Ubungozi ku-cpio kanye ne-libarchive

Iminyaka emine kusukela kumagazini wokugcina eshicilelwe Ukukhishwa kwe-cpio 2.13, insiza yokubeka kungobo yomlando ifayela esetshenziswa kumaphakheji we-RPM nama-initramfs. Lokhu kukhishwa okusha kulungisa ubungozi obuthathu:

  • I-CVE-2015-1197 - ikuvumela ukuthi ubhale ngaphezulu amafayela ngaphandle kwenkomba lapho ingobo yomlando inwetshwa khona.
  • I-CVE-2016-2037 - ibangela ukubhalela endaweni engaphandle kwebhafa eyabelwe lapho kusetshenzwa amafayela e-cpio afomethwe ngokukhethekile;
  • I-CVE-2019-14866) - ngenxa yokuhlolwa okunganele kwesihloko sefayela le-TAR, lapho udala ingobo yomlando ngefomethi ye-TAR ohlwini lwamafayela, uma ingobo yomlando yetiyela eklanywe ngokukhethekile, enkulu kakhulu ikhona kulolu hlu, ingobo yomlando ewumphumela ingadalwa, okuhlanganisa namafayela angapakishwa endaweni yomlando yetiyela eyengeziwe enamalungelo okufinyelela angalungile.

    i-tar cf isijobelelo.tar ABABHALI
    dd uma=/dev/zero seek=16G bs=1 count=0 of=isijobelelo.tar
    isandiso se-echo.tar | cpio -H tar -o | i-tar tvf -

    -rw-r—r— 1000/1000 0 2019-08-30 16:40 isijobelelo.tar
    -rw-r—r— thomas/thomas 161 2019-08-30 16:40 ABABHALI

Futhi emtatsheni wezincwadi I-Libarchive, ehlinzeka ngamathuluzi okusebenza ngamafomethi ahlukahlukene engobo yomlando namafomethi wefayela acindezelwe, ikhonjiwe ukuba sengozini (I-CVE-2019-18408), okubangela ukufinyelela kokusetshenziswa ngemva kwamahhala kubhulokhi yememori ekhululwe ngaphambilini lapho kucutshungulwa amafayela e-RAR aklanywe ngokukhethekile. Inkinga ingase iholele ekusebenziseni ikhodi enonya, kodwa ukuxhashazwa kuthathwa njengento engenakwenzeka (izinga lobunzima lingu-4.4 kokungu-10, okusho ukuthi indaba ibhekwa njengengenangozi). Indaba ayisakazwa kabanzi. kuqedwe odabeni 3.4.0.

Source: opennet.ru

Thenga ukusingathwa okuthembekile kwamasayithi anokuvikelwa kwe-DDoS, amaseva e-VPS VDS 🔥 Thenga ukusingathwa kwewebhusayithi okuthembekile ngokuvikelwa kwe-DDoS, amaseva e-VPS VDS | ProHoster