Iyo nyowani vhezheni yePacman 5.2 package maneja yave kuwanikwa

ArchLinux

Vhiki rapfuura tanga tichitaura nezvazvo iyo nhau dzakaburitswa neArch Linux vanogadzira kuisa tsigiro yeiyo zstd compression algorithm saPacman vhezheni 5.2. Uye zvakanaka maawa mashoma apfuura iyo vhezheni itsva yakaburitswa maneja Pacman 5.2 mapakeji

Kune avo vasingazive nezve Pacman, vanofanirwa kuziva izvo uyu ndiye Arch Linux package package, inokwanisa kugadzirisa kutsamira, uye otomatiki kurodha pasi uye nekuisa ese anodiwa mapakeji. Mune dzidziso, mushandisi anongoda kuita chete kuraira kunyatso gadziridza iyo system.

Pacman anoshandisa mafaera akarongedzwa mutara uye akatsikirirwa mu gzip kana xz yemapakeji ese, yega yega ine zvinyorwa zvakanyorwa. Mapakeji anotorwa pasi kuburikidza neFTP, unogona zvakare kushandisa HTTP uye emuno mafaera, zvinoenderana nekuti imwe neimwe yekuchengetera inogadziriswa sei. Inoenderana neLinux Arch Vaka Sisitimu (ABS) inoshandiswa kugadzira mapakeji kubva kunobva kodhi.

Zvinyorwa zvitsva zvePacman 5.2

Nekuvhurwa kweiyi nyowani vhezheni yePacman 5.2, tinogona kuona kuti imwe yeanonyanya kuzivikanwa mabhuku ari kuiswa kweiyo zstd algorithm iyo, ichienzaniswa ne "xz" algorithm, mhanyisa kumanikidza uye kuburitsa mapakeji, uku uchichengetedza danho rekumanikidza.

Pamwe chete nazvo akawedzera kugona kubatanidza mamaneja kune makepkg kurodha pasi sosi mapakeji uye ongorora nesiginicha yedhijitari. Uye zvakare, rutsigiro rwakawedzerwawo pakomputa yekumanikidza uchishandisa iyo lzip uye lz4 algorithms.

Panyaya yeRepo-wedzera, rwakawedzerwa rutsigiro rwekumanikidza dhatabhesi uchishandisa zstd inomira. Munguva pfupi iri kutevera, Arch Linux inotarisira shanduko yekushandisa kushandisa zstd.

Imwe shanduko muPacman 5.2 ndeyekuti rutsigiro rwekuvandudza kwedelta rwabviswa zvachose, ichikubvumidza iwe kurodha pasi chete shanduko. Iko kugona kwakabviswa nekuda kwekunetsekana (CVE-2019-18183), iyo inobvumidza mirau yekumanikidza kuti iitwe pachirongwa kana uchishandisa zvisina kunyorwa dhatabhesi.

Zvekurwisa, zvakafanira kuti mushandisi atore mafaera akagadzirirwa neanorwisa aine dhatabhesi uye yekuvandudza kwedelta. Tsigiro yekuvandudzwa kwedelta yakaremara nekutadza uye haina kushandiswa zvakanyanya. Mune ramangwana, zvakarongwa kunyorazve zvizere kuiswa kwe delta kugadzirisa.

Kune rimwe divi futi Tsigiro yekurodha pasi makiyi ePGP uchishandisa Web Key Directory inoratidzwa (WKD), ine musimboti wekuisa makiyi eruzhinji pawebhu ine chinongedzo kudomasi yakatarwa mune email kero

Imwe shanduko iyo inofanirwa kutariswa ndeyekuti mune iyi nyowani vhezheni yePacman 5.2 bvisa "- simba" sarudzo nekuti nekushandisa kwayo mukana wekuve nezvinetso neyakavimbika unogona kuitika. Iye zvino panzvimbo yesarudzo "-kunyora" kunopihwa. fungisisa zvakanyatsonaka.

Ipo yefaira yekutsvaga mhedzisiro ine "-F" sarudzo inopa ruzivo rwakawedzerwa seboka repakeji uye chinzvimbo chekuisa.

Chekupedzisira zvirinani kutaura kuti nekuburitswa kwaPacman 5.2, kusagadzikana kwakagadziriswa muXferCommand command handler (CVE-2019-18182), iyo inobvumidza MITM kurwisa uye isina kunyorwa dhatabhesi kuti uwane kuitiswa kwemirairo yako pachirongwa. .

Uye izvo nePacman 5.2 zvinokwanisika kuvaka uchishandisa iyo Meson system pane Autotools. Mune inotevera vhezheni, Meson anotsiva zvachose Autotools.

Gadziridza Pacman kune iyo nyowani vhezheni

Mune dzino nguva dzakanyorwa chinyorwa iyo itsva vhezheni yePacman haisati yaburitswa mune Arch Linux zvinyorwa, saka ndiyo chete nzira yekuwana iyi vhezheni vhezheni yePacman 5.2 mune yedu system uyes nekurodha pasi nekunyora kodhi yekodhi yacho pakombuta yedu.

Kune vanofarira vanofarira kuvaka, vanogona kuwana iyo Pacman 5.2 kodhi kubva pane iyi link iripazasi.

Zvichakadaro kune vamwe, inguva yekumirira kuziviswa muOctopi kana kumirira kuti iyo yekuvandudza iratidzwe mukati meArch Linux repositories.


Siya yako yekutaura

Your kero e havazobvumirwi ichibudiswa. Raida minda anozivikanwa ne *

*

*

  1. Inotarisira data: AB Internet Networks 2008 SL
  2. Chinangwa cheiyo data: Kudzora SPAM, manejimendi manejimendi.
  3. Legitimation: Kubvuma kwako
  4. Kutaurirana kwedata
  5. Dhata yekuchengetedza: Dhatabhesi inobatwa neOccentus Networks (EU)
  6. Kodzero: Panguva ipi neipi iwe unogona kudzora, kupora uye kudzima ruzivo rwako