Cisco Security Abacwaningi
Ukuba sengozini kungase kusetshenziswe ukuze kufakwe ikhodi esimweni lapho umhlaseli engakwazi ukuhlela ukwakheka kwevelu engalungile yokuhluka okudluliswa ngakho usayizi wedatha ekopishiwe (ngokwesibonelo, kuzoba kubi uma kudluliselwa ngaphezu kuka-2 GB we idatha, kodwa ngesikhathi sokuhlasela, ukuze weqe imikhawulo ye-buffer, udinga ukudlulisa okungenani i-4GB). Umsebenzi we-memcpy () usetshenziswa kakhulu ezinhlelweni zokusebenza, futhi ama-ARMv7 processors ajwayelekile ezinhlelweni zezimoto, iselula, izimboni, abathengi, ukuxhumana kanye namadivayisi ashumekiwe, okungenzeka angaphansi kokuhlaselwa kusetshenziswa i-Bluetooth, HD Radio/DAB, USB, CAN ibhasi, I-Wi-Fi Fi neminye imithombo yedatha yangaphandle (isibonelo, amasevisi nezinhlelo zokusebenza ezifinyeleleka ngenethiwekhi eyamukela idatha yokufaka ngaphandle kwemikhawulo yosayizi ingahlaselwa).
Isibonelo ukwakhiwa kokusebenza kokuhlasela iseva ye-HTTP eyakhelwe kumasistimu olwazi lwezimoto, okufinyeleleka ngenethiwekhi yemoto ye-Wi-Fi. Umhlaseli ongaphandle angasebenzisa ukuba sengozini kwe-memcpy kule seva ngokuthumela isicelo esikhulu kakhulu se-GET futhi athole ukufinyelela kwezimpande kusistimu.
Kuzinhlelo ze-32-bit x86, inkinga ayiveli, njengoba ukuqaliswa kwe-memcpy kwalesi sakhiwo kuhumusha kahle ukuhluka kosayizi njengenani eliyinombolo engasayiniwe lohlobo lukasayizi_t (ngolimi lomhlangano.
Ukulungisa kubilisa ekushintsheni ukusetshenziswa kwemiyalelo yokuhlanganisa esebenza emisebenzini esayiniwe (i-bge ne-blt) ngozakwabo abangabhalisiwe (i-blo kanye nama-bhs).
Inkinga ayikaxazululwa
Source: opennet.ru