Ukuba sesichengeni kwi-chrony

Π’ ikratshi, ukuphunyezwa kweNTP protocol esetyenziselwa ukulungelelanisa ixesha elichanekileyo kwizinikezelo ezahlukeneyo zeLinux, ichongiwe ukuba sesichengeni (I-CVE-2020-14367), ikuvumela ukuba ubhale ngaphezulu nayiphi na ifayile kwindlela enonikezelo kumsebenzisi ongenalungelo lobulali chrony. Ukuba sesichengeni kunokusetyenziswa kuphela nge-chrony yomsebenzisi, enciphisa ingozi yayo. Nangona kunjalo, umba ubeka esichengeni inqanaba lokuzahlula kwi-chrony kwaye unokusetyenziswa ukuba obunye ubuthathaka ichongiwe kwikhowudi eyenziwe emva kokuba amalungelo enziwe ngokutsha.

Ukuba sesichengeni kubangelwa yindalo engakhuselekanga yefayile ye pid, eyadalwa kwinqanaba xa ichrony yayingekaseti kwakhona amalungelo kwaye yayisebenza njengengcambu. Kule meko, i-directory / run/chrony directory, apho ifayile ye-pid ibhalwe khona, yenziwe ngamalungelo 0750 nge-systemd-tmpfiles okanye xa i-chronyd yasungulwa ngokubambisana nomsebenzisi kunye neqela elithi "chrony". Ngaloo ndlela, ukuba unokufikelela kwi-chrony yomsebenzisi, kunokwenzeka ukubuyisela ifayile ye-pid /run/chrony/chronyd.pid ngekhonkco elingumfuziselo. Ikhonkco lokomfuziselo linokwalatha kuyo nayiphi na ifayile yesixokelelwano eya kubhalwa ngaphezulu xa i-chronyd isungulwa.

ingcambu# systemctl yeka chronyd.service
ingcambu# sudo -u chrony /bin/bash

chrony$ cd /run/chrony
chrony$ ln -s /etc/shadow chronyd.pid
chrony$ phuma

ingcambu# /usr/sbin/chronyd -n
^C
# endaweni yemixholo ye /etc/shadow i-ID yenkqubo ye-chronyd iya kugcinwa
ingcambu# ikati /etc/shadow
15287

Ukuba sesichengeni isusiwe kumcimbi chrony 3.5.1. Uhlaziyo lwepakethi olulungisa ukuba sesichengeni luyafumaneka Fedora. Kwinkqubo yokulungiselela uhlaziyo lwe RHEL, Debian ΠΈ Ubuntu.

SUSE kunye ne-openSUSE ingxaki ayichaphazeleki, kuba ikhonkco lokomfuziselo lechrony lenziwe ngokuthe ngqo kwi/run directory, ngaphandle kokusebenzisa oovimba abangaphantsi abongezelelweyo.

umthombo: opennet.ru

Yongeza izimvo