Ubungozi obuthathu bulungiswe ku-FreeBSD

I-FreeBSD ikhuluma ngobungozi obuthathu obungavumela ukusetshenziswa kwekhodi uma usebenzisa i-libfetch, ukuthunyelwa kabusha kwephakethe le-IPsec, noma ukufinyelela kudatha ye-kernel. Izinkinga zilungiswa kuzibuyekezo 12.1-RELEASE-p2, 12.0-RELEASE-p13 kanye no-11.3-RELEASE-p6.

  • I-CVE-2020-7450 - ukuchichima kwebhafa kulabhulali ye-libfetch, esetshenziselwa ukulayisha amafayela kumyalo wokulanda, umphathi wephakheji we-pkg nezinye izinsiza. Ukuba sengozini kungaholela ekusebenziseni ikhodi lapho kucutshungulwa i-URL eklanywe ngokukhethekile. Ukuhlasela kungenziwa lapho ufinyelela isayithi elilawulwa umhlaseli, okuthi, ngokuqondisa kabusha kwe-HTTP, akwazi ukuqalisa ukucutshungulwa kwe-URL engalungile;
  • I-CVE-2019-15875 - ubungozi bomshini wokukhiqiza ukulahlwa kwenqubo okubalulekile. Ngenxa yephutha, kufika kumabhayithi angu-20 edatha esuka ku-kernel stack aqoshwe ekulahlwayo okuyinhloko, okungenzeka kuqukathe ulwazi oluyimfihlo olucutshungulwe yi-kernel. Njengendlela yokusebenza ukuze uvikeleke, ungakhubaza ukukhiqizwa kwamafayela angumongo usebenzisa i-sysctl kern.coredump=0;
  • I-CVE-2019-5613 - iphutha kukhodi yokuvimbela ukuthunyelwa kwedatha kabusha ku-IPsec kwenze kwaba nokwenzeka ukuphinda uthumele amaphakethe athwetshulwe ngaphambilini. Ngokuya ngephrothokholi yezinga eliphezulu edluliswa nge-IPsec, inkinga ekhonjiwe ivumela, isibonelo, ukuthi imiyalo edluliselwe ngaphambilini iphinde iphindiselwe.

Source: opennet.ru

Engeza amazwana