Esikhundleni sePython 3.5.8, inguqulo engalungile yasakazwa ngephutha

Ngenxa yephutha ngenkathi kuhlelwa ukugcinwa kwesikhashana ohlelweni lokulethwa kokuqukethwe, ngenkathi uzama ukulanda enye yama-assemblies eshicilelwe ngosuku olwandulela izolo ukukhululwa kokulungisa Python 3.5.8 ukubhebhetheka Isakhiwo sokubuka kuqala esingaqukethe zonke izilungiso. Inkinga kuthintwa ingobo yomlando kuphela I-Python-3.5.8.tar.xz, umhlangano I-Python-3.5.8.tgz kusatshalaliswa ngendlela efanele.

Bonke abasebenzisi abalande ifayela elithi β€œPython-3.5.8.tar.xz” emahoreni ayi-12 okuqala ngemva kokukhishwa bayelulekwa ukuthi bahlole ukulunga kwedatha elandiwe kusetshenziswa i-checksum (MD5 4464517ed6044bca4fc78ea9ed086c36). Ngokungafani nokukhishwa kokugcina, inguqulo yokubuka kuqala ayizange ifake ukulungiswa ubuthakathaka I-CVE-2019-16935 kukhodi yeseva ye-XML-RPC. Ukuba sengozini kuvumele ukujova kwe-JavaScript (XSS) kunkambu ye-server_title ngenxa yokushoda kwe-engeli yokubaleka. Umhlaseli angazuza esikhundleni se-JavaScript uma uhlelo lokusebenza lusetha igama leseva ngokusekelwe kokufakwayo komsebenzisi (isibonelo, "server.set_server_name('test ’)Β»).

Source: opennet.ru

Engeza amazwana