Ukuba sesichengeni okubalulekileyo kwiProFTPd

Kwiseva ye-ProFTPD ftp ichongiwe ubuthathaka obunobungozi (I-CVE-2019-12815), ekuvumela ukuba ukopishe iifayile ngaphakathi komncedisi ngaphandle kokuqinisekisa usebenzisa "isayithi cpfr" kunye ne "site cpto" imiyalelo. ingxaki eyabelwe inqanaba lengozi 9.8 ngaphandle kwe-10, ekubeni ingasetyenziselwa ukuququzelela ukuphunyezwa kwekhowudi ekude ngelixa inikezela ukufikelela ngokungaziwa kwi-FTP.

Ukuba sesichengeni bangelwa itshekhi engalunganga yokufikelela kwizithintelo zokufunda nokubhala idatha (Umda FUNDA kunye noMda WRITE) kwimodyuli ye-mod_copy, esetyenziswa ngokungagqibekanga kwaye inikwe amandla kwiipakethe zeproftpd kunikezelo oluninzi. Kuyaphawuleka ukuba ubuthathaka sisiphumo sengxaki efanayo engekasonjululwa ngokupheleleyo, ichongiwe ngo-2015, apho ii-vectors zokuhlaselwa ezintsha zichongiwe ngoku. Ngaphezu koko, ingxaki yaxelwa kubaphuhlisi ngoSeptemba kulo nyaka uphelileyo, kodwa isiqwenga sasinjalo zilungisiwe kwiintsuku nje ezimbalwa ezidlulileyo.

Ingxaki ikwavela kukukhutshwa kwangoku kweProFTPd 1.3.6 kunye ne-1.3.5d. Ulungiso luyafumaneka njenge isiqwenga. Njengomsebenzi wokhuseleko, kuyacetyiswa ukuba ukhubaze i-mod_copy kuqwalaselo. Ukuba sesichengeni kuye kwalungiswa kuphela Fedora kwaye ihlala ingalungiswanga Debian, SUSE/openSUSE, Ubuntu, FreeBSD, EPEL-7 (I-ProFTPD ayinikezelwanga kwindawo yokugcina i-RHEL, kwaye iphakheji esuka kwi-EPEL-6 ayichaphazeleki yingxaki kuba ayibandakanyi i-mod_copy).

umthombo: opennet.ru

Yongeza izimvo