1.修复的CVE
CVE-2020-21913
IBM International Components for Unicode(ICU)是美国IBM公司的一个为C/C++和Java编程语言提供了一整套操作Unicode数据的函数库,也是一个用于支持软件国际化的开源项目。
Unicode的国际组件(ICU-20850)存在安全漏洞,该漏洞源于在文件工具pkgdata pkgdata.cpp的pkg createWithAssemblyCode函数中包含一个使用后免费错误。
2.影响的操作系统
银河麒麟桌面操作系统V4 SP1
银河麒麟桌面操作系统V4 SP2
银河麒麟桌面操作系统V4 SP3
银河麒麟桌面操作系统V4 SP4
银河麒麟服务器操作系统V4 SP1
银河麒麟服务器操作系统V4 SP2
银河麒麟服务器操作系统V4 SP3
银河麒麟服务器操作系统V4 SP4
银河麒麟桌面操作系统V10
软件包:icu
55.1-7kord0.5+esm1(V4、V10)
·银河麒麟操作系统V10桌面版、V4
icu-devtools
icu-doc
libicu-dev
libicu55-dbg
libicu55
打开软件包源配置文件,根据仓库地址进行修改。
4.0.2-sp1:
http://archive.kylinos.cn/kylin/KYLIN-ALL 4.0.2sp1-desktop main restricted universe multiverse
4.0.2-sp2:
http://archive.kylinos.cn/kylin/KYLIN-ALL 4.0.2sp2-desktop main restricted universe multiverse
4.0.2-sp3:
http://archive.kylinos.cn/kylin/KYLIN-ALL 4.0.2sp3-desktop main restricted universe multiverse
4.0.2-sp4:
http://archive.kylinos.cn/kylin/KYLIN-ALL 4.0.2sp4-desktop main restricted universe multiverse
10.0:
http://archive.kylinos.cn/kylin/KYLIN-ALL 10.0 main restricted universe multiverse
10.0 SP1:
http://archive.kylinos.cn/kylin/KYLIN-ALL 10.1 main restricted universe multiverse
配置完成后执行更新命令进行升级
$sudo apt update
通过软件包地址下载软件包,使用软件包升级命令根据受影响的组件包列表 升级相关的组件包。
$dpkg -i Packagelists
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/i/icu/icu-devtools_55.1-7kord0.5%2Besm1_amd64.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/i/icu/icu-doc_55.1-7kord0.5%2Besm1_all.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/i/icu/libicu-dev_55.1-7kord0.5%2Besm1_amd64.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/i/icu/libicu55-dbg_55.1-7kord0.5%2Besm1_amd64.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/i/icu/libicu55_55.1-7kord0.5%2Besm1_amd64.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/i/icu/icu-devtools_55.1-7kord0.5%2Besm1_arm64.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/i/icu/icu-doc_55.1-7kord0.5%2Besm1_all.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/i/icu/libicu-dev_55.1-7kord0.5%2Besm1_arm64.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/i/icu/libicu55-dbg_55.1-7kord0.5%2Besm1_arm64.deb
http://archive.kylinos.cn/kylin/KYLIN-ALL/pool/main/i/icu/libicu55_55.1-7kord0.5%2Besm1_arm64.deb