Ukuvuselelwa kwephakheji ye-antivirus yamahhala i-ClamAV 0.101.3

Cisco kwethulwe ukukhishwa okulungisayo kwephakheji yamahhala yokulwa namagciwane i-ClamAV 0.101.3, eqeda ukuba sengozini okukuvumela ukuthi uqale ukwenqatshelwa kwesevisi ngokudluliswa kwengobo yomlando ye-zip eklanywe ngokukhethekile njengesinamathiseli.

Inkinga inketho ibhomu le-zip elingaphindiseli, ukukhishwa kwakho okudinga isikhathi esiningi nezinsiza. Ingqikithi yendlela ukubeka idatha kungobo yomlando ekuvumela ukuthi ufinyelele isilinganiso esiphezulu sokucindezela sefomethi ye-zip - izikhathi ezingaba yizigidi ezingu-28. Isibonelo, ifayela le-zip elilungiselelwe ngokukhethekile elingu-10 MB ngosayizi lizoholela ekukhipheni idatha engaba ngu-281 TB, kanye no-46 MB - 4.5 PB.

Ngaphezu kwalokho, ukukhishwa okusha kubuyekeze ilabhulali ye-libmpack eyakhelwe ngaphakathi, lapho kuqedwe ukuchichima kwe-buffer (I-CVE-2019-1010305), okuholela ekuvuzeni kwedatha lapho kuvulwa ifayela le-chm eliklanywe ngokukhethekile.

Ngesikhathi esifanayo, kwethulwa inguqulo ye-beta yegatsha elisha i-ClamAV 0.102, lapho ukusebenza kokuhlola okusobala kwamafayela avuliwe (ukuskena ekufinyeleleni, hlola ngesikhathi sokuvulwa kwefayela) kwadluliselwa kusuka ku-clamd kuya kunqubo ehlukile ye-clamonacc. , isetshenziswe ngokufanisa ne-clamdscan ne-clamav-milter. Lolu shintsho lwenza kwaba nokwenzeka ukuhlela ukusebenza kwe-clamd ngaphansi komsebenzisi ovamile ngaphandle kwesidingo sokuthola amalungelo ezimpande.
Igatsha elisha liphinde lengeza ukusekelwa kwezingobo zomlando zamaqanda (ESTsoft) futhi laklama kabusha ngokuphawulekayo uhlelo lwe-freshclam, olwengeze ukusekelwa kwe-HTTPS kanye nekhono lokusebenza ngezibuko ezicubungula izicelo kumachweba wenethiwekhi ngaphandle kwama-80.

Source: opennet.ru

Engeza amazwana