Ukuba sengozini ku-KDE Ark okuvumela amafayela ukuthi abhalwe ngaphezulu lapho kuvulwa ingobo yomlando

Kumphathi wengobo yomlando yoMphongolo othuthukiswe iphrojekthi ye-KDE ikhonjiwe ubungozi (I-CVE-2020-16116), okuvumela, lapho uvula ingobo yomlando eklanywe ngokukhethekile kuhlelo lokusebenza, ukubhala phezu kwamafayela ngaphandle kohla lwemibhalo olushiwo ukuze kuvulwe ingobo yomlando. Inkinga iphinde ivele lapho kuvulwa izingobo zomlando kumphathi wefayela le-Dolphin (Khipha into kumenyu yokuqukethwe), esebenzisa ukusebenza koMphongolo ukuze kusebenze nezingobo zomlando. Ukuba sengozini kufana nenkinga eyaziwa kudala I-Zip Slip.

Ukuxhashazwa kokuba sengozini kwehla ekungezeni izindlela eziya kungobo yomlando eziqukethe izinhlamvu ezithi β€œ../”, lapho zicutshungulwa, i-Ark ingadlulela ngale kohla lwemibhalo oluyisisekelo. Isibonelo, usebenzisa ukuba sengozini okucacisiwe, ungabhala phezu kweskripthi se-.bashrc noma ubeke umbhalo ohlwini lwemibhalo ~/.config/autostart ukuze uhlele ukwethulwa kwekhodi yakho ngezimvume zomsebenzisi wamanje. Amasheke okukhipha isexwayiso uma kunezingobo zomlando eziyinkinga angeziwe ekukhishweni koMphongolo 20.08.0. Iyatholakala futhi ukuze ilungiswe i-patch.

Source: opennet.ru

Engeza amazwana