ืขื“ื›ื•ืŸ Nginx 1.22.1 ื•-1.23.2 ืขื ืคื’ื™ืขื•ื™ื•ืช ืžืชื•ืงื ื•ืช

ื”ืขื ืฃ ื”ืจืืฉื™ ืฉืœ nginx 1.23.2 ืฉื•ื—ืจืจ, ืฉื‘ืชื•ื›ื• ื ืžืฉืš ื”ืคื™ืชื•ื— ืฉืœ ืชื›ื•ื ื•ืช ื—ื“ืฉื•ืช, ื›ืžื• ื’ื ืฉื—ืจื•ืจื• ืฉืœ ื”ืขื ืฃ ื”ื™ืฆื™ื‘ ื”ื ืชืžืš ื”ืžืงื‘ื™ืœ ืฉืœ nginx 1.22.1, ื”ื›ื•ืœืœ ืจืง ืฉื™ื ื•ื™ื™ื ื”ืงืฉื•ืจื™ื ืœื‘ื™ื˜ื•ืœ ืฉื’ื™ืื•ืช ื—ืžื•ืจื•ืช ื• ืคื’ื™ืขื•ื™ื•ืช.

ื”ื’ืจืกืื•ืช ื”ื—ื“ืฉื•ืช ืžื‘ื˜ืœื•ืช ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” (CVE-2022-41741, CVE-2022-41742) ื‘ืžื•ื“ื•ืœ ngx_http_mp4_module, ื”ืžืฉืžืฉ ืœืืจื’ื•ืŸ ืกื˜ืจื™ืžื™ื ื’ ืžืงื‘ืฆื™ื ื‘ืคื•ืจืžื˜ H.264/AAC. ื”ืคื’ื™ืขื•ื™ื•ืช ืขืœื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœืคื’ื™ืขื” ื‘ื–ื™ื›ืจื•ืŸ ืื• ืœื“ืœื™ืคืช ื–ื™ื›ืจื•ืŸ ื‘ืขืช โ€‹โ€‹ืขื™ื‘ื•ื“ ืงื•ื‘ืฅ mp4 ื‘ืขืœ ืžื‘ื ื” ืžื™ื•ื—ื“. ืกื™ื•ื ื—ื™ืจื•ื ืฉืœ ืชื”ืœื™ืš ืขื‘ื•ื“ื” ืžื•ื–ื›ืจ ื›ืชื•ืฆืื” ืžื›ืš, ืืš ื‘ื™ื˜ื•ื™ื™ื ืื—ืจื™ื ืื™ื ื ื ื›ืœืœื™ื, ื›ื’ื•ืŸ ืืจื’ื•ืŸ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืฉืจืช.

ืจืื•ื™ ืœืฆื™ื™ืŸ ืฉืคื’ื™ืขื•ืช ื“ื•ืžื” ื›ื‘ืจ ืชื•ืงื ื” ื‘ืžื•ื“ื•ืœ ngx_http_mp4_module ื‘-2012. ื‘ื ื•ืกืฃ, F5 ื“ื™ื•ื•ื— ืขืœ ืคื’ื™ืขื•ืช ื“ื•ืžื” (CVE-2022-41743) ื‘ืžื•ืฆืจ NGINX Plus, ื”ืžืฉืคื™ืขื” ืขืœ ืžื•ื“ื•ืœ ngx_http_hls_module, ื”ืžืกืคืง ืชืžื™ื›ื” ื‘ืคืจื•ื˜ื•ืงื•ืœ HLS (Apple HTTP Live Streaming).

ื‘ื ื•ืกืฃ ืœื‘ื™ื˜ื•ืœ ืคื’ื™ืขื•ื™ื•ืช, ื”ืฉื™ื ื•ื™ื™ื ื”ื‘ืื™ื ืžื•ืฆืขื™ื ื‘-nginx 1.23.2:

  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืžืฉืชื ื™ "$proxy_protocol_tlv_*", ื”ืžื›ื™ืœื™ื ืืช ื”ืขืจื›ื™ื ืฉืœ ืฉื“ื•ืช TLV โ€‹โ€‹(Type-Length-Value) ื”ืžื•ืคื™ืขื™ื ื‘ืคืจื•ื˜ื•ืงื•ืœ Type-Length-Value PROXY v2.
  • ืกื™ืคืง ืกื™ื‘ื•ื‘ ืื•ื˜ื•ืžื˜ื™ ืฉืœ ืžืคืชื—ื•ืช ื”ืฆืคื ื” ืขื‘ื•ืจ ื›ืจื˜ื™ืกื™ ื”ืคืขืœื” ืฉืœ TLS, ื‘ืฉื™ืžื•ืฉ ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ื–ื™ื›ืจื•ืŸ ืžืฉื•ืชืฃ ื‘ื”ื ื—ื™ื™ืช ssl_session_cache.
  • ืจืžืช ื”ืจื™ืฉื•ื ืขื‘ื•ืจ ืฉื’ื™ืื•ืช ื”ืงืฉื•ืจื•ืช ืœืกื•ื’ื™ ืจืฉื•ืžื•ืช SSL ืฉื’ื•ื™ื™ื ื™ืจื“ื” ืžืจืžื” ืงืจื™ื˜ื™ืช ืœืจืžืช ืžื™ื“ืข.
  • ืจืžืช ื”ืจื™ืฉื•ื ืฉืœ ื”ื•ื“ืขื•ืช ืขืœ ื—ื•ืกืจ ื”ื™ื›ื•ืœืช ืœื”ืงืฆื•ืช ื–ื™ื›ืจื•ืŸ ืœื”ืคืขืœื” ื—ื“ืฉื” ืฉื•ื ืชื” ืžื”ืชืจืื” ืœื”ืชืจืื” ื•ื”ื™ื ืžื•ื’ื‘ืœืช ืœื”ื•ืฆืืช ืขืจืš ืื—ื“ ื‘ืฉื ื™ื™ื”.
  • ื‘ืคืœื˜ืคื•ืจืžืช Windows, ื”ื•ืงืžื” ื”ืจื›ื‘ื” ืขื OpenSSL 3.0.
  • ื”ืฉืชืงืคื•ืช ืžืฉื•ืคืจืช ืฉืœ ืฉื’ื™ืื•ืช ืคืจื•ื˜ื•ืงื•ืœ PROXY ื‘ื™ื•ืžืŸ.
  • ืชื•ืงื ื” ื‘ืขื™ื” ืฉื‘ื” ืคืกืง ื”ื–ืžืŸ ืฉืฆื•ื™ืŸ ื‘ื”ื ื—ื™ื™ืช "ssl_session_timeout" ืœื ืขื‘ื“ ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-TLSv1.3 ื”ืžื‘ื•ืกืก ืขืœ OpenSSL ืื• BoringSSL.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”