Tor 0.3.5.10, 0.4.1.9 kunye 0.4.2.7 uhlaziyo ukulungisa DoS sesichengeni

Zinikiwe ukukhutshwa kwezilungiso ze-Tor toolkit (0.3.5.10, 0.4.1.9, 0.4.2.7, 0.4.3.3-alpha), esetyenziselwa ukuququzelela umsebenzi wenethiwekhi yeTor engaziwa. Iinguqulelo ezintsha zilungisa ubuthathaka obubini:

  • I-CVE-2020-10592 - inokusetyenziswa nguye nawuphi na umhlaseli ukuqalisa ukwaliwa kwenkonzo kwiirelays. Uhlaselo lunokuthi lwenziwe ngamaseva e-Tor directory ukuhlasela abathengi kunye neenkonzo ezifihliweyo. Umhlaseli unokudala iimeko ezikhokelela kumthwalo omkhulu kwi-CPU, ukuphazamisa ukusebenza okuqhelekileyo kwemizuzwana emininzi okanye imizuzu (ngokuphinda uhlaselo, i-DoS inokwandiswa ixesha elide). Ingxaki ibonakala ukususela ekukhululweni kwe-0.2.1.5-alpha.
  • I-CVE-2020-10593 - inkumbulo evuzayo eqalwa kude eyenzeka xa i-padding yesekethe idityaniswa kabini kwitsheyini enye.

Kwakhona kunokuqatshelwa ukuba kwi Isiphequluli soThutho 9.0.6 ukuba sesichengeni kwesongezo kuhlala kungalungiswanga I-NoScript, ekuvumela ukuba usebenzise ikhowudi yeJavaScript kwimodi yokukhusela ekhuselekileyo. Kwabo banqanda ukuphunyezwa kweJavaScript kubalulekile, kuyacetyiswa ukuba ungasebenzi okwexeshana usetyenziso lweJavaScript kwisikhangeli malunga ne:config ngokutshintsha iparamitha yejavascript.enabled malunga ne:config.

Bazama ukuphelisa isiphene NoScript 11.0.17, kodwa njengoko kwavela, ukulungiswa okucetywayo akusombululi ngokupheleleyo ingxaki. Ngokujonga utshintsho kukhupho olulandelayo olukhutshiweyo NoScript 11.0.18, ingxaki nayo ayisonjululwa. Isikhangeli seTor sibandakanya uhlaziyo lweNoScript oluzenzekelayo, ke ukuba ukulungiswa kufumaneka, kuya kuhanjiswa ngokuzenzekelayo.

umthombo: opennet.ru

Yongeza izimvo