ืขื“ื›ื•ืŸ PostgreSQL ืขื ืคื’ื™ืขื•ื™ื•ืช ืฉืชื•ืงื ื•. Odyssey Connection Balancer 1.2 ื™ืฆื ืœืื•ืจ

ื ื•ืฆืจื• ืขื“ื›ื•ื ื™ื ืžืชืงื ื™ื ืขื‘ื•ืจ ื›ืœ ืกื ื™ืคื™ PostgreSQL ื”ื ืชืžื›ื™ื: 14.1, 13.5, 12.9, 11.14, 10.19 ื•-9.6.24. ืฉื—ืจื•ืจ 9.6.24 ื™ื”ื™ื” ื”ืขื“ื›ื•ืŸ ื”ืื—ืจื•ืŸ ืœืกื ื™ืฃ 9.6, ืฉื”ื•ืคืกืง. ืขื“ื›ื•ื ื™ื ืœืกื ื™ืฃ 10 ื™ื•ืคืงื• ืขื“ ื ื•ื‘ืžื‘ืจ 2022, 11 - ืขื“ ื ื•ื‘ืžื‘ืจ 2023, 12 - ืขื“ ื ื•ื‘ืžื‘ืจ 2024, 13 - ืขื“ ื ื•ื‘ืžื‘ืจ 2025, 14 - ืขื“ ื ื•ื‘ืžื‘ืจ 2026.

ื”ื’ืจืกืื•ืช ื”ื—ื“ืฉื•ืช ืžืฆื™ืขื•ืช ื™ื•ืชืจ ืž-40 ืชื™ืงื•ื ื™ื ื•ืžื‘ื˜ืœื•ืช ืฉืชื™ ืคื’ื™ืขื•ื™ื•ืช (CVE-2021-23214, CVE-2021-23222) ื‘ืชื”ืœื™ืš ื”ืฉืจืช ื•ื‘ืกืคืจื™ื™ืช ื”ืœืงื•ื— libpq. ื ืงื•ื“ื•ืช ื”ืชื•ืจืคื” ืžืืคืฉืจื•ืช ืœืชื•ืงืฃ ืœืคืจื•ืฅ ืœืขืจื•ืฅ ืชืงืฉื•ืจืช ืžื•ืฆืคืŸ ื‘ืืžืฆืขื•ืช ืžืชืงืคืช MITM. ื”ื”ืชืงืคื” ืื™ื ื” ื“ื•ืจืฉืช ืื™ืฉื•ืจ SSL ืชืงืฃ ื•ื ื™ืชืŸ ืœื‘ืฆืข ืื•ืชื” ื›ื ื’ื“ ืžืขืจื›ื•ืช ื”ื“ื•ืจืฉื•ืช ืื™ืžื•ืช ืœืงื•ื— ื‘ืืžืฆืขื•ืช ืื™ืฉื•ืจ. ื‘ื”ืงืฉืจ ืฉืœ ื”ืฉืจืช, ื”ืžืชืงืคื” ืžืืคืฉืจืช ืœืš ืœื”ื—ืœื™ืฃ ืฉืื™ืœืชืช SQL ืžืฉืœืš ื‘ื–ืžืŸ ื™ืฆื™ืจืช ื—ื™ื‘ื•ืจ ืžื•ืฆืคืŸ ืžื”ืœืงื•ื— ืœืฉืจืช PostgreSQL. ื‘ื”ืงืฉืจ ืฉืœ libpq, ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืชื•ืงืฃ ืœื”ื—ื–ื™ืจ ืชื’ื•ื‘ืช ืฉืจืช ืžื–ื•ื™ืคืช ืœืœืงื•ื—. ื‘ืฉื™ืœื•ื‘, ื”ืคื’ื™ืขื•ื™ื•ืช ืžืืคืฉืจื•ืช ืœื—ืœืฅ ืžื™ื“ืข ืขืœ ืกื™ืกืžืช ืœืงื•ื— ืื• ื ืชื•ื ื™ื ืจื’ื™ืฉื™ื ืื—ืจื™ื ื”ืžื•ืขื‘ืจื™ื ื‘ืฉืœื‘ ืžื•ืงื“ื ืฉืœ ื”ื—ื™ื‘ื•ืจ.

ื‘ื ื•ืกืฃ, ืื ื• ื™ื›ื•ืœื™ื ืœืฆื™ื™ืŸ ืืช ื”ืคืจืกื•ื ืขืœ ื™ื“ื™ Yandex ืฉืœ ื’ืจืกื” ื—ื“ืฉื” ืฉืœ ืฉืจืช ื”-Proxy Odyssey 1.2, ืฉื ื•ืขื“ื” ืœืฉืžื•ืจ ืขืœ ืžืื’ืจ ืฉืœ ื—ื™ื‘ื•ืจื™ื ืคืชื•ื—ื™ื ืœ-PostgreSQL DBMS ื•ืœืืจื’ืŸ ื ื™ืชื•ื‘ ืฉืื™ืœืชื•ืช. Odyssey ืชื•ืžื›ืช ื‘ื”ืคืขืœืช ืชื”ืœื™ื›ื™ ืขื‘ื•ื“ื” ืžืจื•ื‘ื™ื ืขื ืžื˜ืคืœื™ื ืžืจื•ื‘ื™ ื”ืœื™ื›ื™, ื ื™ืชื•ื‘ ืœืื•ืชื• ืฉืจืช ื›ืืฉืจ ืœืงื•ื— ืžืชื—ื‘ืจ ืžื—ื“ืฉ, ื•ื™ื›ื•ืœืช ืœืงืฉื•ืจ ืžืื’ืจื™ ื—ื™ื‘ื•ืจ ืœืžืฉืชืžืฉื™ื ื•ืœื‘ืกื™ืกื™ ื ืชื•ื ื™ื. ื”ืงื•ื“ ื›ืชื•ื‘ ื‘-C ื•ืžื•ืคืฅ ืชื—ืช ืจื™ืฉื™ื•ืŸ BSD.

ื”ื’ืจืกื” ื”ื—ื“ืฉื” ืฉืœ Odyssey ืžื•ืกื™ืคื” ื”ื’ื ื” ืœื—ืกื™ืžืช ื”ื—ืœืคืช ื ืชื•ื ื™ื ืœืื—ืจ ืžืฉื ื•ืžืชืŸ ืขืœ ื”ืคืขืœืช SSL (ืžืืคืฉืจืช ืœืš ืœื—ืกื•ื ื”ืชืงืคื•ืช ื‘ืืžืฆืขื•ืช ื”ืคื’ื™ืขื•ื™ื•ืช ื”ืžืฆื•ื™ื ื•ืช ืœืขื™ืœ CVE-2021-23214 ื•-CVE-2021-23222). ืชืžื™ื›ื” ืขื‘ื•ืจ PAM ื•-LDAP ื™ื•ืฉืžื”. ื ื•ืกืคื” ืื™ื ื˜ื’ืจืฆื™ื” ืขื ืžืขืจื›ืช ื”ื ื™ื˜ื•ืจ ืฉืœ ืคืจื•ืžืชืื•ืก. ื—ื™ืฉื•ื‘ ืžืฉื•ืคืจ ืฉืœ ืคืจืžื˜ืจื™ื ืกื˜ื˜ื™ืกื˜ื™ื™ื ื›ื“ื™ ืœื”ืชื—ืฉื‘ ื‘ื–ืžื ื™ ื‘ื™ืฆื•ืข ืขืกืงืื•ืช ื•ืฉืื™ืœืชื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”