Ukuba sengozini okubalulekile kuseva ye-Dovecot IMAP

Π’ ukukhishwa kokulungisa POP3/IMAP4 amaseva I-Dovecot 2.3.7.2 kanye no-2.2.36.4, kanye nasesengezo I-Pigeonhole 0.5.7.2 kanye ne-0.4.24.2 , kuqedwe ukuba sengozini okubalulekile (I-CVE-2019-11500), okukuvumela ukuthi ubhale idatha ngale kwebhafa enikeziwe ngokuthumela isicelo esiklanywe ngokukhethekile nge-IMAP noma i-ManageSieve protocol.

Inkinga ingasetshenziswa esigabeni sokufakazela ubuqiniso kwangaphambili. Ukuxhaphaza okusebenzayo akukakalungiselelwa, kodwa onjiniyela be-Dovecot abakhiphi amathuba okusebenzisa ukuba sengozini ukuhlela ukuhlaselwa kokwenziwa kwekhodi okukude ohlelweni noma ukuvuza idatha eyimfihlo. Bonke abasebenzisi bayanconywa ukuthi bafake izibuyekezo ngokushesha (Debian, Fedora, I-Arch Linux, Ubuntu, SUSE, RHEL, I-FreeBSD).

Ubungozi bukhona kubahlaziyi bephrothokholi ye-IMAP kanye ne-ManageSieve futhi kubangelwa ukucubungula okungalungile kwezinhlamvu ezingenalutho lapho kudluliswa idatha ngaphakathi kweyunithi yezinhlamvu ecashuniwe. Inkinga ifinyelelwa ngokubhala idatha engaqondakali ezintweni ezigcinwe ngaphandle kwebhafa eyabelwe (kufika ku-8 KB ingabhalwa phezu kwesiteji ngaphambi kokuqinisekisa, futhi kufike ku-64 KB ngemva kokuqinisekisa).

Ngu umbono Onjiniyela abavela ku-Red Hat benza kube nzima ukusebenzisa inkinga ekuhlaselweni kwangempela ngoba umhlaseli akakwazi ukulawula indawo yokubhala phezu kwedatha engafanele enqwabeni. Ekuphenduleni, umbono uvezwa ukuthi lesi sici sinzima kakhulu ukuhlasela, kodwa asibandakanyi ukuqaliswa kwakho - umhlaseli angaphinda umzamo wokuxhaphaza izikhathi eziningi aze afike endaweni yokusebenza enqwabeni.

Source: opennet.ru

Engeza amazwana