ืžื”ื“ื•ืจื” ื™ืฆื™ื‘ื” ืฉืœ ืฉืจืช ื”-proxy Squid 5

ืœืื—ืจ ืฉืœื•ืฉ ืฉื ื™ื ืฉืœ ืคื™ืชื•ื—, ื”ื•ืฆื’ื” ืžื”ื“ื•ืจื” ื™ืฆื™ื‘ื” ืฉืœ ืฉืจืช ื”-Proxy Squid 5.1, ืžื•ื›ื ื” ืœืฉื™ืžื•ืฉ ื‘ืžืขืจื›ื•ืช ื™ื™ืฆื•ืจ (ื’ืจืกืื•ืช 5.0.x ื”ื™ื• ื‘ืกื˜ื˜ื•ืก ืฉืœ ื’ืจืกืื•ืช ื‘ื˜ื). ืœืื—ืจ ืฉืขื ืฃ 5.x ืงื™ื‘ืœ ืกื˜ื˜ื•ืก ื™ืฆื™ื‘, ืžืขืชื” ื•ืื™ืœืš ื™ื‘ื•ืฆืขื• ื‘ื• ืจืง ืชื™ืงื•ื ื™ื ืœืคืจืฆื•ืช ื•ื‘ืขื™ื•ืช ื™ืฆื™ื‘ื•ืช, ื•ืžืืคืฉืจื•ืช ื’ื ืื•ืคื˜ื™ืžื™ื–ืฆื™ื•ืช ืงืœื•ืช. ืคื™ืชื•ื— ืชื›ื•ื ื•ืช ื—ื“ืฉื•ืช ื™ืชื‘ืฆืข ื‘ืขื ืฃ ื”ื ื™ืกื•ื™ ื”ื—ื“ืฉ 6.0. ืœืžืฉืชืžืฉื™ื ื‘ืกื ื™ืฃ ื”ื™ืฆื™ื‘ ื”ืงื•ื“ื ืฉืœ 4.x ืžื•ืžืœืฅ ืœืชื›ื ืŸ ืžืขื‘ืจ ืœืกื ื™ืฃ 5.x.

ื—ื™ื“ื•ืฉื™ื ืžืจื›ื–ื™ื™ื ื‘-Squid 5:

  • ื”ื˜ืžืขืช ื”-ICAP (Internet Content Adaptation Protocol), ื”ืžืฉืžืฉ ืœืื™ื ื˜ื’ืจืฆื™ื” ืขื ืžืขืจื›ื•ืช ืื™ืžื•ืช ืชื•ื›ืŸ ื—ื™ืฆื•ื ื™ื•ืช, ื”ื•ืกื™ืคื” ืชืžื™ื›ื” ื‘ืžื ื’ื ื•ืŸ ืฆื™ืจื•ืฃ ื ืชื•ื ื™ื (ื˜ืจื™ื™ืœืจ), ื”ืžืืคืฉืจ ืœืฆืจืฃ ื›ื•ืชืจื•ืช ื ื•ืกืคื•ืช ืขื ืžื˜ื ื ืชื•ื ื™ื ืœืชื’ื•ื‘ื”, ื”ืžื•ืฆื‘ื•ืช ืœืื—ืจ ื”ื”ื•ื“ืขื” body (ืœื“ื•ื’ืžื”, ืืชื” ื™ื›ื•ืœ ืœืฉืœื•ื— ืกื›ื•ื ื‘ื“ื™ืงื” ื•ืคืจื˜ื™ื ืขืœ ื”ื‘ืขื™ื•ืช ืฉื–ื•ื”ื•).
  • ื‘ืขืช ื”ืคื ื™ื™ืช ื‘ืงืฉื•ืช, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืืœื’ื•ืจื™ืชื "Happy Eyeballs", ืืฉืจ ืžืฉืชืžืฉ ื‘ืื•ืคืŸ ืžื™ื™ื“ื™ ื‘ื›ืชื•ื‘ืช ื”-IP ื”ืžืชืงื‘ืœืช, ืžื‘ืœื™ ืœื”ืžืชื™ืŸ ืœืคืชืจื•ืŸ ื›ืœ ื›ืชื•ื‘ื•ืช ื”ื™ืขื“ ื”ืคื•ื˜ื ืฆื™ืืœื™ื•ืช ืฉืœ IPv4 ื•-IPv6. ื‘ืžืงื•ื ืœื”ืฉืชืžืฉ ื‘ื”ื’ื“ืจื” "dns_v4_first" ื›ื“ื™ ืœืงื‘ื•ืข ืื ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžืฉืคื—ืช ื›ืชื•ื‘ื•ืช IPv4 ืื• IPv6, ืกื“ืจ ืชื’ื•ื‘ืช ื”-DNS ื ืœืงื— ื›ืขืช ื‘ื—ืฉื‘ื•ืŸ: ืื ืชื’ื•ื‘ืช ื”-DNS AAAA ืžื’ื™ืขื” ืจืืฉื•ื ื” ื›ืืฉืจ ืžืžืชื™ื ื™ื ืœืคืชืจื•ืŸ ื›ืชื•ื‘ืช IP, ืื–ื™ ื™ื™ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื›ืชื•ื‘ืช IPv6 ืฉื”ืชืงื‘ืœื”. ืœืคื™ื›ืš, ื”ื’ื“ืจืช ืžืฉืคื—ืช ื”ื›ืชื•ื‘ื•ืช ื”ืžื•ืขื“ืคืช ืžืชื‘ืฆืขืช ื›ืขืช ื‘ืจืžืช ื—ื•ืžืช ื”ืืฉ, ื”-DNS ืื• ื”ื”ืคืขืœื” ืขื ื”ืืคืฉืจื•ืช "--disable-ipv6". ื”ืฉื™ื ื•ื™ ื”ืžื•ืฆืข ืžืืคืฉืจ ืœื ื• ืœื”ืื™ืฅ ืืช ื–ืžืŸ ื”ื”ื’ื“ืจื” ืฉืœ ื—ื™ื‘ื•ืจื™ TCP ื•ืœื”ืคื—ื™ืช ืืช ื”ืฉืคืขืช ื”ื‘ื™ืฆื•ืขื™ื ืฉืœ ืขื™ื›ื•ื‘ื™ื ื‘ืžื”ืœืš ืคืชืจื•ืŸ DNS.
  • ืœืฉื™ืžื•ืฉ ื‘ื”ื ื—ื™ื™ืช "external_acl", ื”ืžื˜ืคืœ "ext_kerberos_sid_group_acl" ื ื•ืกืฃ ืœืฆื•ืจืš ืื™ืžื•ืช ืขื ื‘ื“ื™ืงื” ืงื‘ื•ืฆืชื™ืช ื‘-Active Directory ื‘ืืžืฆืขื•ืช Kerberos. ื›ื“ื™ ืœืฉืื•ืœ ืืช ืฉื ื”ืงื‘ื•ืฆื”, ื”ืฉืชืžืฉ ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช ldapsearch ื”ืžืกื•ืคืง ืขืœ ื™ื“ื™ ื—ื‘ื™ืœืช OpenLDAP.
  • ื”ืชืžื™ื›ื” ื‘ืคื•ืจืžื˜ Berkeley DB ื”ื•ืฆืื” ืžืฉื™ืžื•ืฉ ืขืงื‘ ื‘ืขื™ื•ืช ืจื™ืฉื•ื™. ืกื ื™ืฃ Berkeley DB 5.x ืื™ื ื• ืžืชื•ื—ื–ืง ื‘ืžืฉืš ืžืกืคืจ ืฉื ื™ื ื•ื ืฉืืจ ืขื ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืœืœื ืชื™ืงื•ืŸ, ื•ื”ืžืขื‘ืจ ืœืžื”ื“ื•ืจื•ืช ื—ื“ืฉื•ืช ื™ื•ืชืจ ื ืžื ืข ืขืœ ื™ื“ื™ ืฉื™ื ื•ื™ ืจื™ืฉื™ื•ืŸ ืœ-AGPLv3, ืฉื“ืจื™ืฉื•ืชื™ื• ื—ืœื•ืช ื’ื ืขืœ ืืคืœื™ืงืฆื™ื•ืช ื”ืžืฉืชืžืฉื•ืช ื‘-BerkeleyDB ื‘ืฆื•ืจื” ืฉืœ ืกืคืจื™ื™ื” - Squid ืžืกื•ืคืง ืชื—ืช ืจื™ืฉื™ื•ืŸ GPLv2, ื•-AGPL ืื™ื ื• ืชื•ืื ืœ-GPLv2. ื‘ืžืงื•ื Berkeley DB, ื”ืคืจื•ื™ืงื˜ ื”ื•ืขื‘ืจ ืœืฉื™ืžื•ืฉ ื‘-TrivialDB DBMS, ืฉื‘ื ื™ื’ื•ื“ ืœ-Berkeley DB, ืžื•ืชืื ืœื’ื™ืฉื” ืžืงื‘ื™ืœื” ืกื™ืžื•ืœื˜ื ื™ืช ืœืžืกื“ ื”ื ืชื•ื ื™ื. ื”ืชืžื™ื›ื” ื‘-Berkeley DB ื ืฉืžืจืช ืœืขืช ืขืชื”, ืืš ื”ืžื˜ืคืœื™ื "ext_session_acl" ื•-"ext_time_quota_acl" ืžืžืœื™ืฆื™ื ื›ืขืช ืœื”ืฉืชืžืฉ ื‘ืกื•ื’ ื”ืื—ืกื•ืŸ "libtdb" ื‘ืžืงื•ื "libdb".
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ื›ื•ืชืจืช CDN-Loop HTTP, ื”ืžื•ื’ื“ืจืช ื‘-RFC 8586, ื”ืžืืคืฉืจืช ืœืš ืœื–ื”ื•ืช ืœื•ืœืื•ืช ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืจืฉืชื•ืช ืืกืคืงืช ืชื•ื›ืŸ (ื”ื›ื•ืชืจืช ืžืกืคืงืช ื”ื’ื ื” ืžืคื ื™ ืžืฆื‘ื™ื ืฉื‘ื”ื ื‘ืงืฉื” ื‘ืชื”ืœื™ืš ืฉืœ ื”ืคื ื™ื™ื” ื‘ื™ืŸ CDN ืžืกื™ื‘ื” ื›ืœืฉื”ื™ ื—ื•ื–ืจืช ื—ื–ืจื” ืœ- CDN ืžืงื•ืจื™, ื™ื•ืฆืจ ืœื•ืœืื” ืื™ื ืกื•ืคื™ืช).
  • ืžื ื’ื ื•ืŸ SSL-Bump, ื”ืžืืคืฉืจ ืœื™ื™ืจื˜ ืืช ื”ืชื•ื›ืŸ ืฉืœ ื”ืคืขืœื•ืช HTTPS ืžื•ืฆืคื ื•ืช, ื”ื•ืกื™ืฃ ืชืžื™ื›ื” ืœื”ืคื ื™ื” ืžื—ื“ืฉ ืฉืœ ื‘ืงืฉื•ืช HTTPS ืžื–ื•ื™ืคื•ืช (ืžื•ืฆืคื ื•ืช ืžื—ื“ืฉ) ื“ืจืš ืฉืจืชื™ ืคืจื•ืงืกื™ ืื—ืจื™ื ื”ืžืฆื•ื™ื ื™ื ื‘-cache_peer, ื‘ืืžืฆืขื•ืช ืžื ื”ืจื” ืจื’ื™ืœื” ื”ืžื‘ื•ืกืกืช ืขืœ ืฉื™ื˜ืช HTTP CONNECT ( ืฉื™ื“ื•ืจ ื‘ืืžืฆืขื•ืช HTTPS ืื™ื ื• ื ืชืžืš, ืžื›ื™ื•ื•ืŸ ืฉ-Squid ืขื“ื™ื™ืŸ ืื™ื ื• ื™ื›ื•ืœ ืœื”ืขื‘ื™ืจ TLS ื‘ืชื•ืš TLS). SSL-Bump ืžืืคืฉืจ ืœืš ืœื™ืฆื•ืจ ื—ื™ื‘ื•ืจ TLS ืขื ืฉืจืช ื”ื™ืขื“ ืขื ืงื‘ืœืช ื‘ืงืฉืช ื”-HTPS ื”ืจืืฉื•ื ื” ืฉื™ื™ืจื˜ื• ื•ืœืงื‘ืœ ืืช ื”ืื™ืฉื•ืจ ืฉืœื•. ืœืื—ืจ ืžื›ืŸ, Squid ืžืฉืชืžืฉ ื‘ืฉื ื”ืžืืจื— ืžื”ืชืขื•ื“ื” ื”ืืžื™ืชื™ืช ืฉื”ืชืงื‘ืœื” ืžื”ืฉืจืช ื•ื™ื•ืฆืจ ืชืขื•ื“ืช ื“ืžื”, ืฉืื™ืชื” ื”ื•ื ืžื—ืงื” ืืช ื”ืฉืจืช ื”ืžื‘ื•ืงืฉ ื‘ืขืช ืื™ื ื˜ืจืืงืฆื™ื” ืขื ื”ืœืงื•ื—, ืชื•ืš ืฉื”ื•ื ืžืžืฉื™ืš ืœื”ืฉืชืžืฉ ื‘ื—ื™ื‘ื•ืจ TLS ืฉื ื•ืฆืจ ืขื ืฉืจืช ื”ื™ืขื“ ื›ื“ื™ ืœืงื‘ืœ ื ืชื•ื ื™ื ( ื›ื“ื™ ืฉื”ื”ื—ืœืคื” ืœื ืชื•ื‘ื™ืœ ืœืื–ื”ืจื•ืช ื”ืคืœื˜ ื‘ื“ืคื“ืคื ื™ื ื‘ืฆื“ ื”ืœืงื•ื—, ืขืœื™ืš ืœื”ื•ืกื™ืฃ ืืช ื”ืื™ืฉื•ืจ ืฉืœืš ื”ืžืฉืžืฉ ืœื”ืคืงืช ืื™ืฉื•ืจื™ื ืคื™ืงื˜ื™ื‘ื™ื™ื ืœืžืื’ืจ ืชืขื•ื“ื•ืช ื”ืฉื•ืจืฉ).
  • ื ื•ืกืคื• ื”ื ื—ื™ื•ืช mark_client_connection ื•-mark_client_pack ื›ื“ื™ ืœืื’ื“ ืกื™ืžื ื™ Netfilter (CONNMARK) ืœื—ื™ื‘ื•ืจื™ TCP ืฉืœ ื”ืœืงื•ื— ืื• ืžื ื•ืช ื‘ื•ื“ื“ื•ืช.

ื—ืžื•ืช ืขืœ ืขืงื‘ื•ืชื™ื”ื, ืคื•ืจืกืžื• ื”ื’ืจืกืื•ืช ืฉืœ Squid 5.2 ื•- Squid 4.17, ื‘ื”ืŸ ืชื•ืงื ื• ื”ืคื’ื™ืขื•ื™ื•ืช:

  • CVE-2021-28116 - ื“ืœื™ืคืช ืžื™ื“ืข ื‘ืขืช ืขื™ื‘ื•ื“ ื”ื•ื“ืขื•ืช WCCPv2 ื‘ืขืœื™ ืžื‘ื ื” ืžื™ื•ื—ื“. ื”ืคื’ื™ืขื•ืช ืžืืคืฉืจืช ืœืชื•ืงืฃ ืœื”ืฉื—ื™ืช ืืช ืจืฉื™ืžืช ื”ื ืชื‘ื™ื ื”ื™ื“ื•ืขื™ื ืฉืœ WCCP ื•ืœื”ืคื ื•ืช ืชืขื‘ื•ืจื” ืžืœืงื•ื—ื•ืช ืฉืจืช ืคืจื•ืงืกื™ ืืœ ื”ืžืืจื— ืฉืœื”ื. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืจืง ื‘ืชืฆื•ืจื•ืช ืขื ืชืžื™ื›ื” ื‘-WCCPv2 ืžื•ืคืขืœืช ื•ื›ืืฉืจ ื ื™ืชืŸ ืœื–ื™ื™ืฃ ืืช ื›ืชื•ื‘ืช ื”-IP ืฉืœ ื”ื ืชื‘.
  • CVE-2021-41611 - ื‘ืขื™ื” ื‘ืื™ืžื•ืช ืื™ืฉื•ืจ TLS ืžืืคืฉืจืช ื’ื™ืฉื” ื‘ืืžืฆืขื•ืช ืื™ืฉื•ืจื™ื ืœื ืžื”ื™ืžื ื™ื.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”