{"id":100167,"date":"2021-05-14T16:23:01","date_gmt":"2021-05-14T14:23:01","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/obnovlenie-postgresql-s-ustraneniem-uyazvimostej"},"modified":"2021-05-14T16:23:01","modified_gmt":"2021-05-14T14:23:01","slug":"obnovlenie-postgresql-s-ustraneniem-uyazvimostej","status":"publish","type":"post","link":"https:\/\/prohoster.info\/pl\/blog\/news\/obnovlenie-postgresql-s-ustraneniem-uyazvimostej","title":{"rendered":"Aktualizacja PostgreSQL z usuni\u0119tymi lukami","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Zosta\u0142y wydane poprawki dla wszystkich wspieranych wersji PostgreSQL: 13.3, 12.7, 11.12, 10.17 i 9.6.22. Aktualizacje dla wersji 9.6 b\u0119d\u0105 tworzone do listopada 2021 roku, 10 \u2014 do listopada 2022 roku, 11 \u2014 do listopada 2023 roku, 12 \u2014 do listopada 2024 roku, 13 do listopada 2025 roku. W nowych wydaniach usuni\u0119to trzy luki bezpiecze\u0144stwa i naprawiono zgromadzone b\u0142\u0119dy.    <\/p>\n<p> Podatno\u015b\u0107 CVE-2021-32027 mo\u017ce prowadzi\u0107 do zapisu danych poza granicami bufora, spowodowanego przepe\u0142nieniem ca\u0142kowitym przy obliczaniu indeks\u00f3w tablic. Poprzez manipulacj\u0119 warto\u015bciami tablic w zapytaniach SQL, atakuj\u0105cy, kt\u00f3ry ma dost\u0119p do wykonywania zapyta\u0144 SQL, mo\u017ce zapisa\u0107 dowolne dane w dowolnym obszarze pami\u0119ci procesu i uzyska\u0107 wykonanie swojego kodu z odpowiednimi uprawnieniami. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/pl\/server\/dts-los-angeles\/\"   title=\"serwery\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3715\">serwery<\/a> DBMS. Dwie inne luki (CVE-2021-32028, CVE-2021-32029) prowadz\u0105 do ujawnienia zawarto\u015bci pami\u0119ci procesu podczas manipulacji zapytaniami \u201eINSERT \u2026 ON CONFLICT \u2026 DO UPDATE\u201d oraz \u201eUPDATE \u2026 RETURNING\u201d.    <\/p>\n<p>Z niezwi\u0105zanych z podatno\u015bciami poprawek mo\u017cna wskaza\u0107:  <\/p>\n<ul>\n<li class=\"l\"> Usuni\u0119cie nieprawid\u0142owych oblicze\u0144 podczas wykonywania \u201eUPDATE \u2026 RETURNING\u201d dla aktualizacji po\u0142\u0105czonych tabel segmentowanych.\n<li class=\"l\"> Usuni\u0119cie b\u0142\u0119du polecenia \u201eALTER TABLE \u2026 ALTER CONSTRAINT\u201d w przypadku istnienia ogranicze\u0144 dla kluczy obcych w po\u0142\u0105czeniu z u\u017cywaniem tabel segmentowanych.\n<li class=\"l\"> Usprawnienie funkcjonalno\u015bci \u201eCOMMIT AND CHAIN\u201d.\n<li class=\"l\"> Dla nowych wyda\u0144 FreeBSD zapewniono domy\u015blne ustawienie trybu fdatasync w thatwal_sync_method.\n<li class=\"l\"> Domy\u015blnie wy\u0142\u0105czono parametr vacuum_cleanup_index_scale_factor.\n<li class=\"l\"> Naprawiono wycieki pami\u0119ci, kt\u00f3re wyst\u0119powa\u0142y podczas inicjalizacji po\u0142\u0105cze\u0144 TLS.\n<li class=\"l\"> W pg_upgrade dodano dodatkowe kontrole na obecno\u015b\u0107 typ\u00f3w danych w tabelach u\u017cytkownik\u00f3w, kt\u00f3re nie mog\u0105 by\u0107 aktualizowane.  <\/ul>\n<p>\u0179r\u00f3d\u0142o: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55148\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0432\u0441\u0435\u0445 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0432\u0435\u0442\u043e\u043a PostgreSQL: 13.3, 12.7, 11.12, 10.17 \u0438 9.6.22. \u041e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0432\u0435\u0442\u043a\u0438 9.6 \u0431\u0443\u0434\u0443\u0442 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u043e \u043d\u043e\u044f\u0431\u0440\u044f 2021 \u0433\u043e\u0434\u0430, 10 &#8212; \u0434\u043e \u043d\u043e\u044f\u0431\u0440\u044f 2022 \u0433\u043e\u0434\u0430, 11 &#8212; \u0434\u043e \u043d\u043e\u044f\u0431\u0440\u044f 2023 \u0433\u043e\u0434\u0430, 12 &#8212; \u0434\u043e \u043d\u043e\u044f\u0431\u0440\u044f 2024 \u0433\u043e\u0434\u0430, 13 \u0434\u043e \u043d\u043e\u044f\u0431\u0440\u044f 2025 \u0433\u043e\u0434\u0430. \u0412 \u043d\u043e\u0432\u044b\u0445 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0442\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0438 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u044b [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-100167","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0432\u0441\u0435\u0445 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0432\u0435\u0442\u043e\u043a PostgreSQL: 13.3, 12.7, 11.12, 10.17 \u0438 9.6.22.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/pl\/blog\/news\/obnovlenie-postgresql-s-ustraneniem-uyazvimostej\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"pl_PL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 PostgreSQL \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0432\u0441\u0435\u0445 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0432\u0435\u0442\u043e\u043a PostgreSQL: 13.3, 12.7, 11.12, 10.17 \u0438 9.6.22.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/pl\/blog\/news\/obnovlenie-postgresql-s-ustraneniem-uyazvimostej\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-05-14T14:23:01+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-05-14T14:23:01+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Aktualizacja PostgreSQL z usuni\u0119tymi podatno\u015bciami | ProHoster","description":"Opracowano poprawki dla wszystkich wspieranych ga\u0142\u0119zi PostgreSQL: 13.3, 12.7, 11.12, 10.17 i 9.6.22.","canonical_url":"https:\/\/prohoster.info\/pl\/blog\/news\/obnovlenie-postgresql-s-ustraneniem-uyazvimostej","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"pl_PL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 PostgreSQL \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 | ProHoster","og:description":"\u0421\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u044b \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0432\u0441\u0435\u0445 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u0432\u0435\u0442\u043e\u043a PostgreSQL: 13.3, 12.7, 11.12, 10.17 \u0438 9.6.22.","og:url":"https:\/\/prohoster.info\/pl\/blog\/news\/obnovlenie-postgresql-s-ustraneniem-uyazvimostej","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-05-14T14:23:01+00:00","article:modified_time":"2021-05-14T14:23:01+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"100167","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-05-14 21:05:32","updated":"2026-02-22 15:30:17","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/100167","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/comments?post=100167"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/100167\/revisions"}],"predecessor-version":[{"id":162243,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/100167\/revisions\/162243"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/media?parent=100167"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/categories?post=100167"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/tags?post=100167"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}