Kotsi ea unrar e lumellang ho ngola lifaele ha u ntse u notlolla polokelong ea litaba

Ho na le ts'oaetso e bonts'itsoeng ts'ebelisong ea unrar (CVE-2022-30333), e lumellang, ha ho notlolloa polokelong ea khale e etselitsoeng ka ho khetheha, ho hlakola lifaele kantle ho bukana ea hajoale, ho ea kamoo litokelo tsa mosebelisi li lumellang. Taba ena e lokisitsoe ho RAR 6.12 le unrar 6.1.7 tokollo. Ho ba kotsing ho iponahatsa ka mefuta ea Linux, FreeBSD le macOS, empa ha e ame Android le Windows builds.

Bothata bo bakoa ke ho hloka tlhahlobo e nepahetseng ea tatellano ea "/.." litseleng tsa lifaele tse boletsoeng polokelong ea polokelo, e u lumellang hore u fetele ka nģ'ane ho meeli ea lenane la motheo ha u phutholla. Ka mohlala, ka ho beha "../.ssh/authorized_keys" polokelong, mohlaseli a ka leka ho hlakola faele ea mosebelisi "~/.ssh/authorized_keys" nakong eo a e phuthollang.

Source: opennet.ru

Eketsa ka tlhaloso