ืฉื—ืจื•ืจ ืฉืœ ืฉืจืช http Apache 2.4.52 ืขื ืชื™ืงื•ืŸ ื’ืœื™ืฉืช ืžืื’ืจ ื‘-mod_lua

ืฉืจืช ื”-HTTP ืฉืœ Apache 2.4.52 ืฉื•ื—ืจืจ, ืžืฆื™ื’ 25 ืฉื™ื ื•ื™ื™ื ื•ืžื‘ื˜ืœ 2 ืคื’ื™ืขื•ื™ื•ืช:

  • CVE-2021-44790 ื”ื•ื ื’ืœื™ืฉืช ืžืื’ืจ ื‘-mod_lua ื”ืžืชืจื—ืฉืช ื‘ืขืช ื ื™ืชื•ื— ื‘ืงืฉื•ืช ืžืจื•ื‘ื™ ื—ืœืง. ื”ืคื’ื™ืขื•ืช ืžืฉืคื™ืขื” ืขืœ ืชืฆื•ืจื•ืช ืฉื‘ื”ืŸ ืกืงืจื™ืคื˜ื™ื ืฉืœ Lua ืงื•ืจืื™ื ืœืคื•ื ืงืฆื™ื” r:parsebody() ื›ื“ื™ ืœื ืชื— ืืช ื’ื•ืฃ ื”ื‘ืงืฉื”, ืžื” ืฉืžืืคืฉืจ ืœืชื•ืงืฃ ืœื’ืจื•ื ืœื’ืœื™ืฉื” ื‘ืžืื’ืจ ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื” ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“. ืขื“ื™ื™ืŸ ืœื ื–ื•ื”ื• ืขื“ื•ืช ืœื ื™ืฆื•ืœ, ืืš ื”ื‘ืขื™ื” ืขืœื•ืœื” ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœื” ื‘ืฉืจืช.
  • CVE-2021-44224 - ืคื’ื™ืขื•ืช SSRF (Server Side Request Forgery) ื‘-mod_proxy, ื”ืžืืคืฉืจืช, ื‘ืชืฆื•ืจื•ืช ืขื ื”ื”ื’ื“ืจื” "ProxyRequests on", ื‘ืืžืฆืขื•ืช ื‘ืงืฉื” ืœ-URI ืฉืชื•ื›ื ืŸ ื‘ืžื™ื•ื—ื“, ืœื”ืฉื™ื’ ื”ืคื ื™ื™ืช ื‘ืงืฉื” ืœืžื˜ืคืœ ืื—ืจ ื‘ืื•ืชื• ืฉืจืช ืฉืžืงื‘ืœ ื—ื™ื‘ื•ืจื™ื ื“ืจืš ืฉืงืข ืชื—ื•ื Unix. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื‘ืขื™ื” ื’ื ื›ื“ื™ ืœื’ืจื•ื ืœืงืจื™ืกื” ืขืœ ื™ื“ื™ ื™ืฆื™ืจืช ื”ืชื ืื™ื ืœื”ืคื ื™ื™ืช ืžืฆื‘ื™ืข ืืคืก. ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืขืœ ื’ืจืกืื•ืช ืฉืœ Apache httpd ื”ื—ืœ ืžื’ืจืกื” 2.4.7.

ื”ืฉื™ื ื•ื™ื™ื ื”ื‘ื•ืœื˜ื™ื ืฉืื™ื ื ื‘ื™ื˜ื—ื•ื ื™ื™ื ื”ื:

  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ื‘ื ื™ื™ื” ืขื ืกืคืจื™ื™ืช OpenSSL 3 ืœ-mod_ssl.
  • ื–ื™ื”ื•ื™ ืกืคืจื™ื™ืช OpenSSL ืžืฉื•ืคืจ ื‘ืกืงืจื™ืคื˜ื™ื ืื•ื˜ื•ืžื˜ื™ื™ื.
  • ื‘-mod_proxy, ืœืคืจื•ื˜ื•ืงื•ืœื™ ืžื ื”ื•ืจ, ื ื™ืชืŸ ืœื‘ื˜ืœ ื ื™ืชื•ื‘ ืžื—ื“ืฉ ืฉืœ ื—ื™ื‘ื•ืจื™ TCP ื—ืฆื™ ืกื’ื•ืจื™ื ืขืœ ื™ื“ื™ ื”ื’ื“ืจืช ื”ืคืจืžื˜ืจ "SetEnv proxy-nohalfclose".
  • ื ื•ืกืคื• ื‘ื“ื™ืงื•ืช ื ื•ืกืคื•ืช ืœื›ืš ืฉ-URI ืฉืื™ื ื ืžื™ื•ืขื“ื™ื ืœ-proxy ืžื›ื™ืœื™ื ืืช ืกื›ื™ืžืช http/https, ื•ืืœื” ื”ืžื™ื•ืขื“ื™ื ืœ-proxy ืžื›ื™ืœื™ื ืืช ืฉื ื”ืžืืจื—.
  • mod_proxy_connect ื•-mod_proxy ืื™ื ื ืžืืคืฉืจื™ื ืœืฉื ื•ืช ืืช ืงื•ื“ ื”ืกื˜ื˜ื•ืก ืœืื—ืจ ืฉื ืฉืœื— ืœืœืงื•ื—.
  • ื‘ืขืช ืฉืœื™ื—ืช ืชื’ื•ื‘ื•ืช ื‘ื™ื ื™ื™ื ืœืื—ืจ ืงื‘ืœืช ื‘ืงืฉื•ืช ืขื ื”ื›ื•ืชืจืช "ืฆืคื•: 100-ื”ืžืฉืš", ื•ื“ื ืฉื”ืชื•ืฆืื” ืžืฆื™ื™ื ืช ืืช ื”ืžืฆื‘ ืฉืœ "ื”ืžืฉืš 100" ื•ืœื ืืช ื”ืžืฆื‘ ื”ื ื•ื›ื—ื™ ืฉืœ ื”ื‘ืงืฉื”.
  • mod_dav ืžื•ืกื™ืฃ ืชืžื™ื›ื” ื‘ื”ืจื—ื‘ื•ืช CalDAV, ื”ืžื—ื™ื™ื‘ื•ืช ืœืงื—ืช ื‘ื—ืฉื‘ื•ืŸ ื’ื ืจื›ื™ื‘ื™ ืžืกืžืš ื•ื’ื ืจื›ื™ื‘ื™ ื ื›ืก ื‘ืขืช ื™ืฆื™ืจืช ื ื›ืก. ื ื•ืกืคื• ืคื•ื ืงืฆื™ื•ืช ื—ื“ืฉื•ืช dav_validate_root_ns(), dav_find_child_ns(), dav_find_next_ns(), dav_find_attr_ns() ื•-dav_find_attr(), ืืฉืจ ื ื™ืชืŸ ืœืงืจื•ื ืžืžื•ื“ื•ืœื™ื ืื—ืจื™ื.
  • ื‘-mpm_event, ื”ื‘ืขื™ื” ืขื ืขืฆื™ืจืช ืชื”ืœื™ื›ื™ ืฆืืฆื ืกืจืง ืœืื—ืจ ืขืœื™ื™ื” ื‘ืขื•ืžืก ื”ืฉืจืช ื ืคืชืจื”.
  • ืœ-Mod_http2 ื™ืฉ ืฉื™ื ื•ื™ื™ ืจื’ืจืกื™ื” ืงื‘ื•ืขื™ื ืฉื’ืจืžื• ืœื”ืชื ื”ื’ื•ืช ืฉื’ื•ื™ื” ื‘ืขืช ื˜ื™ืคื•ืœ ื‘ื”ื’ื‘ืœื•ืช MaxRequestsPerChild ื•- MaxConnectionsPerChild.
  • ื”ื™ื›ื•ืœื•ืช ืฉืœ ืžื•ื“ื•ืœ mod_md, ื”ืžืฉืžืฉ ืœืื•ื˜ื•ืžื˜ื™ื•ืช ืฉืœ ืงื‘ืœื” ื•ืชื—ื–ื•ืงื” ืฉืœ ืื™ืฉื•ืจื™ื ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ ACME (ืกื‘ื™ื‘ื” ืื•ื˜ื•ืžื˜ื™ืช ืœื ื™ื”ื•ืœ ืชืขื•ื“ื•ืช), ื”ื•ืจื—ื‘ื•:
    • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืžื ื’ื ื•ืŸ ACME External Account Binding (EAB), ื”ืžื•ืคืขืœ ื‘ืืžืฆืขื•ืช ื”ื•ืจืืช MDExternalAccountBinding. ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืขืจื›ื™ื ืขื‘ื•ืจ EAB ืžืงื•ื‘ืฅ JSON ื—ื™ืฆื•ื ื™, ืชื•ืš ื”ื™ืžื ืขื•ืช ืžื—ืฉื™ืคืช ืคืจืžื˜ืจื™ ืื™ืžื•ืช ื‘ืงื•ื‘ืฅ ืชืฆื•ืจืช ื”ืฉืจืช ื”ืจืืฉื™.
    • ื”ื”ื ื—ื™ื” 'MDCertificateAuthority' ืžื‘ื˜ื™ื—ื” ืฉืคืจืžื˜ืจ ื›ืชื•ื‘ืช ื”ืืชืจ ืžื›ื™ืœ http/https ืื• ืื—ื“ ืžื”ืฉืžื•ืช ื”ืžื•ื’ื“ืจื™ื ืžืจืืฉ ('LetsEncrypt', 'LetsEncrypt-Test', 'Buypass' ื•-'Buypass-Test').
    • ืžื•ืชืจ ืœืฆื™ื™ืŸ ืืช ื”ื ื—ื™ื™ืช MDContactEmail ื‘ืชื•ืš ื”ืงื˜ืข .
    • ืžืกืคืจ ื‘ืื’ื™ื ืชื•ืงื ื•, ื›ื•ืœืœ ื“ืœื™ืคืช ื–ื™ื›ืจื•ืŸ ื”ืžืชืจื—ืฉืช ื›ืืฉืจ ื˜ืขื™ื ืช ืžืคืชื— ืคืจื˜ื™ ื ื›ืฉืœืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”