PostgreSQL update addressing vulnerabilities. Release of the connection balancer Odyssey 1.2

Corrective updates have been released for all supported branches of PostgreSQL: 14.1, 13.5, 12.9, 11.14, 10.19, and 9.6.24. The release 9.6.24 will be the last update for the 9.6 branch, which has reached its end of life. Updates for branch 10 will continue until November 2022, for 11 until November 2023, for 12 until November 2024, for 13 until November 2025, and for 14 until November 2026.

The new versions include over 40 fixes and address two vulnerabilities (CVE-2021-23214, CVE-2021-23222) in the server process and client library libpq. These vulnerabilities allow an attacker to infiltrate an encrypted communication channel through a MITM attack. The attack does not require a valid SSL-certificate and can be conducted against systems that require client authentication via certificate. In the server context, the attack allows for the injection of an attacker's SQL query at the moment a secure connection is established between the client and PostgreSQL server. In the context of libpq, the vulnerability permits an attacker to return a fake server response to the client. Together, these vulnerabilities can be used to extract information about passwords or other confidential client data exchanged in the early connection phase.

Additionally, it is worth noting that Yandex has published a new version of its proxy server, Odyssey 1.2, designed to maintain a pool of open connections to the PostgreSQL DBMS and organize the routing of requests. Odyssey supports the running of multiple worker processes with multithreaded handlers, along with server options for client reconnections and the ability to bind connection pools to users and databases. The code is written in C and distributed under the BSD license.

The new version of Odyssey includes protection to block data injection after the SSL session handshake (this feature blocks attacks using the aforementioned vulnerabilities CVE-2021-23214 and CVE-2021-23222). Support for PAM and LDAP has been implemented. Integration with the Prometheus monitoring system has been added. The calculation of statistics parameters for tracking transaction and query execution times has been improved.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster