Isibuyekezo se-GnuPG 2.2.23 esinokulungiswa okubalulekile kokuba sengozini

eshicilelwe ukukhululwa kwekhithi yamathuluzi I-GnuPG 2.2.23 (I-GNU Privacy Guard), ehambisana namazinga e-OpenPGP (I-RFC-4880) kanye ne-S/MIME, futhi inikeza izinsiza zokubethela idatha, ukusebenza ngamasiginesha kagesi, ukuphathwa kokhiye kanye nokufinyelela ezitolo ezibalulekile zomphakathi. Inguqulo entsha ilungisa ubungozi obubalulekile (I-CVE-2020-25125), evela enguqulweni engu-2.2.21 futhi iyasetshenziswa uma kungeniswa ukhiye we-OpenPGP oklanywe ngokukhethekile.

Ukungenisa ukhiye onohlu olukhulu oluklanywe ngokukhethekile lwama-algorithms e-AEAD kungaholela ekuchichimeni kwamalungu afanayo nokuphahlazeka noma ukuziphatha okungachazwanga. Kuyaphawulwa ukuthi ukudala ukuxhashazwa okungaholeli nje kuphela ukuphahlazeka kuwumsebenzi onzima, kodwa lokho okungenzeka akunakugwenywa. Ubunzima obukhulu ekuthuthukiseni ukuxhaphaza kungenxa yokuthi umhlaseli angakwazi ukulawula kuphela i-byte yesibili yokulandelana, futhi ibhayithi yokuqala ihlala ithatha inani elingu-0x04. Amasistimu okusabalalisa isofthiwe anokuqinisekiswa kokhiye wedijithali aphephile ngoba asebenzisa uhlu oluchazwe ngaphambilini lokhiye.

Source: opennet.ru

Engeza amazwana