ืžื”ื“ื•ืจื•ืช ื—ื“ืฉื•ืช ืฉืœ Node.js 13.8, 12.15 ื•-10.19 ืขื ืคื’ื™ืขื•ื™ื•ืช ืžืชื•ืงื ื•ืช

ืžืคืชื—ื™ื ืฉืœ ืคืœื˜ืคื•ืจืžืช JavaScript ื‘ืฆื“ ื”ืฉืจืช Node.js ืคื•ืจืกื ืชื™ืงื•ืŸ ื’ืจืกืื•ืช 13.8.0, 12.15.0 ื•- 10.19.0, ืืฉืจ ืžืชืงื ื™ื ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื”:

  • CVE-2019-15606 - ื˜ื™ืคื•ืœ ืฉื’ื•ื™ ื‘ืชื•ื•ื™ ืจื•ื•ื— ืื•ืคืฆื™ื•ื ืœื™ื™ื (OWS) ื‘ืขืงื‘ื•ืช ืขืจืš ื‘ื›ื•ืชืจืช HTTP;
  • CVE-2019-15605 - ืืคืฉืจื•ืช ืœื‘ืฆืข ืžืชืงืคืช HRS (ื”ื‘ืจื—ืช ื‘ืงืฉืช HTTP, ื”ื™ื ืžืืคืฉืจืช ืœื”ื™ืฆืžื“ ืœืชื•ื›ืŸ ืฉืœ ื‘ืงืฉื•ืช ืื—ืจื•ืช ื”ืžืขื•ื‘ื“ื•ืช ื‘ืื•ืชื• ื—ื•ื˜ ื‘ื™ืŸ ื”ืงืฆื” ื”ืงื“ืžื™ ืœื—ืœืง ื”ืื—ื•ืจื™) ื‘ืืžืฆืขื•ืช ื”ืขื‘ืจื” ืฉืœ ื›ื•ืชืจืช HTTP ืžืกื•ื’ Transfer-Encoding;
  • CVE-2019-15604 ื”ื™ื ืงืจื™ืกืช ืฉืจืช TLS ื”ืžื•ืคืขืœืช ืžืจื—ื•ืง ื‘ืืžืฆืขื•ืช ืฉื™ื“ื•ืจ ืฉืœ ืžื—ืจื•ื–ืช ืฉื’ื•ื™ื” ื‘ืชืขื•ื“ื”.

ื‘ื ื•ืกืฃ, ื‘ืžื”ื“ื•ืจื•ืช ื—ื“ืฉื•ืช ื ืขืฉืชื” ืขื‘ื•ื“ื” ืœืฉื™ืคื•ืจ ื”ืื‘ื˜ื—ื” ืฉืœ ืžื ืชื— HTTP ื•ื ื™ืชื•ื— ืงืคื“ื ื™ ื™ื•ืชืจ ืฉืœ ืจื›ื™ื‘ื™ ื‘ืงืฉืช HTTP. ื”ืฉื™ื ื•ื™ ืขืœื•ืœ ืœื’ืจื•ื ืœื‘ืขื™ื•ืช ืชืื™ืžื•ืช ืขื ื™ื™ืฉื•ืžื™ HTTP ืฉืžืคืจื™ื ืืช ื”ืžืคืจื˜. ื›ื“ื™ ืœื”ืฉื‘ื™ืช ืืช ืžืฆื‘ ื”ืื™ืžื•ืช ื”ืงืคื“ื ื™, ืžืกื•ืคืงื•ืช ื”ื”ื’ื“ืจื” insecureHTTPParser ื•ืืคืฉืจื•ืช ืฉื•ืจืช ื”ืคืงื•ื“ื” "-insecure-http-parser".

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”