ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ SQLite ืึทื– ืึทืœืึทื•ื– ื•ื•ื™ื™ึทื˜ ืื ืคืืœืŸ ืื•ื™ืฃ ืงืจืึธื•ื ื“ื•ืจืš WebSQL

ื–ื™ื›ืขืจื”ื™ื™ื˜ ืจื™ืกืขืจื˜ืฉืขืจื– ืคื•ืŸ ื“ื™ ื›ื™ื ืขื–ื™ืฉ ืคื™ืจืžืข Tencent ื“ืขืจืœืื ื’ื˜ ื ื™ื™ึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื•ื•ืึทืจื™ืึทื ื˜ ืžืึทื’ืขืœืœืึทืŸ (CVE-2019-13734), ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื“ืขืจื’ืจื™ื™ื›ืŸ ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืกืงืœ ืงืึทื ืกื˜ืจืึทืงืฉืึทื ื– ื“ื™ื–ื™ื™ื ื“ ืื™ืŸ ืึท ื–ื™ื›ืขืจ ื•ื•ืขื’ ืื™ืŸ ื“ื™ SQLite DBMS. ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ืึท ืขื ืœืขืš ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืืจื•ื™ืก ื“ื•ืจืš ื“ื™ ื–ืขืœื‘ืข ืจื™ืกืขืจื˜ืฉืขืจื– ืžื™ื˜ ืึท ื™ืึธืจ ืฆื•ืจื™ืง. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื ืึธื•ื˜ืึทื‘ืึทืœ ืื™ืŸ ืึทื– ืขืก ืึทืœืึทื•ื– ืื™ื™ื ืขืจ ืฆื• ืจื™ืžืึธื•ื˜ืœื™ ื‘ืึทืคืึทืœืŸ ื“ื™ ืงืจืึธื•ื ื‘ืœืขื˜ืขืจืขืจ ืื•ืŸ ื“ืขืจื’ืจื™ื™ื›ืŸ ืงืึธื ื˜ืจืึธืœ ืื™ื‘ืขืจ ื“ื™ ื‘ืึทื ื™ืฆืขืจ 'ืก ืกื™ืกื˜ืขื ื•ื•ืขืŸ ืขืคืŸ ื•ื•ืขื‘ ื–ื™ื™ึทื˜ืœืขืš ืงืึทื ื˜ืจืึธื•ืœื“ ื“ื•ืจืš ื“ื™ ืึทื˜ืึทืงืขืจ.

ื“ื™ ื‘ืึทืคืึทืœืŸ ืื•ื™ืฃ ืงืจืึธื•ื / ืงืจืึธื•ืžื™ืึทื ืื™ื– ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ื“ื•ืจืš ื“ื™ WebSQL API, ื“ื™ ื”ืึทื ื“ืœืขืจ ืคื•ืŸ ื•ื•ืึธืก ืื™ื– ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ SQLite ืงืึธื“. ืึท ื‘ืึทืคืึทืœืŸ ืื•ื™ืฃ ืื ื“ืขืจืข ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ืื™ื– ื‘ืœื•ื™ื– ืžืขื’ืœืขืš ืื•ื™ื‘ ื–ื™ื™ ืœืึธื–ืŸ ื“ื™ ืึทืจื™ื‘ืขืจืคื™ืจืŸ ืคื•ืŸ SQL ืงืึทื ืกื˜ืจืึทืงื˜ืขืจื– ืคึฟื•ืŸ ืึทืจื•ื™ืก ืฆื• SQLite, ืœืžืฉืœ, ื–ื™ื™ ื ื•ืฆืŸ SQLite ื•ื•ื™ ืึท ืคึฟืึธืจืžืึทื˜ ืคึฟืึทืจ ื“ืึทื˜ืŸ ื•ื•ืขืงืกืœ. ืคื™ืจืขืคืึธืงืก ืื™ื– ื ื™ืฉื˜ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ื•ื•ื™ื™ึทืœ ืžืึธื–ื™ืœืœืึท ืืคื’ืขื–ืื’ื˜ ืคึฟื•ืŸ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ WebSQL ื ื•ืฅ IndexedDB API.

Google ืคืึทืจืคืขืกื˜ื™ืงื˜ ื“ืขื ืึทืจื•ื™ืกื’ืขื‘ืŸ ืื™ืŸ ืžืขืœื“ื•ื ื’ ืงืจืึธื•ื ืงืกื ื•ืžืงืก. ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ืึท ืคึผืจืึธื‘ืœืขื ืื™ืŸ ื“ื™ SQLite ืงืึธื“ืขื‘ืึทืกืข ืคืึทืจืคืขืกื˜ื™ืงื˜ 17 ื ืื•ื•ืขืžื‘ืขืจ, ืื•ืŸ ืื™ืŸ ื“ื™ Chromium ืงืึธื“ืขื‘ืึทืกืข - ืงืกื ื•ืžืงืก ื ืื•ื•ืขืžื‘ืขืจ.
ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ืคืึธืจืฉื˜ืขืœืŸ ืื™ืŸ ืงืึธื“ FTS3 ืคื•ืœ-ื˜ืขืงืกื˜ ื–ื•ื›ืŸ ืžืึธื˜ืึธืจ ืื•ืŸ ื“ื•ืจืš ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทืŸ ืคื•ืŸ ืฉืึธื˜ืŸ ื˜ื™ืฉืŸ (ืึท ืกืคึผืขืฆื™ืขืœ ื˜ื™ืคึผ ืคื•ืŸ ื•ื•ื™ืจื˜ื•ืึทืœ ื˜ื™ืฉ ืžื™ื˜ ืจื™ื™ื˜ืึทื‘ื™ืœื™ื˜ื™) ืงืขื ืขืŸ ืคื™ืจืŸ ืฆื• ืื™ื ื“ืขืงืก ืงืึธืจื•ืคึผืฆื™ืข ืื•ืŸ ื‘ืึทืคืขืจ ืœื•ื™ืคืŸ. ื“ื™ื˜ื™ื™ืœื“ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืึทืคึผืขืจื™ื™ื˜ื™ื ื’ ื˜ืขืงื ื™ืงืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืืจื•ื™ืก ื ืึธืš 90 ื˜ืขื’.

ื ื™ื• SQLite ืžืขืœื“ื•ื ื’ ืžื™ื˜ ืคืึทืจืจื™ื›ื˜ืŸ ืคึฟืึทืจ ืื™ืฆื˜ ื ื™ื˜ ื’ืขืฉืืคืŸ (ื’ืขืจื™ื›ื˜ ืฆื• 31 ื“ืขืฆืขืžื‘ืขืจ). ื•ื•ื™ ืึท ื–ื™ื›ืขืจื”ื™ื™ื˜ ื•ื•ืึธืจืงืึทืจืึธื•ื ื“, ืกื˜ืึทืจื˜ื™ื ื’ ืžื™ื˜ SQLite 3.26.0, ื“ื™ SQLITE_DBCONFIG_DEFENSIVE ืžืึธื“ืข ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜, ื•ื•ืึธืก ื“ื™ืกื™ื™ื‘ืึทืœื– ืฉืจื™ื™ื‘ืŸ ืฆื• ืฉืึธื˜ืŸ ื˜ื™ืฉืŸ ืื•ืŸ ืื™ื– ืจืขืงืึทืžืขื ื“ื™ื“ ืคึฟืึทืจ ื™ื ืงืœื•ื–ืฉืึทืŸ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืกืงืœ ืงื•ื•ื™ืจื™ื– ืื™ืŸ SQLite. ืื™ืŸ ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ืงื™ืฅ, ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ SQLite ื‘ื™ื‘ืœื™ืึธื˜ืขืง ื‘ืœื™ื™ื‘ื˜ ืึทื ืคื™ืงืกื˜ ืื™ืŸ ื“ืขื‘ื™ืึทืŸ, ื•ื‘ื•ื ื˜ื•, rhel, openSUSE / SUSE, ืึทืจื˜ืฉ ืœื™ื ื•ืงืก, ืคืขื“ืึธืจืึท, FreeBSD. ืงืจืึธื•ืžื™ืึทื ืื™ืŸ ืึทืœืข ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ืื™ื– ืฉื•ื™ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ืื•ืŸ ื ื™ืฉื˜ ืึทืคืขืงื˜ืึทื“ ื“ื•ืจืš ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ืึธื‘ืขืจ ื“ื™ ืคึผืจืึธื‘ืœืขื ืงืขืŸ ื•ื•ื™ืจืงืŸ ืคืึทืจืฉื™ื“ืŸ ื“ืจื™ื˜-ืคึผืึทืจื˜ื™ื™ ื‘ืจืึทื•ื–ืขืจื– ืื•ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื•ื•ืึธืก ื ื•ืฆืŸ ื“ื™ Chromium ืžืึธื˜ืึธืจ, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ืึทื ื“ืจื•ื™ื“ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื•ื•ืขื‘ื•ื•ื™ืขื•ื•.

ืึทื“ื“ื™ื˜ื™ืึธื ืึทืœืœื™, 4 ื•ื•ื™ื™ื ื™ืงืขืจ ื’ืขืคืขืจืœืขืš ืคึผืจืึธื‘ืœืขืžืก ื–ืขื ืขืŸ ืื•ื™ืš ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ SQLite (CVE-2019-13750, CVE-2019-13751, CVE-2019-13752, CVE-2019-13753), ื•ื•ืึธืก ืงืขื ืขืŸ ืคื™ืจืŸ ืฆื• ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืœื™ืงืึทื“ื–ืฉ ืื•ืŸ ืกืขืจืงืึทืžื•ื•ืขื ื˜ืฉืึทืŸ ืคื•ืŸ ืจื™ืกื˜ืจื™ืงืฉืึทื ื– (ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ื•ื•ื™ ืงืึทื ื˜ืจื™ื‘ื™ื•ื˜ื™ื ื’ ืกื™ื‘ื•ืช ืคึฟืึทืจ ืึท ื‘ืึทืคืึทืœืŸ ืื•ื™ืฃ ืงืจืึธื•ื). ื“ื™ ื™ืฉื•ื– ื–ืขื ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื“ื™ SQLite ืงืึธื“ ืื•ื™ืฃ 13 ื“ืขืฆืขืžื‘ืขืจ. ืฆื•ื–ืึทืžืขืŸ, ื“ื™ ืคืจืื‘ืœืขืžืขืŸ ืขืจืœื•ื™ื‘ื˜ ื“ื™ ืจื™ืกืขืจื˜ืฉืขืจื– ืฆื• ืฆื•ื’ืจื™ื™ื˜ืŸ ืึท ืืจื‘ืขื˜ืŸ ื’ื•ื•ื•ืจืข ื•ื•ืึธืก ืึทืœืึทื•ื– ืงืึธื“ ืฆื• ื–ื™ื™ืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“ ืื™ืŸ ื“ืขื ืงืึธื ื˜ืขืงืกื˜ ืคื•ืŸ ื“ื™ Chromium ืคึผืจืึธืฆืขืก ืคืึทืจืึทื ื˜ื•ื•ืึธืจื˜ืœืขืš ืคึฟืึทืจ ืจืขื ื“ืขืจื™ื ื’.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’