Ukuvuselelwa: ukuba sengozini ku-Sudo kungavumela abasebenzisi okungafanele basebenzise imiyalo njengezimpande

Vulnetability in Sudo

Emizuzwini embalwa edlule, abakwaCanonical bashicilele umbiko omusha wezokuphepha. Ukuba sengozini okulungiswe ngalesi sikhathi kungenye yalezo ezingabonwa futhi ebesingase siziphuthe, kepha kuyamangaza ukuba sentweni eyaziwa ngabasebenzisi bonke be-Ubuntu: umyalo sudo. Umbiko oshicilelwe yi I-USN-4154-1 futhi, njengoba ungalindela, kuthinta zonke izinhlobo ze-Ubuntu ezisekelwayo.

Ukucacisa okuthe xaxa, izinhlobo ezixhaswayo esibhekise kuzo zingukuthi Ubuntu 19.04, Ubuntu 18.04, kanye no-Ubuntu 16.04 kumjikelezo wayo ojwayelekile no-Ubuntu 14.04 no-Ubuntu 12.04 kuhlobo lwayo lwe-ESM (Extended Security Maintenance). Uma singena ekhasini le- ukuba sengozini okulungisiwe, eshicilelwe yi-Canonical, siyabona ukuthi sekukhona iziqeshana ezitholakalayo zazo zonke izinhlobo ezishiwo ngenhla, kepha lokho Ubuntu 19.10 Eoan Ermine kusathinteka njengoba singafunda embhalweni ngokubomvu "kuyadingeka".

Iziphazamisi eziningi ku-Ubuntu kernel- Update
I-athikili ehlobene:
Ukuvuselelwa: ICanonical iphinde yamaka kabusha amaphutha amaningi ku-Ubuntu kernel

sudo ivuselelwa kunguqulo 1.8.27 ukulungisa ubungozi

Isiphazamisi esilungisiwe yi- I-CVE-2019-14287, echazwa njenge:

Lapho i-Sudo ihlelelwe ukuvumela umsebenzisi ukuthi enze imiyalo njengomsebenzisi ongenakuphikiswa ngegama LONKE elingukhiye kusincazelo se-Runas, kungenzeka ukwenza imiyalo njengezimpande ngokucacisa i-ID yomsebenzisi -1 noma i-4294967295.

ICanonical ibhale isinqumo ngokuthi okubaluleke kakhulu. Noma kunjalo, "sudo" kanye "nezimpande" kusenza sicabange ngakho I-Lockdown, imodyuli yokuphepha ezobonakala ngeLinux 5.4. Le mojula izophinda ikhawulele izimvume, ezivikeleke ngakolunye uhlangothi kepha ngakolunye uhlangothi izovimbela abanikazi beqembu ekubeni uhlobo "lukaNkulunkulu" nayo. Ngalesi sizathu, kube nenkulumompikiswano ngayo isikhathi eside futhi iLockdown izokhutshazwa ngokuzenzakalela, yize isizathu esiyinhloko salokhu ukuthi kungalimaza izinhlelo ezikhona zokusebenza.

Isibuyekezo sesivele sitholakala ezikhungweni ezahlukahlukene zesoftware. Uma ucabanga ukuthi kulula kangakanani futhi kuyashesha ukubuyekeza, ngombono akudingeki ukuthi uqale kabusha, uvuselele manje.


Shiya umbono wakho

Ikheli lakho le ngeke ishicilelwe. Ezidingekayo ibhalwe nge *

*

*

  1. Ubhekele imininingwane: Miguel Ángel Gatón
  2. Inhloso yedatha: Lawula Ugaxekile, ukuphathwa kwamazwana.
  3. Ukusemthethweni: Imvume yakho
  4. Ukuxhumana kwemininingwane: Imininingwane ngeke idluliselwe kubantu besithathu ngaphandle kwesibopho esisemthethweni.
  5. Isitoreji sedatha: Idatabase ebanjwe yi-Occentus Networks (EU)
  6. Amalungelo: Nganoma yisiphi isikhathi ungakhawulela, uthole futhi ususe imininingwane yakho.