ืขื“ื›ื•ื ื™ Nginx 1.26.2 ื•-1.27.1 ืขื ื‘ื™ื˜ื•ืœ ืคื’ื™ืขื•ืช DoS ื‘-ngx_http_mp4_module

ื”ืขื ืฃ ื”ืจืืฉื™ ืฉืœ nginx 1.27.1 ืฉื•ื—ืจืจ, ืฉื‘ืชื•ื›ื• ื ืžืฉืš ื”ืคื™ืชื•ื— ืฉืœ ืชื›ื•ื ื•ืช ื—ื“ืฉื•ืช, ื›ืžื• ื’ื ืฉื—ืจื•ืจื• ืฉืœ ื”ืขื ืฃ ื”ื™ืฆื™ื‘ ื”ื ืชืžืš ื”ืžืงื‘ื™ืœ ืฉืœ nginx 1.22.1, ื”ื›ื•ืœืœ ืจืง ืฉื™ื ื•ื™ื™ื ื”ืงืฉื•ืจื™ื ืœื‘ื™ื˜ื•ืœ ืฉื’ื™ืื•ืช ื—ืžื•ืจื•ืช ื• ืคื’ื™ืขื•ืช. ื”ืขื“ื›ื•ื ื™ื ืžืชืงื ื™ื ืคื’ื™ืขื•ืช (CVE-2024-7347) ื‘ืžื•ื“ื•ืœ ngx_http_mp4_module, ืžื” ืฉืžื•ื‘ื™ืœ ืœื”ืคืกืงื” ื—ืจื™ื’ื” ืฉืœ ื–ืจื™ืžืช ื”ืขื‘ื•ื“ื” ื‘ืขืช ืขื™ื‘ื•ื“ ืงื•ื‘ืฅ MP4 ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ื”ื—ืœ ืžื’ืจืกื” 1.5.13 ื‘ืขืช ื‘ื ื™ื™ืช nginx ืขื ืžื•ื“ื•ืœ ngx_http_mp4_module (ืœื ื‘ื ื•ื™ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ) ื•ืฉื™ืžื•ืฉ ื‘ื”ื ื—ื™ื™ืช mp4 ื‘ื”ื’ื“ืจื•ืช. ื›ื“ื™ ืœืชืงืŸ ืืช ื”ืคื’ื™ืขื•ืช ื‘ื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืชื™ืงื•ืŸ.

ื‘ื ื•ืกืฃ ืœืคื’ื™ืขื•ืช, ื”ืžื”ื“ื•ืจื” ืฉืœ nginx 1.27.1 ืชื™ืงื ื” ื’ื ืฉื’ื™ืื•ืช ื‘ื™ื™ืฉื•ื ืคืจื•ื˜ื•ืงื•ืœ HTTP/3, ื”ืขื‘ื™ืจื” ืืช ื”ืžื˜ืคืœ ื‘ืžื•ื“ื•ืœ ื”ื–ืจื ืœืงื˜ื’ื•ืจื™ื” ืฉืœ ืื•ืคืฆื™ื•ื ืœื™, ื•ืคืชืจื” ืืช ื”ื‘ืขื™ื” ื‘ื”ืชืขืœืžื•ืช ืžื—ื™ื‘ื•ืจื™ HTTP/2 ื—ื“ืฉื™ื ื›ืืฉืจ ืชื”ืœื™ื›ื™ ืขื•ื‘ื“ื™ื ืžืกืชื™ื™ืžื™ื ื‘ืฆื•ืจื” ื—ืœืงื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”