I-Exim 4.92.3 ishicilelwe ngokususa ubungozi besine obubalulekile onyakeni

eshicilelwe iseva yemeyili ukukhululwa okukhethekile Ukukhipha 4.92.3 ngokuqedwa komunye ukuba sengozini okubalulekile (I-CVE-2019-16928), ngokunamandla okukuvumela ukuthi wenze ikhodi yakho ukude kuseva ngokudlulisela iyunithi yezinhlamvu efomethwe ngokukhethekile kumyalo we-EHLO. Ubungozi buvela esiteji ngemva kokuthi amalungelo asethwe kabusha futhi akhawulelwe ekusebenziseni ikhodi ngamalungelo omsebenzisi ongenamalungelo, lapho kusetshenziswa isibambi somlayezo ongenayo.

Inkinga ivela kuphela egatsheni le-Exim 4.92 (4.92.0, 4.92.1 kanye no-4.92.2) futhi ayidluleli nokuba sengozini okulungisiwe ekuqaleni kwenyanga. I-CVE-2019-15846. Ukuba sengozini kubangelwa ukuchichima kwebhafa emsebenzini string_vformat(), echazwe kuchungechunge lwefayela.c. Kubonisiwe ukuxhaphaza ikuvumela ukuthi udale ukuphahlazeka ngokudlula iyunithi yezinhlamvu ende (amakhilobhayithi amaningana) kumyalo we-EHLO, kodwa ukuba sengozini kungasetshenziswa eminye imiyalo, futhi kungase kusetshenziswe ukuhlela ukukhishwa kwekhodi.

Awekho amasu okusebenza okuvimbela ukuba sengozini, ngakho bonke abasebenzisi bayanconywa ukuthi bafake isibuyekezo ngokushesha, basebenzise i-patch noma qinisekisa ukuthi usebenzisa amaphakheji anikezwe ukusatshalaliswa okuqukethe ukulungiswa kokuba sengozini kwamanje. I-hotfix ikhishelwe Ubuntu (ithinta kuphela igatsha 19.04), I-Arch Linux, I-FreeBSD, Debian (ithinta kuphela i-Debian 10 Buster) futhi Fedora. I-RHEL ne-CentOS abathinteki kule nkinga, njengoba i-Exim ingafakiwe kunqolobane yabo yephakheji ejwayelekile (ku- I-EPEL7 buyekeza okwamanje akukho). Ku-SUSE/openSUSE ubungozi abubonakali ngenxa yokusetshenziswa kwegatsha le-Exim 4.88.

Source: opennet.ru

Engeza amazwana