Systemd ikozvino ine anopfuura 1.2 miriyoni mitsara yekodhi

Debian-ine-systemd

Systemd ndiyo yekutanga system uye daemon iyo yakagadzirirwa chaizvo iyo Linux kernel seimwe nzira yeSystem V yekutanga daemon (sysvinit). Chinangwa chayo chikuru ndechekupa chimiro chiri nani chekugadzirisa kutsamira pakati pemasevhisi, kubvumidza kurodha zvakafanana kwemasevhisi pakutanga uye kudzikisa mafoni kune maShell zvinyorwa.

Mushure mekupfuura mamirioni emitsetse yekodhi muna 2017, systemd's Git repository inoratidza kuti ikozvino yasvika 1.207.302 mitsara yekodhi. Iyi mitsara 1.2 miriyoni yakapararira pamafaera mazana matatu nemakumi maviri nemakumi matanhatu uye ine makumi mana nemakumi mashanu ane makumi mashanu neshanu yekusimbiswa kubva kune vangangoita 3,260 vanyori vakasiyana

Systemd yakanyorwa rekodhi nhamba yezvikwereti gore rapfuura, asi Parizvino, zvakaoma kufungidzira izvozvo iyi rekodhi inogona kutyorwa mu2019.

Gore rino, kwave kuine 2 commits. Mwaka wadarika, huwandu hwakataridza 145 6,245.

Lennart Poettering anoramba ari mutsigiri ane mukurumbira ye systemd ine inopfuura makumi matatu kubva muzana yezvibvumirano kusvika zvino gore rino.

Mushure make tinogona kuona kuti vamwe vanyori vanotevera Lennart Poettering gore rino ndi Yu Watanabe, Zbigniew Jędrzejewski-Szmek, Frantisek Sumsal, Susant Sahani naEvgeny Vereshchagin. Vakakomberedza vanhu zana nemakumi mana nevaviri vakabatsira iyo Systemd sosi yemuti kubvira kutanga kwegore.

Systemd haisati yafarirwa nevazhinji

Kunyangwe nhasi uno mazhinji ekugoverwa kweGNU / Linux anotora systemd, izvi zvakashoropodzwa zvakanyanya (uye hazvisi zvevamwe) nedzimwe nhengo dzemunharaunda yakavhurika sosi, , que tenda kuti chirongwa ichi chinopesana nehunyanzvi hweUnix uye kuti vagadziri vayo vane anti-Unix maitiro, nekuti systemd haina kuenderana neese asiri maLinux masisitimu.

Ndokusaka Izvo zvakakosha kuti urangarire kuti systemd yaive kumavambo enharaunda yeDebian yakatsemuka payakasarudza kuitora. seyakagadziriswa yekutanga system, kunyangwe paityisidzirwa nevamwe vateresi.

Izvo pamberi pezviito zvakadaro saka vakasiya chirongwa cheDebian kuti vagadzire forogo inonzi Devuan (Debian isingashandise systemd).

Zvakanaka iyo yekutanga chinangwa cheiyo purojekiti kupa musiyano weDebian pasina kuomarara uye kutsamira kweiyo systemd, init system uye maneja maneja yakatanga kugadzirwa neRed Hat uye yakazogamuchirwa nedzimwe dzakawanda distros.

Uye ndizvo izvozvo pakutanga kwegore takazivisa izvozvo kumwe kwekuparadzirwa kukuru kweLinux kwaive kunetseka kune vamwe systemd bugs.

systemd
Nyaya inoenderana:
Kushushikana kutsva kwakawanikwa muSystemd

Pakati pechimwe chezvikanganiso zvaivepo, mumwe wavo anga ari mu 'journald' sevhisi, iyo inounganidza nekuchengetedza dhata dhata. Ivo vanogona kushandiswa kuti vawane midzi irombo pane chakanangwa muchina kana kuburitsa ruzivo.

Zvimwe zvezvikanganiso izvi zvakawanikwa nevatsvakurudzi vekambani yekuchengetedza yeQualys, zvikanganiso zvaive zviviri zvekurangarira huori hushoma (stack buffer kufashukira - CVE-2018-16864 uye risingaperi ndangariro kugoverwa - CVE-2018-16865) uye imwe ichibvumira ruzivo kuburitsa (kuverenga kunze kwemiganhu, CVE- 2018-16866).

Vatsvakurudzi vakagadzira kushandisa yeCVE-2018-16865 uye CVE-2018-16866 iyo inopa yemuno midzi ganda pane x86 uye x64 michina.

Kushandisa akamhanya nekukurumidza papuratifomu yeX86 uye akazadzisa chinangwa chake mumaminitsi gumi. Pa x64, kushandisa kwacho kwakatora maminetsi makumi manomwe.

Qualys yakanga yazivisa kuti yakaronga kuburitsa kodhi yekushandisa yePoC kuratidza kuvepo kwezvikanganiso uye ikatsanangura zvakadzama kuti yaikwanisa sei kushandisa zvisizvo izvi. Vatsvakurudzi vakagadzirawo humbowo hwepfungwa yeCVE-2018-16864 iyo inobvumidza iwe kutora kutonga kweeip, i386 yekuraira mureza.

Iyo buffer yekufashukira kusagadzikana (CVE-2018-16864) yakaunzwa muna Kubvumbi 2013 (systemd v203) uye yakaitwa kushandiswa muna Kukadzi 2016 (systemd v230).

Nezve iyo isinga ganhurirwe memory yekugovaniswa kusagadzikana (CVE-2018-16865), yakaunzwa muna Zvita 2011 (systemd v38) uye ikaitwa kushandiswa muna Kubvumbi 2013 (systemd v201), nepo ndangariro ichidonha kushomeka (CVE-2018-16866) yakaunzwa mu Chikumi 2015 (systemd v221) uye yakagadziriswa nokusaziva muna Nyamavhuvhu 2018.


Siya yako yekutaura

Your kero e havazobvumirwi ichibudiswa. Raida minda anozivikanwa ne *

*

*

  1. Inotarisira iyo data: Miguel Ángel Gatón
  2. Chinangwa cheiyo data: Kudzora SPAM, manejimendi manejimendi.
  3. Legitimation: Kubvuma kwako
  4. Kutaurirana kwedata
  5. Dhata yekuchengetedza: Dhatabhesi inobatwa neOccentus Networks (EU)
  6. Kodzero: Panguva ipi neipi iwe unogona kudzora, kupora uye kudzima ruzivo rwako

  1.   luix akadaro

    systemd inoyamwa !!!!!!!!!!!!!!!

  2.   01101001b akadaro

    - Mhoroi apo? Guinness World Zvinyorwa? Pano ndine imwe! Iyo malware yemamirioni 1.2 emitsetse yekodhi!
    - Kutenda nekufona! Asi iyo yazvino rekodhi ine mamirioni makumi mashanu inobatwa kechigumi nguva neMSWi ...
    - Usataurazve.