Ukukhishwa kwe-VirtualBox 6.0.6

Inkampani ye-Oracle kwakheka ukukhishwa kokulungiswa kwesistimu ye-virtualization VirtualBox 6.0.6 kanye ne-5.2.28, ephawulile 39 ukulungiswa. Iphinde ilungiswe ekukhishweni okusha 12 ubuthakathaka, okuyi-7 yazo inezinga elibucayi lengozi (CVSS Score 8.8). Imininingwane ayinikeziwe, kodwa ukwahlulela ngezinga le-CVSS izinkinga sezilungisiwe, kubonisiwe emqhudelwaneni we-Pwn2Own 2019 futhi ikuvumela ukuthi ukhiphe ikhodi kuhlangothi lwesistimu yomsingathi endaweni yesistimu yesivakashi.

Izinguquko ezinkulu ekukhishweni kwe-6.0.6:

  • Usekelo lwe-Linux kernels 4.4.169, 5.0 kanye no-5.1 lwengezwe kuzivakashi ze-Linux nababungazi. Kwengezwe ilogi enemiphumela yamamojula wokwakha we-Linux kernel. Ukuhlanganiswa kwabashayeli ukuze kulayishwe kumodi ye-Secure Boot kuqalisiwe. Ukusebenza okuthuthukisiwe nokuthembeka kwamafolda okwabelwana ngawo;
  • Izinguquko ezincane zenziwe kusixhumi esibonakalayo somsebenzisi. Ukuboniswa okuthuthukisiwe kwenqubekelaphambili yokususa isifinyezo. Izinkinga ezilungisiwe ngokukopisha amafayela nokubonisa ukuqhubeka kokukopishwa kwemisebenzi kusiphathi sefayela esakhelwe ngaphakathi. Amaphutha alungisiwe avele ngesikhathi sokufakwa kwe-Ubuntu ngokuzenzakalelayo ezinhlelweni zezivakashi;
  • Kwengezwe usekelo lokuqala lwefomethi ye-QCOW3 kumodi yokufunda kuphela. Amaphutha alungisiwe lapho ufunda ezinye izithombe ze-QCOW2;
  • Ukulungiswa okuningi kwenziwe kudivayisi yezithombe ezilingisayo ze-VMSVGA. Ukusebenzisana kwe-VMSVGA okuthuthukisiwe namaseva ama-X amadala. Kungenzeka ukusebenzisa i-VMSVGA lapho usebenza ne-EFI firmware interface. Izinkinga ezixazululiwe ngesikhombisi siyanyamalala uma izengezo zokuhlanganisa usekelo lwegundane zingafakiwe.
    Izinkinga zokukhumbula usayizi wesikrini sesivakashi nokusebenzisa i-RDP sezixazululiwe;

  • Izinkinga ngokulayisha isimo esilondoloziwe samadivayisi we-LsiLogic zixazululiwe;
  • Izinkinga nge-virtualization esidlekeni kumasistimu anama-AMD processors sezixazululiwe;
  • Ukulingisa kwe-IDE PCI kuthuthukisiwe, okuvumela abashayeli be-NetWare IDE ukuthi basebenze besebenzisa imodi yokuphatha ibhasi;
  • Nge-backend ye-DirectSound, ikhono lokusesha kumadivayisi atholakalayo womsindo wengeziwe;
  • Kuhlelo olungaphansi lwenethiwekhi, izinkinga zokugcwaliswa kwephakethe okukhuphukayo lapho usebenzisa iWindows ohlangothini lomsingathi zixazululiwe;
  • Izinkinga ngokulingiswa kwe-serial port sezixazululiwe;
  • Kulungiswe isiphazamisi esiholele ekuphindaphindweni kohla lwemibhalo okwabiwe (Ifolda eyabelwe) ngemva kokubuyisela umshini obonakalayo ovela esimweni esilondoloziwe;
  • Izinkinga ezilungisiwe lapho ukopisha amafayela phakathi komsingathi nesistimu yesivakashi kumodi yokuhudula bese uphonsa;
  • Ukuphahlazeka okulungisiwe lapho usebenzisa i-VBoxManage;
  • Kulungiswe iphutha eliholele ekumiseni lapho uzama ukuqala umshini obonakalayo ngemuva kokwehluleka;
  • Ezinhlelweni zezivakashi ezine-Windows, izinkinga zokusebenzisa izilungiselelo zesikrini eziyinkimbinkimbi usebenzisa umshayeli we-WDDM zixazululiwe (Ukuqandisa kwe-Skype Yebhizinisi nokuphahlazeka kwezinhlelo zezivakashi ezine-WDDM kulungisiwe);
  • Ukusekelwa okuthuthukisiwe kwemibhalo eyabiwe yezihambeli ze-OS/2;
  • Amasevisi ewebhu ahlinzeka ngokusekela kwe-Java 11;
  • Ukuhlanganiswa ne-LibreSSL kuthuthukisiwe;
  • Izinkinga ngesakhiwo seFreeBSD sezixazululiwe.

Source: opennet.ru

Engeza amazwana