Buyekeza i-Tor 0.3.5.10, 0.4.1.9 kanye no-0.4.2.7 ngokususa ubungozi be-DoS

Kwethulwa ukukhishwa kokulungisa kwekhithi yamathuluzi ye-Tor (0.3.5.10, 0.4.1.9, 0.4.2.7, 0.4.3.3-alpha), okusetshenziselwa ukuhlela umsebenzi wenethiwekhi ye-Tor engaziwa. Izinguqulo ezintsha zilungisa ubungozi obubili:

  • I-CVE-2020-10592 - ingasetshenziswa yinoma yimuphi umhlaseli ukuqalisa ukwenqatshelwa kwesevisi kuma-relay. Ukuhlasela kungenziwa futhi ngamaseva e-Tor directory ukuhlasela amaklayenti nezinsizakalo ezifihliwe. Umhlaseli angakwazi ukudala izimo eziholela ekulayisheni okuningi ku-CPU, ukuphazamisa ukusebenza okuvamile imizuzwana embalwa noma imizuzu (ngokuphinda ukuhlasela, i-DoS inganwetshwa isikhathi eside). Inkinga ivela kusukela ekukhululweni kwe-0.2.1.5-alpha.
  • I-CVE-2020-10593 β€” ukuvuza kwenkumbulo okuqaliswe kude okwenzeka lapho i-circuit padding ifaniswe kabili kuchungechunge olufanayo.

Kungaphawulwa futhi ukuthi ku I-Tor Browser i-9.0.6 ukuba sengozini kusengezo kuhlala kungalungisiwe I-NoScript, ekuvumela ukuthi usebenzise ikhodi ye-JavaScript kumodi yokuvikela ephephile. Kulabo abavimbela ukusetshenziswa kwe-JavaScript okubalulekile kubo, kunconywa ukuthi ukhubaze okwesikhashana ukusetshenziswa kwe-JavaScript esipheqululini kokuthi mayelana:config ngokushintsha ipharamitha enikwe amandla i-javascript kokuthi mayelana:config.

Bazama ukuqeda iphutha phakathi I-NoScript 11.0.17, kodwa njengoba kwavela, ukulungiswa okuhlongozwayo akuyixazululi ngokuphelele inkinga. Uma sibheka izinguquko ekukhishweni okulandelayo okukhishiwe I-NoScript 11.0.18, inkinga nayo ayixazululeki. Isiphequluli se-Tor sifaka izibuyekezo ze-NoScript ezizenzakalelayo, ngakho-ke uma ukulungiswa sekukhona, kuzolethwa ngokuzenzakalelayo.

Source: opennet.ru

Engeza amazwana