Uhlobo olusha lwe-SpamAssassin 3.4.3 yokusetshenziswa kokuhlunga ogaxekile lufika

I-SpamAssassin

Ngemuva konyaka wentuthuko inguqulo entsha ye ipulatifomu yokuhlunga ogaxekile, I-SpamAssassin 3.4.3 okuyi iza nezinguquko eziningi nokulungiswa kwamaphutha enye yazo kwakuwukungcupheka okungaholela ekwenqabelweni kwensizakalo.

I-SpamAssassin wuhlelo lokuhlunga ugaxekile esebenzisa amasu ahlukahlukene wokuthola ogaxekile, kufaka phakathi i-DNS nokutholwa kogaxekile okususelwe ku-fuzzy-checksum, ukuhlunga, izinhlelo zangaphandle, uhlu lokugcina, kanye nemininingwane yolwazi eku-inthanethi. Uhlelo lungahlanganiswa neseva yeposi ukuhlunga ngokuzenzakalela yonke imeyili evela kusayithi.

Ingasetshenziswa futhi ngabasebenzisi ngabodwana ebhokisini labo leposi futhi ihlangana nezinhlelo ezahlukahlukene ze-imeyili. I-Apache SpamAssassin iyalungiswa kakhulu uma isetshenziswa njengesihlungi sohlelo lonke.

I-SpamAssassin isebenzisa indlela ephelele yokwenza isinqumo ngebhulokhio: Umlayezo uhlola uchungechunge lwamasheke (ukuhlaziywa komongo, uhlu olumnyama nolumhlophe lwe-DNSBL, izigaba eziqeqeshiwe zaseBazesian, ukuqinisekiswa kwesiginesha, ukuqinisekiswa komthumeli kusetshenziswa i-SPF ne-DKIM, njll.).

Ngemuva kokuhlaziya umyalezo ngezindlela ezahlukahlukene, kunqwabelana inani elithile lesisindo. Uma i-coefficient ebaliwe yeqa umkhawulo othile, umyalezo uyavalwa noma umakwe njengogaxekile.

Ngaphandle kwalokho isebenzisa amathuluzi ahambisanayo wokuvuselela okuzenzakalelayo komthetho isihlungi, iphakethe lingasetshenziswa kuzinhlelo zombili zamakhasimende nezeseva. Ikhodi yeSpamAssassin ibhalwe ePerl futhi isatshalaliswa ngaphansi kwelayisense le-Apache.

Izici ze-SpamAssassin 3.4.3

Ekumenyezelweni kwenguqulo entsha yeSpamAssassin 3.4.3 kuqokonyiswa ukuthi sekufakiwe igama elingukhiye elisha "I-Subjprefix" ekucushweni ukwengeza isiqalo kusihloko somyalezo lapho umthetho ubangelwa. Ilebula "_SUBJPREFIX_»Kungezwe kumathempulethi, okukhombisa ukusethwa kwe-«isizinda".

Kungezwe umsebenzi we-check_rbl_ns_from ohlola iseva ye-DNS kuhlu lwe-RBL. Umsebenzi owengeziwe cmthandeni_sa ukuqinisekisa izizinda noma amakheli e-IP azo zonke izihloko ezitholwe ku-RBL.

Mayelana nokulungiswa kule nguqulo entsha yeSpamAssassin 3.4.3 kushiwo ukulungiswa kobungozi (I-CVE-2018-11805), ukuthi ikuvumela ukuthi usebenzise imiyalo yohlelo kusuka kumafayela we-CF (Amafayela wokumiswa kwe-SpamAssassin) ngaphandle kokukhombisa imininingwane ngokuqaliswa kwayo.

Kanye nokulungiswa kobungozi (CVE-2019-12420) engasetshenziswa ukudala ukwenqatshwa kwensizakalo lapho ucubungula i-imeyili enengxenye eyenziwe ngokukhethekile ye-Multipart.

Onjiniyela kusuka kuSpamAssassin futhi umemezele ukulungiswa kwegatsha 4.0, elizosebenzisa ukucubungula okugcwele okushumekiwe kwe-UTF-8.

NgoMashi 1, 2020, ukushicilelwa kwemithetho enamasiginesha asuselwa ku-SHA-1 algorithm nakho kuzomiswa (kunguqulo 3.4.2, imisebenzi ye-hashi ye-SHA-256 ne-SHA-512 ithathe isikhundla se-SHA-1).

Kwezinye izinguquko okugqamile esikhangisweni:

  • Kungezwe i-plugin entsha OLEVBMacro yakhelwe ukuthola ama-OLE macros nekhodi ye-VB ngaphakathi kwemibhalo
  • Isivinini esithuthukisiwe nokuphepha kokuskena kokuphrinta okukhulu ngezilungiselelo i-body_part_scan_size ne-rawbody_part_scan_size.
  • Isiphathi senkomba «akukho sihloko»Kungezwe emithethweni yokucubungula umzimba wencwadi ukumisa ukufuna unhlokweni weSifundo njengengxenye yombhalo emzimbeni womyalezo
  • Ngezizathu zokuphepha, inketho 'i-sa-update -allowpluginsyehlisiwe.
  • Okukhethwa kukho izihloko ze-rbl_ ingezwe ku-plugin I-DNSEval ukuchaza izihloko ozozihlola ezinhlwini ze-RBL.
  • Izinketho zengezwe emsebenzini hlola_hashbl_emails ukuchaza izihloko, okuqukethwe okufanele kuhlolwe kuqhathaniswa ne-RBL noma i-ACL.
  • Umsebenzi hlola_i-hashbl_bodyre ingezwe ukuthola umzimba wencwadi kusetshenziswa isisho esijwayelekile futhi kubhekwa ukufana okutholakala ku-RBL.
  • Umsebenzi hlola_hashbl_uris ingeziwe ukuthola ama-URL emzimbeni womlayezo nokuwaqinisekisa ku-RBL.

Okokugcina kulabo abafuna ukuthola le nguqulo entsha ungathola ikhodi yomthombo kusuka isixhumanisi esilandelayo noma ngakolunye uhlangothi, linda ama-binaries ahambisanayo ukuze kusatshalaliswe ukwabiwa okuhlukile kwe-Linux eziteshini ezihambisanayo.


Shiya umbono wakho

Ikheli lakho le ngeke ishicilelwe. Ezidingekayo ibhalwe nge *

*

*

  1. Unomthwalo wemfanelo ngedatha: AB Internet Networks 2008 SL
  2. Inhloso yedatha: Lawula Ugaxekile, ukuphathwa kwamazwana.
  3. Ukusemthethweni: Imvume yakho
  4. Ukuxhumana kwemininingwane: Imininingwane ngeke idluliselwe kubantu besithathu ngaphandle kwesibopho esisemthethweni.
  5. Isitoreji sedatha: Idatabase ebanjwe yi-Occentus Networks (EU)
  6. Amalungelo: Nganoma yisiphi isikhathi ungakhawulela, uthole futhi ususe imininingwane yakho.