I-Samba 4.10.8 kanye ne-4.9.13 ibuyekeza ngokulungiswa kokuba sengozini

Ilungiselelwe ukukhishwa okulungisiwe kwephakheji ye-Samba 4.10.8 kanye ne-4.9.13, eqediwe ukuba sengozini (I-CVE-2019-10197), okuvumela umsebenzisi ukuthi afinyelele kumkhombandlela wezimpande lapho ukuhlukaniswa kwenethiwekhi ye-Samba kutholakala khona. Inkinga yenzeka lapho inketho ethi 'wide links = yebo' icaciswa kuzilungiselelo kuhlanganiswe ne-'unix extensions = no' noma 'vumela izixhumanisi ezibanzi ezingavikelekile = yebo'. Ukufinyelela kumafayela angaphandle kwengxenye yamanje eyabiwe kunqunyelwe amalungelo okufinyelela omsebenzisi, i.e. umhlaseli angafunda futhi abhale amafayela ngokuya nge-uid/gid yawo.

Inkinga ibangelwa ukuthi ngemva kwesicelo sokuqala sempande yokuhlukaniswa okwabiwe, iphutha lokufinyelela libuyiselwa kuklayenti, kodwa i-smbd igcina inqolobane yokufinyelela kohla lwemibhalo futhi ayisusi inqolobane uma kwenzeka kunenkinga yokufinyelela. Ngokufanelekile, ngemva kokuthumela isicelo esiphindaphindiwe se-SMB, sicutshungulwa ngempumelelo ngokusekelwe ekufakweni kwenqolobane ngaphandle kokuhlolwa kwemvume okuphindaphindiwe.

Source: opennet.ru

Engeza amazwana