I-Exim 4.92.3 ipapashwe kunye nokupheliswa kobuthathaka besine obubalulekileyo enyakeni

ipapashiwe iseva yemeyile ukukhululwa okukhethekileyo Exim 4.92.3 ngokupheliswa komnye ukuba sesichengeni okubalulekileyo (I-CVE-2019-16928) Ukuba sesichengeni kubonakala kwinqanaba emva kokuba amalungelo asetyenzisiwe kwaye anqunyelwe ekuqhutyweni kwekhowudi kunye namalungelo omsebenzisi ongekho mthethweni, apho umbambi womyalezo ongenayo uphunyezwa.

Ingxaki ibonakala kuphela kwi-Exim 4.92 yesebe (4.92.0, 4.92.1 kunye ne-4.92.2) kwaye ayihambelani nobuthathaka obulungisiweyo ekuqaleni kwenyanga. I-CVE-2019-15846. Ukuba sesichengeni kubangelwa kukuphuphuma kwebuffer kumsebenzi umtya_vformat(), ichazwe kumtya wefayile.c. Umboniso ukuxhaphaza ikuvumela ukuba wenze ingozi ngokugqithisa umtya omde (iikhilobhayithi ezininzi) kumyalelo we-EHLO, kodwa ubuthathaka bunokusetyenziswa ngeminye imiyalelo, kwaye kusenokusetyenziswa ukulungelelanisa ukwenziwa kwekhowudi.

Akukho misebenzi yokuthintela ukuba sesichengeni, ke bonke abasebenzisi bayacetyiswa ukuba bafakele uhlaziyo ngokukhawuleza, bafake isicelo. isiqaqa okanye qinisekisa ukuba usebenzisa iipakethe ezibonelelwe ngonikezelo oluqulathe ukulungiswa kobuthathaka bangoku. I-hotfix ikhululwe Ubuntu (ichaphazela kuphela isebe 19.04), Arch Linux, FreeBSD, Debian (ichaphazela kuphela i-Debian 10 Buster) kunye Fedora. I-RHEL kunye ne-CentOS azichatshazelwa yingxaki, kuba i-Exim ayiqukwanga kwindawo yabo yokugcina ipakethe (kwi EPEL7 hlaziya okwangoku engekhoyo). Kwi-SUSE/openSUSE ukuba sesichengeni akubonakali ngenxa yosetyenziso lwesebe le-Exim 4.88.

umthombo: opennet.ru

Yongeza izimvo