Inguqulelo engalunganga yasasazwa endaweni yePython 3.5.8 ngempazamo

Ngenxa yempazamo xa uququzelela i-caching kwinkqubo yokuhanjiswa komxholo, xa uzama ukukhuphela enye yeendibano ipapashiwe kusuku oluphambi kokukhululwa kolungiso izolo Python 3.5.8 usasazeko Ulwakhiwo lwepreview olungaqulathanga zonke izilungiso. Ingxaki uchukumisekile indawo yokugcina kuphela Python-3.5.8.tar.xz, indibano Python-3.5.8.tgz isasazwe ngokuchanekileyo.

Bonke abasebenzisi abakhuphele ifayile "Python-3.5.8.tar.xz" kwiiyure zokuqala ze-12 emva kokukhululwa bayacetyiswa ukuba bajonge ukuchaneka kwedatha ekhutshiweyo usebenzisa i-checksum (MD5 4464517ed6044bca4fc78ea9ed086c36). Ngokungafaniyo nokukhululwa kokugqibela, inguqulo yokujonga kwangaphambili ayizange ibandakanye ukulungiswa ubuthathaka I-CVE-2019-16935 kwikhowudi yeseva ye-XML-RPC. Ukuba sesichengeni kuvumele ukutofa kweJavaScript (XSS) kwi-server_title field ngenxa yokungabikho kwe-engile yesibiyeli ebalekayo. Umhlaseli angafikelela endaweni yeJavaScript ukuba isicelo sicwangcisa igama leseva ngokusekelwe kwigalelo lomsebenzisi (umzekelo, "server.set_server_name('test ’)Β»).

umthombo: opennet.ru

Yongeza izimvo