Samba 4.10.8 le 4.9.13 ntlafatso e nang le ts'oaetso ea ts'oaetso

Lokisitsoe litokollo tsa khalemelo tsa sephutheloana sa Samba 4.10.8 le 4.9.13, se felisitsoeng bofokodi (CVE-2019-10197), ho lumella mosebelisi ho fihlella bukana ea motso moo karohano ea marang-rang ea Samba e leng teng. Bothata bo etsahala ha khetho ea 'wide links = e' e hlalositsoe litlhophisong hammoho le 'unix extensions = che' kapa 'lumella lihokelo tse sa sireletsehang tse pharaletseng = e'. Ho fihlella lifaele ka ntle ho karohano ea hona joale e arolelanoang e lekanyelitsoe ke litokelo tsa ho fihlella tsa mosebedisi, ke hore. mohlaseli a ka bala le ho ngola lifaele ho latela uid/gid ea bona.

Bothata bo bakoa ke taba ea hore ka mor'a kopo ea pele ea motso oa karohano e arolelanoang, phoso ea ho fihlella e khutlisetsoa ho mofani, empa smbd e boloka mokhoa oa ho fumana boitsebiso 'me ha e hlakise cache ha ho e-na le bothata ba ho fihlella. Ka hona, ka mor'a ho romela kopo ea SMB khafetsa, e sebetsoa ka katleho ho ipapisitse le keno ea cache ntle le ho hlahlojoa khafetsa.

Source: opennet.ru

Eketsa ka tlhaloso