah ee koodhka xaqiijinta GSSAPI marka la adeegsanayo magacyada isticmaale ee ka badan 6000 xaraf.

Isku dar: la heli karo sii daayo 6.4.1 oo leh hagaajin laba dib-u-noqosho ah ( hagaajin aan dhamaystirnayn oo loogu talagalay Bug Debian 941129 waxay keentay awood la'aanta in la helo faylasha qaabeynta fetchmail xaaladaha qaarkood iyo dhibaatada _FORTIFY_SOURCE marka PATH_MAX ay ka weyn tahay ugu yaraan _POSIX_PATH_MAX).

Source: opennet.ru

Add a comment