Saddex baylahdu waxay go'an tahay FreeBSD

FreeBSD waxay wax ka qabataa saddex baylah oo u oggolaan kara fulinta kood marka la isticmaalayo libfetch, IPsec baakadda dib u gudbinta, ama helitaanka xogta kernelka. Dhibaatooyinka waxaa lagu hagaajiyaa cusboonaysiinta 12.1-SIIDAYN-p2, 12.0-SIIDAYN-p13 iyo 11.3-SIIDAYN-p6.

  • CVE-2020-7450 - bakhaar buux dhaafiyay maktabadda libfetch, oo loo isticmaalay in lagu raro faylalka amarka keensiga, maareeyaha xirmada pkg iyo adeegyada kale. Nuglaanta waxay u horseedi kartaa fulinta kood marka la farsameynayo URL si gaar ah loo sameeyay. Weerarka waxa la qaadi karaa marka la gelayo goobta uu gacanta ku hayo weeraryahanku, kaas oo, iyada oo loo marayo HTTP redirect, uu awoodo inuu bilaabo habaynta URL xaasidnimo ah;
  • CVE-2019-15875 - nuglaanshaha habka abuurista qashinka hab-socodka asaasiga ah. Khalad dartiis, ilaa 20 bytes oo xog ah oo laga helay kaydka kernel-ka ayaa lagu duubay qashinka xudunta u ah, kuwaas oo laga yaabo inay ku jiraan macluumaadka sirta ah ee lagu farsameeyay kernel-ku. Ka-hortagga ilaalinta, waxaad joojin kartaa jiilka faylalka asaasiga ah adigoo isticmaalaya sysctl kern.coredump=0;
  • CVE-2019-5613 - bug ku jira koodka xannibaadda xogta dib-u-diridda IPsec ayaa suurtogal ka dhigtay in dib loo diro baakado hore loo qabtay. Iyada oo ku xidhan nidaamka heerka sare ah ee lagu gudbiyo IPsec, dhibaatada la aqoonsaday ayaa u oggolaanaysa, tusaale ahaan, amarradii hore loo gudbiyay in la diido.

Source: opennet.ru

Add a comment