Mefokolo e meraro e kentsoeng ho FreeBSD

FreeBSD e sebetsana le mefokolo e meraro e ka lumellang ts'ebetso ea khoutu ha o sebelisa libfetch, IPsec packet retransmission, kapa phihlello ea data ea kernel. Mathata a lokisoa lintlafatsong 12.1-RELEASE-p2, 12.0-RELEASE-p13 le 11.3-RELEASE-p6.

  • CVE-2020-7450 - buffer e phalla laebraring ea libfetch, e sebelisetsoang ho kenya lifaele ka taelo ea ho lata, mookameli oa sephutheloana sa pkg le lisebelisoa tse ling. Ho ba kotsing ho ka lebisa ts'ebetsong ea khoutu ha o sebetsana le URL e entsoeng ka mokhoa o khethehileng. Tlhaselo e ka etsoa ha u kena sebakeng se laoloang ke mohlaseli, eo, ka ho tsamaisa HTTP, e khonang ho qala ts'ebetso ea URL e kotsi;
  • CVE-2019-15875 - ho ba le ts'oaetso mochining oa ho hlahisa lithōle tsa mantlha. Ka lebaka la phoso, ho fihla ho li-byte tse 20 tsa data ho tsoa ho kernel stack li ile tsa rekotoa lithōlehong tsa mantlha, tse ka bang le leseli la lekunutu le sebetsitsoeng ke kernel. E le mokhoa oa ho sireletsa, o ka thibela ho hlahisa lifaele tsa mantlha ka sysctl kern.coredump=0;
  • CVE-2019-5613 - phoso ka khoutu bakeng sa ho thibela ho romelloa ha data hape ho IPsec ho entse hore ho khonehe ho romela lipakete tse nkiloeng pele. Ho itšetlehile ka protocol e phahameng e fetisitsoeng ho IPsec, bothata bo khethiloeng bo lumella, ka mohlala, litaelo tse fetisitsoeng pele hore li halefe.

Source: opennet.ru

Eketsa ka tlhaloso