ืคื’ื™ืขื•ืช ื‘-SQLite ื”ืžืืคืฉืจืช ื”ืชืงืคื•ืช ืžืจื—ื•ืง ืขืœ Chrome ื‘ืืžืฆืขื•ืช WebSQL

ื—ื•ืงืจื™ ืื‘ื˜ื—ื” ืžื—ื‘ืจืช Tencent ื”ืกื™ื ื™ืช ื”ืฆื™ื’ ื•ืจื™ืื ื˜ ืคื’ื™ืขื•ืช ื—ื“ืฉ ืžื’ืœื” (CVE-2019-13734), ื”ืžืืคืฉืจ ืœืš ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืขื™ื‘ื•ื“ ืžื‘ื ื™ SQL ืฉืชื•ื›ื ื ื• ื‘ืฆื•ืจื” ืžืกื•ื™ืžืช ื‘- SQLite DBMS. ื”ื™ื™ืชื” ืคื’ื™ืขื•ืช ื“ื•ืžื” ื™ืฆื ืœืื•ืจ ืขืœ ื™ื“ื™ ืื•ืชื ื—ื•ืงืจื™ื ืœืคื ื™ ืฉื ื”. ื”ืคื’ื™ืขื•ืช ื‘ื•ืœื˜ืช ื‘ื›ืš ืฉื”ื™ื ืžืืคืฉืจืช ืœืชืงื•ืฃ ืžืจื—ื•ืง ืืช ื“ืคื“ืคืŸ ื›ืจื•ื ื•ืœื”ืฉื™ื’ ืฉืœื™ื˜ื” ืขืœ ื”ืžืขืจื›ืช ืฉืœ ื”ืžืฉืชืžืฉ ื‘ืขืช ืคืชื™ื—ืช ื“ืคื™ ืื™ื ื˜ืจื ื˜ ื‘ืฉืœื™ื˜ืช ื”ืชื•ืงืฃ.

ื”ื”ืชืงืคื” ืขืœ Chrome/Chromium ืžืชื‘ืฆืขืช ื‘ืืžืฆืขื•ืช ื”-API ืฉืœ WebSQL, ืฉื”ืžื˜ืคืœ ื‘ื• ืžื‘ื•ืกืก ืขืœ ืงื•ื“ SQLite. ื”ืชืงืคื” ืขืœ ื™ื™ืฉื•ืžื™ื ืื—ืจื™ื ืืคืฉืจื™ืช ืจืง ืื ื”ื ืžืืคืฉืจื™ื ื”ืขื‘ืจื” ืฉืœ ืžื‘ื ื™ SQL ื”ืžื’ื™ืขื™ื ืžื‘ื—ื•ืฅ ืœ-SQLite, ืœืžืฉืœ, ื”ื ืžืฉืชืžืฉื™ื ื‘-SQLite ื›ืคื•ืจืžื˜ ืœื”ื—ืœืคืช ื ืชื•ื ื™ื. ืคื™ื™ืจืคื•ืงืก ืื™ื ื• ืคื’ื™ืข ื‘ื’ืœืœ ืžื•ื–ื™ืœื” ืกื™ืจื‘ ืžื”ื˜ืžืขืช WebSQL ืชื•ืขืœืช API ืฉืœ IndexedDB.

ื’ื•ื’ืœ ืชื™ืงื ื” ืืช ื”ื‘ืขื™ื” ื‘ืžื”ื“ื•ืจื” ื›ืจื•ื 79. ื”ื™ื™ืชื” ื‘ืขื™ื” ื‘ื‘ืกื™ืก ื”ืงื•ื“ ืฉืœ SQLite ืชื•ืงืŸ 17 ื‘ื ื•ื‘ืžื‘ืจ, ื•ื‘ื‘ืกื™ืก ื”ืงื•ื“ ืฉืœ Chromium - 21 ื ื•ื‘ืžื‘ืจ.
ื”ื‘ืขื™ื” ืงื™ื™ืžืช ื‘ ืงื•ื“ ืžื ื•ืข ื—ื™ืคื•ืฉ ื˜ืงืกื˜ ืžืœื FTS3 ื•ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ื˜ื‘ืœืื•ืช ืฆืœ (ืกื•ื’ ืžื™ื•ื—ื“ ืฉืœ ื˜ื‘ืœื” ื•ื™ืจื˜ื•ืืœื™ืช ืขื ื™ื›ื•ืœืช ื›ืชื™ื‘ื”) ืขืœื•ืœื™ื ืœื”ื•ื‘ื™ืœ ืœืฉื—ื™ืชื•ืช ื‘ืื™ื ื“ืงืก ื•ืœื”ืฆืคืช ืžืื’ืจ. ืžื™ื“ืข ืžืคื•ืจื˜ ืขืœ ื˜ื›ื ื™ืงื•ืช ื”ืคืขืœื” ื™ืคื•ืจืกื ืœืื—ืจ 90 ื™ื•ื.

ืžื”ื“ื•ืจื” ื—ื“ืฉื” ืฉืœ SQLite ืขื ืชื™ืงื•ืŸ ืœืขืช ืขืชื” ืœื ื ื•ืฆืจ (ืฆืคื•ื™ 31 ื‘ื“ืฆืžื‘ืจ). ื›ืคืชืจื•ืŸ ืื‘ื˜ื—ื”, ื”ื—ืœ ืž-SQLite 3.26.0, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืžืฆื‘ SQLITE_DBCONFIG_DEFENSIVE, ืืฉืจ ืžืฉื‘ื™ืช ื›ืชื™ื‘ื” ืœื˜ื‘ืœืื•ืช ืฆืœ ื•ืžื•ืžืœืฅ ืœื”ื›ืœืœื” ื‘ืขืช ืขื™ื‘ื•ื“ ืฉืื™ืœืชื•ืช SQL ื—ื™ืฆื•ื ื™ื•ืช ื‘-SQLite. ื‘ืขืจื›ื•ืช ื”ืคืฆื”, ื”ืคื’ื™ืขื•ืช ื‘ืกืคืจื™ื™ืช SQLite ื ืฉืืจืช ืœืœื ืชื™ืงื•ืŸ ื“ื‘ื™ืืŸ, ืื•ื‘ื•ื ื˜ื•, ืจื”ืœ, openSUSE / SUSE, Arch Linux, ืคื“ื•ืจื”, FreeBSD. Chromium ื‘ื›ืœ ื”ื”ืคืฆื•ืช ื›ื‘ืจ ืžืขื•ื“ื›ืŸ ื•ืœื ืžื•ืฉืคืข ืžื”ืคื’ื™ืขื•ืช, ืืš ื”ื‘ืขื™ื” ืขืฉื•ื™ื” ืœื”ืฉืคื™ืข ืขืœ ื“ืคื“ืคื ื™ื ื•ืืคืœื™ืงืฆื™ื•ืช ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ืฉื•ื ื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืžื ื•ืข Chromium, ื›ืžื• ื’ื ืืคืœื™ืงืฆื™ื•ืช ืื ื“ืจื•ืื™ื“ ื”ืžื‘ื•ืกืกื•ืช ืขืœ Webview.

ื‘ื ื•ืกืฃ, ื–ื•ื”ื• ื’ื 4 ื‘ืขื™ื•ืช ืคื—ื•ืช ืžืกื•ื›ื ื•ืช ื‘-SQLite (CVE-2019-13750, CVE-2019-13751, CVE-2019-13752, CVE-2019-13753), ืžื” ืฉืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœื“ืœื™ืคืช ืžื™ื“ืข ื•ืœืขืงื™ืคืช ื”ื’ื‘ืœื•ืช (ื™ื›ื•ืœ ืœืฉืžืฉ ื›ื’ื•ืจืžื™ื ืชื•ืจืžื™ื ืœื”ืชืงืคื” ืขืœ Chrome). ื‘ืขื™ื•ืช ืืœื• ืชื•ืงื ื• ื‘ืงื•ื“ SQLite ื‘-13 ื‘ื“ืฆืžื‘ืจ. ื‘ื™ื—ื“, ื”ื‘ืขื™ื•ืช ืืคืฉืจื• ืœื—ื•ืงืจื™ื ืœื”ื›ื™ืŸ ื ื™ืฆื•ืœ ืขื•ื‘ื“ ื”ืžืืคืฉืจ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ื”ืงืฉืจ ืฉืœ ืชื”ืœื™ืš Chromium ื”ืื—ืจืื™ ืขืœ ื”ืขื™ื‘ื•ื“.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”