PostgreSQL ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืžื™ื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜. Odyssey Connection Balancer 1.2 ื‘ืืคืจื™ื™ื˜

ืงืขืจืขืงื˜ื™ื•ื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ื–ืขื ืขืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ืคึฟืึทืจ ืึทืœืข ืฉื˜ื™ืฆื˜ PostgreSQL ืฆื•ื•ื™ื™ื’ืŸ: 14.1, 13.5, 12.9, 11.14, 10.19 ืื•ืŸ 9.6.24. ืžืขืœื“ื•ื ื’ 9.6.24 ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ื™ ืœืขืฆื˜ืข ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืคึฟืึทืจ ื“ื™ 9.6 ืฆื•ื•ื™ื™ึทื’, ื•ื•ืึธืก ืื™ื– ื“ื™ืกืงืึทื ื˜ื™ื ื™ื•ื“. ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืคึฟืึทืจ ืฆื•ื•ื™ื™ึทื’ 10 ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ื‘ื™ื– ื ืื•ื•ืขืžื‘ืขืจ 2022, 11 - ื‘ื™ื– ื ืื•ื•ืขืžื‘ืขืจ 2023, 12 - ื‘ื™ื– ื ืื•ื•ืขืžื‘ืขืจ 2024, 13 - ื‘ื™ื– ื ืื•ื•ืขืžื‘ืขืจ 2025, 14 - ื‘ื™ื– ื ืื•ื•ืขืžื‘ืขืจ 2026.

ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืขืก ืคืึธืจืฉืœืึธื’ืŸ ืžืขืจ ื•ื•ื™ 40 ืคื™ืงืกื™ื– ืื•ืŸ ืขืœื™ืžื™ื ื™ืจืŸ ืฆื•ื•ื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2021-23214, CVE-2021-23222) ืื™ืŸ ื“ื™ ืกืขืจื•ื•ืขืจ ืคึผืจืึธืฆืขืก ืื•ืŸ ื“ื™ libpq ืงืœื™ืขื ื˜ ื‘ื™ื‘ืœื™ืึธื˜ืขืง. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืœืึธื–ืŸ ืึท ืึทื˜ืึทืงืขืจ ืฆื• ื‘ืจืขื›ืŸ ืื™ืŸ ืึท ื™ื ืงืจื™ืคึผื˜ื™ื“ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ืงืึทื ืึทืœ ื“ื•ืจืš ืึท MITM ื‘ืึทืคืึทืœืŸ. ื“ื™ ื‘ืึทืคืึทืœืŸ ื˜ื•ื˜ ื ื™ืฉื˜ ื“ืึทืจืคืŸ ืึท ื’ื™ืœื˜ื™ืง ืกืกืœ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื•ืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืงืขื’ืŸ ืกื™ืกื˜ืขืžืขืŸ ื•ื•ืึธืก ื“ืึทืจืคืŸ ืงืœื™ืขื ื˜ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื ื™ืฆืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ. ืื™ืŸ ื“ืขื ืงืึธื ื˜ืขืงืกื˜ ืคื•ืŸ ื“ื™ ืกืขืจื•ื•ืขืจ, ื“ื™ ื‘ืึทืคืึทืœืŸ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืคืึทืจื‘ื™ื™ึทื˜ืŸ ื“ื™ื™ืŸ ืื™ื™ื’ืขื ืข SQL ืึธื ืคึฟืจืขื’ ืื™ืŸ ื“ืขืจ ืฆื™ื™ื˜ ืคื•ืŸ ื’ืจื™ื ื“ืŸ ืึท ื™ื ืงืจื™ืคึผื˜ื™ื“ ืงืฉืจ ืคื•ืŸ ื“ืขื ืงืœื™ืขื ื˜ ืฆื• ื“ื™ PostgreSQL ืกืขืจื•ื•ืขืจ. ืื™ืŸ ื“ืขื ืงืึธื ื˜ืขืงืกื˜ ืคื•ืŸ libpq, ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืึทืœืึทื•ื– ืึท ืึทื˜ืึทืงืขืจ ืฆื• ืฆื•ืจื™ืงืงื•ืžืขืŸ ืึท ืคืึทืœืฉ ืกืขืจื•ื•ืขืจ ืขื ื˜ืคืขืจ ืฆื• ื“ืขื ืงืœื™ืขื ื˜. ื•ื•ืขืŸ ืงืึทืžื‘ื™ื™ื ื“, ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืœืึธื–ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืึท ืงืœื™ืขื ื˜ ืก ืคึผืึทืจืึธืœ ืึธื“ืขืจ ืื ื“ืขืจืข ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ื“ืึทื˜ืŸ ื˜ืจืึทื ืกืžื™ื˜ื˜ืขื“ ืคืจื™ ืื™ืŸ ื“ื™ ืงืฉืจ ืฆื• ื–ื™ื™ืŸ ื™ืงืกื˜ืจืึทืงื˜ื™ื“.

ืื™ืŸ ื“ืขืจืฆื•, ืžื™ืจ ืงืขื ืขืŸ ื˜ืึธืŸ ื“ื™ ื•ื™ืกื’ืึทื‘ืข ื“ื•ืจืš ื™ืึทื ื“ืขืงืก ืคื•ืŸ ืึท ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ื“ื™ Odyssey 1.2 ืคึผืจืึทืงืกื™ ืกืขืจื•ื•ืขืจ, ื“ื™ื–ื™ื™ื ื“ ืฆื• ื”ืึทืœื˜ืŸ ืึท ื‘ืขืงืŸ ืคื•ืŸ ืึธืคึฟืŸ ืงืึทื ืขืงืฉืึทื ื– ืฆื• ื“ื™ PostgreSQL DBMS ืื•ืŸ ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ืึธื ืคึฟืจืขื’ ืจื•ื˜ื™ื ื’. Odyssey ืฉื˜ื™ืฆื˜ ืคืœื™ืกื ื“ื™ืง ืงื™ื™ืคืœ ืึทืจื‘ืขื˜ ืคึผืจืึทืกืขืกืึทื– ืžื™ื˜ ืžื•ืœื˜ื™-ื˜ืจืขื“ื™ื“ ื”ืึทื ื“ืœืขืจืก, ืจื•ื˜ื™ื ื’ ืฆื• ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืกืขืจื•ื•ืขืจ ื•ื•ืขืŸ ืึท ืงืœื™ืขื ื˜ ืจื™ืงืึทื ืขืงืฅ, ืื•ืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื‘ื™ื ื“ืŸ ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืคึผืึธืึธืœืก ืฆื• ื ื™ืฆืขืจืก ืื•ืŸ ื“ืึทื˜ืึทื‘ื™ื™ืกื™ื–. ื“ืขืจ ืงืึธื“ ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ C ืื•ืŸ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืื•ื ื˜ืขืจ ื“ื™ BSD ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ.

ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ืึธื“ื™ืกืกื™ื™ ืžื•ืกื™ืฃ ืฉื•ืฅ ืฆื• ืคืึทืจืฉืคึผืึทืจืŸ ื“ืึทื˜ืŸ ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ื ืึธืš ื ื™ื’ืึธื•ืฉื™ื™ื™ื˜ื™ื ื’ ืึท SSL ืกืขืกื™ืข (ืึทืœืึทื•ื™ื– ืื™ืจ ืฆื• ืคืึทืจืฉืคึผืึทืจืŸ ืื ืคืืœืŸ ื ื™ืฆืŸ ื“ื™ ืื•ื™ื‘ืŸ-ื“ืขืจืžืื ื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– CVE-2021-23214 ืื•ืŸ CVE-2021-23222). ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ PAM ืื•ืŸ LDAP ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“. ืฆื•ื’ืขื’ืขื‘ืŸ ื™ื ื˜ืึทื’ืจื™ื™ืฉืึทืŸ ืžื™ื˜ ื“ื™ ืคึผืจืึธืžืขื˜ื”ืขื•ืก ืžืึธื ื™ื˜ืึธืจื™ื ื’ ืกื™ืกื˜ืขื. ื™ืžืคึผืจื•ื•ื•ื“ ื›ืขื–ืฉื‘ืŸ ืคื•ืŸ ืกื˜ืึทื˜ื™ืกื˜ื™ืง ืคึผืึทืจืึทืžืขื˜ืขืจืก ืฆื• ื—ืฉื‘ื•ืŸ ืคึฟืึทืจ ื˜ืจืึทื ืกืึทืงื˜ื™ืึธืŸ ืื•ืŸ ืึธื ืคึฟืจืขื’ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืฆื™ื™ื˜.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’