Kusagadzikana muSQLite inobvumira kure kure kurwiswa paChrome kuburikidza neWebSQL

Vaongorori vekuchengetedza kubva kukambani yeChinese Tencent yakaunzwa mutsva wekusagadzikana musiyano Magellan (CVE-2019-13734), iyo inokutendera iwe kuti uwane kodhi kuuraya paunenge uchigadzira SQL inovaka yakagadzirwa neimwe nzira muSQLite DBMS. Paiva nekusagadzikana kwakafanana rakabudiswa nevatsvakurudzi vakafanana gore rapfuura. Kusagadzikana kwacho kunoonekwa nekuti kunobvumira munhu kurwisa Chrome browser ari kure uye kuwana kutonga pamusoro peiyo mushandisi sisitimu kana achivhura mapeji ewebhu anodzorwa neanorwisa.

Kurwiswa kweChrome/Chromium kunoitwa kuburikidza neWebSQL API, inobata iyo yakavakirwa paSQLite kodhi. Kurwiswa kwezvimwe zvikumbiro zvinogoneka chete kana vachibvumira kuendeswa kweSQL constructs kubva kunze kuenda kuSQLite, semuenzaniso, vanoshandisa SQLite sechimiro chekuchinjana data. Firefox haina njodzi nekuti Mozilla akaramba kubva pakushandiswa kweWebSQL kubatsirwa IndexedDB API.

Google yakagadzirisa dambudziko mukuburitswa Chrome 79. Paita dambudziko muSQLite codebase fixed Mbudzi 17, uye muChromium codebase - 21 November.
Dambudziko riripo code FTS3 yakazara-zvinyorwa zvekutsvaga injini uye kuburikidza nekunyengedza kwematafura emumvuri (yakakosha mhando yetafura yechokwadi ine kunyora) inogona kutungamirira kune indekisi huwori uye buffer kufashukira. Ruzivo rwakadzama pamusoro pemaitiro ekushandisa anozoburitswa mushure memazuva makumi mapfumbamwe.

Nyowani SQLite kuburitswa nekugadzirisa ikozvino kwete kuumbwa (inotarisirwa kuti Zvita 31). Senzira yekuchengetedza, kutanga neSQLite 3.26.0, SQLite_DBCONFIG_DEFENSIVE modhi inogona kushandiswa, iyo inodzima kunyora kune mimvuri matafura uye inokurudzirwa kuti ibatanidzwe paunenge uchigadzirisa zvekunze SQL mivhunzo muSQLite. Mumakiti ekugovera, kusazvibata muraibhurari yeSQLite kunoramba kusingagadziriswe mukati Debian, Ubuntu, RHEL, vhuraSUSE / SUSE, Arch Linux, Fedora, FreeBSD. Chromium mukugovera kwese yakatogadziridzwa uye haina kukanganiswa nekusagadzikana, asi dambudziko rinogona kukanganisa akasiyana echitatu-bato mabhurawuza uye maapplication anoshandisa injini yeChromium, pamwe nemaapplication eAroid akavakirwa paWebview.

Pamusoro pezvo, matambudziko mana asina njodzi akaonekwawo muSQLite (CVE-2019-13750, CVE-2019-13751, CVE-2019-13752, CVE-2019-13753), izvo zvinogona kutungamirira kune ruzivo rwekubuda uye kutenderera kwezvirambidzo (zvinogona kushandiswa sezvikonzero zvinopa kurwisa Chrome). Nyaya idzi dzakagadziriswa muSQLite kodhi muna Zvita 13. Kutorwa pamwe chete, matambudziko akabvumira vaongorori kugadzirira kushandiswa kwekushanda kunobvumira kodhi kuti iitwe mumamiriro ezvinhu eChromium process ine basa rekupa.

Source: opennet.ru

Voeg