I-Fedora 37 ilibazisekile iiveki ezimbini ngenxa yokuba sesichengeni esibalulekileyo kwi-OpenSSL

Abaphuhlisi beprojekthi yeFedora babhengeze ukuhlehliswa kokukhululwa kwe-Fedora 37 ukuya kwi-15 kaNovemba ngenxa yesidingo sokuphelisa ubuthathaka obubalulekileyo kwithala leencwadi le-OpenSSL. Ekubeni idatha malunga neyona nto inobungozi iya kubhengezwa kuphela ngoNovemba 1 kwaye akucaci ukuba kuya kuthatha ixesha elingakanani ukuphumeza ukukhuselwa ekusasazeni, kwagqitywa ukuba kuhlehliswe ukukhululwa kwiiveki ezi-2. Eli akulona ixesha lokuqala lokukhululwa kwe-Fedora 37 kulindeleke ngo-Oktobha 18, kodwa yahlehliswa kabini (ngo-Oktobha 25 kunye noNovemba 1) ngenxa yokungaphumeleli ukuhlangabezana nemilinganiselo yomgangatho.

Okwangoku, imiba ye-3 ihlala ingalungiswanga kuvavanyo lokugqibela olwakhayo kwaye ihlelwa njengokuthintela ukukhutshwa. Ukongeza kwisidingo sokulungisa ubuthathaka kwi openssl, umphathi wekwin ujinga xa eqala iseshoni ye Plasma yaseWayland-based xa indlela imiselwe kwi nomodeset (imizobo esisiseko) kwi UEFI, kwaye isicelo sekhalenda ye-gnome siyaba ngumkhenkce xa uhlela uphinda-phinda. iziganeko.

Ubuthathaka obubalulekileyo kwi-OpenSSL buchaphazela kuphela isebe le-3.0.x; ukukhutshwa kwe-1.1.1x akubuthathaka. Isebe le-OpenSSL 3.0 sele lisetyenziswa kulwabiwo olufana nolu Ubuntu 22.04, CentOS Ukusasaza 9, RHEL 9, OpenMandriva 4.2, Gentoo, Fedora 36, Debian Uvavanyo/Aluzinzanga. Kwi-SUSE Linux Iipakeji ze-Enterprise 15 SP4 kunye ne-openSUSE Leap 15.4 ezine-OpenSSL 3.0 ziyafumaneka ngokuzithandela, iipakeji zenkqubo zisebenzisa isebe le-1.1.1. Amasebe e-OpenSSL 1.x asekho Debian 11, I-Arch Linux, Akukho nto Linux, Ubuntu Ngomhla wama-20.04 ku-Epreli, eSlackware, e-ALT Linux, RHEL 8, OpenWrt, Alpine Linux 3.16.

Ubuthathaka buhlulwe njengobubalulekileyo; iinkcukacha azikafumaneki okwangoku, kodwa inqanaba lobunzima balo lifana nobuthathaka obudumileyo beHeartbleed. Inqanaba lobunzima obubalulekileyo lithetha ukuba kunokwenzeka ukuhlaselwa okukude kwiindlela eziqhelekileyo zokucwangcisa. Imiba ebalulekileyo ingabandakanya imiba ekhokelela ekuvuzeni kwememori okukude. umncedisi, ukusebenzisa ikhowudi yomhlaseli, okanye ukufaka izitshixo zabucala zeseva emngciphekweni. Ipetshi ye-OpenSSL 3.0.7 elungisa ingxaki kunye nolwazi malunga nobuthathaka iya kupapashwa ngoNovemba 1.

umthombo: opennet.ru

Thenga ukusingathwa okuthembekileyo kwiindawo ezinokhuseleko lweDDoS, iiseva zeVPS VDS 🔥 Thenga ukusingathwa kwewebhusayithi okuthembekileyo ngokhuseleko lwe-DDoS, iiseva zeVPS VDS | ProHoster