Bofokoli ho mokhanni oa NTFS-3G o lumellang ho fihlella ha metso ho sistimi

Ho lokolloa ha morero oa NTFS-3G 2022.5.17, o hlahisang mokhanni le sete ea lisebelisoa bakeng sa ho sebetsa le tsamaiso ea faele ea NTFS sebakeng sa mosebedisi, e felisitse bofokoli ba 8 bo u lumellang ho phahamisa litokelo tsa hau tsamaisong. Mathata a bakoa ke khaello ea licheke tse nepahetseng ha o sebetsana le likhetho tsa mela ea litaelo le ha o sebetsa le metadata ho likarolo tsa NTFS.

  • CVE-2022-30783, CVE-2022-30785, CVE-2022-30787 - bofokoli ho mokhanni oa NTFS-3G o kopantsoe le laebrari ea libfuse e hahiloeng ka hare (libfuse-lite) kapa le laebrari ea tsamaiso ea libfuse2. Motho ea hlaselang a ka sebelisa khoutu e sa lumellaneng le litokelo tsa metso ka ho qhekella likhetho tsa mola oa taelo haeba a khona ho fumana faele e sebetsang ea ntfs-3g e fanoeng le folakha ea motso oa suid. Mohlala o sebetsang oa ts'ebetso o ile oa bontšoa bakeng sa bofokoli.
  • CVE-2021-46790, CVE-2022-30784, CVE-2022-30786, CVE-2022-30788, CVE-2022-30789 - bofokoli ba khoutu ea metadata ea ho arola likarolo tsa NTFS, tse lebisang ho khaello ea matla. licheke . Tlhaselo e ka etsoa ha ho sebetsa karohano ea NTFS-3G e lokiselitsoeng ke mohlaseli. Ka mohlala, ha mosebedisi a kenya koloi e lokiselitsoeng ke mohlaseli, kapa ha mohlaseli a e-na le monyetla oa ho kena tsamaisong. Haeba sistimi e lokiselitsoe ho kenya likarolo tsa NTFS ka bo eona ho li-drive tsa kantle, sohle se hlokahalang ho hlasela ke ho hokela Flash Flash ka karohano e etselitsoeng ka ho khetheha komporong. Mesebetsi e sebetsang bakeng sa bofokoli bona ha e e-so bontšoe.

    Source: opennet.ru

Eketsa ka tlhaloso