Lintlafatso tsa Java SE, MySQL, VirtualBox le lihlahisoa tse ling tsa Oracle tse nang le bofokoli tse tsitsitseng

Khampani ea Oracle e phatlalalitsoeng tokollo e reriloeng ea lintlafatso ho lihlahisoa tsa eona (Critical Patch Update), e reretsoeng ho felisa mathata a bohlokoa le bofokoli. Ka ntlafatso ea January, kakaretso ea 397 bofokoli.

Litaba Java SE 14.0.1, 11.0.7 le 8u251 felisitsoe 15 mathata a tšireletso. Bofokoli bohle bo ka sebelisoa ka thoko ntle le netefatso. Boemo bo phahameng ka ho fetesisa ke 8.3, bo abetsoeng mathata lilaeboraring (CVE-2020-2803, CVE-2020-2805). Lifokotsi tse peli (ho libxslt le JSSE) li na le maemo a thata a 8.1 le 7.5.

Ntle le litaba tsa Java SE, bofokoli bo phatlalalitsoe lihlahisoa tse ling tsa Oracle, ho kenyelletsa:

  • 35 bofokoli ho seva sa MySQL le
    2 ts'ebetsong ea moreki oa MySQL (C API). Boemo bo phahameng ka ho fetesisa ba 9.8 bo abetsoe ho ba tlokotsing CVE-2019-5482, e hlahang ha e kopanngoa le tšehetso ea cURL. Litaba li lokisitsoe litokollong MySQL Community Server 8.0.20, 5.7.30 le 5.6.49.

  • 19 bofokoli, eo mathata a 7 a nang le boemo bo tebileng ba kotsi (CVSS e kholo ho feta 8). Sena se kenyeletsa ho lokisa bofokoli bo sebelisoang litlhaselong tse bontšitsoeng tlhōlisanong Pwn2Own 2020 / Metsoalle le ho lumella, ka ho qhekella ka lehlakoreng la tsamaiso ea baeti, ho fumana mokhoa oa ho amohela baeti le ho phethahatsa khoutu ka litokelo tsa hypervisor. Bofokoli bo lokisoa lintlafatsong VirtualBox 6.1.6, 6.0.20 le 5.2.40.
  • 6 bofokoli ho Solaris. Boemo ba kotsi bo kaholimo ho 8.8 - bo sebetsoa sebakeng sa heno bothata Sebakeng se Tloaelehileng sa Desktop, se lumellang mosebelisi ea se nang monyetla ho etsa khoutu ka litokelo tsa metso. Litaba li boetse li lokisitsoe mojuleng oa kernel ho kenya tšebetsong protocol ea SMB, ho Whodo, le ho taelo ea svcbundle SMF. Litaba li lokisitsoe ntlafatsong ea maobane Solaris 11.4 SRU 20.

Source: opennet.ru

Eketsa ka tlhaloso