Ukuba sengozini okubalulekile ku-ProFTPd

Kuseva ye-ProFTPD ftp ikhonjiwe ubuthakathaka obuyingozi (I-CVE-2019-12815), okuvumela ukuthi ukopishe amafayela ngaphakathi kweseva ngaphandle kokuqinisekisa usebenzisa imiyalo "yesayithi cpfr" kanye "nendawo ye-cpto". inkinga eyabelwe izinga lengozi 9.8 kwezingu-10, njengoba lingasetshenziswa ukuhlela ukukhishwa kwekhodi yesilawuli kude kuyilapho inikeza ukufinyelela okungaziwa ku-FTP.

Ukuba sengozini kubangelwa ukuhlola okungalungile kwemikhawulo yokufinyelela yokufunda nokubhala idatha (Limit FUNDA futhi Ukhawule WRITE) kumojula ye-mod_copy, esetshenziswa ngokuzenzakalelayo futhi enikwe amandla kumaphakheji e-proftpd ekusatshalalisweni okuningi. Kuyaphawuleka ukuthi ukuba sengozini kuwumphumela wenkinga efanayo engakaxazululwa ngokuphelele, ikhonjiwe ngo-2015, lapho sekuhlonzwe khona amagciwane amasha. Ngaphezu kwalokho, inkinga yabikwa kubathuthukisi emuva ngoSepthemba ngonyaka odlule, kodwa isichibi sasinjalo zilungisiwe ezinsukwini ezimbalwa ezedlule.

Inkinga ivela futhi ekukhishweni kwakamuva kwamanje kwe-ProFTPd 1.3.6 kanye ne-1.3.5d. Ukulungiswa kuyatholakala njenge isichibi. Njengendlela yokuphepha, kuyanconywa ukuthi ukhubaze i-mod_copy ekucushweni. Ukuba sengozini kuze kube manje kulungisiwe kuphela Fedora futhi ihlala ingalungiswanga Debian, SUSE/openSUSE, Ubuntu, I-FreeBSD, I-EPEL-7 (I-ProFTPD ayinikeziwe endaweni yokugcina ye-RHEL, futhi iphakheji elisuka ku-EPEL-6 alithintwa inkinga ngoba ayifaki i-mod_copy).

Source: opennet.ru

Engeza amazwana