Buyekeza i-Ruby 2.6.5, 2.5.7 kanye ne-2.4.8 ngobungozi obulungisiwe

Ukukhishwa okulungile kolimi lohlelo lweRuby kwenziwe 2.6.5, 2.5.7 ΠΈ 2.4.8, elungise ubungozi obune. Ukuba sengozini okuyingozi kakhulu (CVE-2019-16255) kulabhulali ejwayelekile shell (lib/shell.rb), okuthi kuvumela ukwenza ikhodi esikhundleni. Uma idatha etholwe kumsebenzisi icutshungulwa kumpikiswano yokuqala ye-Shell#[] noma izindlela zokuhlola ze-Shell# ezisetshenziselwa ukuhlola ubukhona befayela, umhlaseli angakwazi ukufeza ikholi yendlela ye-Ruby engafanele.

Ezinye izinkinga:

  • I-CVE-2019-16254 - ukuchayeka kuseva ye-http eyakhelwe ngaphakathi WEBrick Ukuhlasela okuhlukanisayo kwempendulo ye-HTTP (uma uhlelo lufaka idatha engaqinisekisiwe enhlokweni yempendulo ye-HTTP, unhlokweni ungahlukaniswa ngokufaka uhlamvu lomugqa omusha);
  • I-CVE-2019-15845 ukufaka esikhundleni sohlamvu olungenalutho (\0) kulezo ezikhethwe ngokusebenzisa izindlela ze-β€œFile.fnmatch” kanye β€œne-File.fnmatch?”. izindlela zefayela zingasetshenziswa ukuqalisa isheke ngamanga;
  • I-CVE-2019-16201 - ukwenqatshwa kwesevisi kumojula yokuqinisekisa ye-Diges ye-WEBrick.

Source: opennet.ru

Engeza amazwana