Uhlaziyo lweJava SE, MySQL, VirtualBox kunye nezinye iimveliso zeOracle ezinobuthathaka obulungisiweyo

Inkampani ye-Oracle ipapashiwe ukukhutshwa okucwangcisiweyo kohlaziyo kwiimveliso zayo (i-Critical Patch Update), ejolise ekupheliseni iingxaki ezibalulekileyo kunye nobuthathaka. Kuhlaziyo luka-Epreli oku kwapheliswa ngokupheleleyo 297 ubuthathaka.

Imiba Java SE 12.0.1, 11.0.3 kunye 8u212 Imiba ye-5 yokhuseleko ilungisiwe. Bonke ubuthathaka bunokusetyenziswa kude ngaphandle kokuqinisekiswa. Ubuthathaka obuthile obuthile kwiqonga leWindows eyabelwe I-CVSS Score 9.0 (CVE-2019-2699), ehambelana nenqanaba elibalulekileyo lengozi kwaye ivumela umsebenzisi ongagunyaziswanga phezu kwenethiwekhi ukuba adibanise izicelo zeJava SE. Ubuthathaka obubini kwi-2D ye-graphics processing subsystem inikwe inqanaba le-8.1 (CVE-2019-2697, CVE-2019-2698). Iinkcukacha azikachazwa.

Ukongeza kwimiba yeJava SE, ubuthathaka benziwe esidlangalaleni kwezinye iimveliso zeOracle, kubandakanya:

  • 40 ubuthathaka kwi-MySQL (inqanaba eliphezulu lobunzima 7.5). Eyona ngxaki iyingozi
    (I-CVE-2019-2632) ichaphazela inkqubo esezantsi yeplagi yokuqinisekisa. Imiba iya kulungiswa kukhupho Umncedisi woLuntu we-MySQL 8.0.16, 5.7.26 kunye no-5.6.44.

  • 12 ubuthathaka kwi-VirtualBox, apho i-7 ine-degree ebalulekileyo yengozi (i-CVSS Score 8.8). Ubuthathaka bulungisiwe kuhlaziyo I-VirtualBox 6.0.6 kunye ne-5.2.28 (ngaphakathi Phawula into yokuba iingxaki zokhuseleko zisonjululwe ayizange ibhengezwe phambi kokukhululwa). Iinkcukacha azibonelelwanga, kodwa kujongwa ngokwenqanaba le-CVSS, ubuthathaka bulungisiwe, bonisiwe kukhuphiswano lwe-Pwn2Own 2019 kwaye ikuvumela ukuba wenze ikhowudi kwicala lenkqubo yomkhosi ukusuka kwindawo yenkqubo yeendwendwe.

    ikuvumela ukuba uhlasele inkqubo yenginginya ukusuka kubume bendwendwe.

  • 3 ubuthathaka kwi-Solaris (ubukhulu obukhulu be-5.3 - iingxaki kunye nomphathi wephakheji ye-IPS, i-SunSSH kunye nenkonzo yokulawula ukutshixa. Iingxaki ezilungisiweyo ekukhululweni
    I-Solaris 11.4 SRU8, eyaphinda yaqalisa inkxaso kwiilayibrari ze-UCB (libucb, librpcsoc, libdbm, libtermcap, libcurses) kunye nenkonzo ye-fc-fabric, iinguqulelo zephakheji ezihlaziyiweyo
    ibus 1.5.19, NTP 4.2.8p12,
    IFirefox 60.6.0esr,
    IZIQINISEKISO 9.11.6
    I-OpenSSL 1.0.2r,
    I-MySQL 5.6.43 & 5.7.25,
    libxml2 2.9.9,
    libxslt 1.1.33,
    I-Wireshark 2.6.7,
    Nurses 6.1.0.20190105,
    Apache httpd 2.4.38,
    perl 5.22.

umthombo: opennet.ru

Yongeza izimvo