I-Samba 4.10.8 kunye ne-4.9.13 yohlaziyo kunye nokulungiswa kobuthathaka

Ilungisiwe ukukhutshwa kokulungiswa kwephakheji ye-Samba 4.10.8 kunye ne-4.9.13, ethe yaphelisa ukuba sesichengeni (I-CVE-2019-10197), ivumela umsebenzisi ukufikelela kulawulo lweengcambu apho isahlulelo somsebenzi womnatha weSamba sikhoyo. Ingxaki yenzeka xa i-'wide links = ewe 'inketho ichazwe kwizicwangciso ngokudibanisa ne-unix extensions = hayi' okanye 'vumela amakhonkco abanzi angakhuselekanga = ewe'. Ukufikelela kwiifayile ngaphandle kwesahlulelo ekwabelwana ngaso ngoku sikhawulelwe ngamalungelo okufikelela komsebenzisi, okt. umhlaseli unokufunda kwaye abhale iifayile ngokwe uid/gid yazo.

Ingxaki ibangelwa kukuba emva kwesicelo sokuqala sengcambu yokwahlula okwabelwanayo, impazamo yokufikelela ibuyiselwa kumxhasi, kodwa i-smbd igcina i-directory yokufikelela kwaye ayicimi i-cache xa kukho ingxaki yokufikelela. Ngokufanelekileyo, emva kokuthumela isicelo esiphindaphindiweyo se-SMB, iqhutywe ngempumelelo ngokusekelwe kwi-cache yokungena ngaphandle kokuhlolwa kwemvume ephindaphindiweyo.

umthombo: opennet.ru

Yongeza izimvo