Kotsi ho libc le FreeBSD IPv6 stack

FreeBSD e hlophisitse mefokolo e mengata e ka lumellang mosebelisi oa lehae ho eketsa litokelo tsa bona ho sistimi:

  • CVE-2020-7458 - ho ba le tsietsi ho posix_spawnp e fanoeng ho libc bakeng sa ho theha lits'ebetso, e sebelisitsoeng hampe ka ho hlakisa boleng bo boholo haholo ho phapano ea tikoloho ea PATH. Bofokoli bo ka lebisa ho ngotseng data ka nqane ho sebaka sa memori se abetsoeng stack, mme e etsa hore ho khonehe ho hlakola litaba tsa li-buffer tse latelang ka boleng bo laoloang.
  • CVE-2020-7457 - ho ba kotsing ho IPv6 stack e lumellang mosebelisi oa lehae ho hlophisa ts'ebetso ea khoutu ea bona boemong ba kernel ka ho qhekella a sebelisa IPV6_2292PKTOPTIONS khetho bakeng sa sokete ea marang-rang.
  • E felisitsoe bofokoli tse peli (CVE-2020-12662, CVE-2020-12663) ho seva e kenyellelitsoeng ea DNS E se nang moeli, e leng se u lumellang hore u bake ho haneloa ha tšebeletso ka thōko ha u kena ho seva e laoloang ke mohlaseli kapa u sebelisa seva sa DNS e le amplifier ea sephethephethe ha u etsa litlhaselo tsa DDoS.

Ho feta moo, litaba tse tharo tseo e seng tsa ts'ireletso (erratas) tse ka etsang hore kernel e oe ha e ntse e sebelisa mokhanni li rarollotsoe. mps (ha o etsa taelo ea sas2ircu), li-subsystems LinuxKPI (ka X11 redirection) le hypervisor bhve (ha o fetisetsa lisebelisoa tsa PCI).

Source: opennet.ru

Eketsa ka tlhaloso