ืึทืคึผื“ื™ื™ื˜ื™ื ื’ PostgreSQL 11.3, 10.8, 9.6.13, 9.5.17 ืื•ืŸ 9.4.22

ื’ืขืฉืืคืŸ ืงืขืจืขืงื˜ื™ื•ื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืคึฟืึทืจ ืึทืœืข ื’ืขืฉื˜ื™ืฆื˜ PostgreSQL ืฆื•ื•ื™ื™ื’ืŸ: 11.3, 10.8, 9.6.13, 9.5.17 ะธ 9.4.22, ื•ื•ืึธืก ื›ึผื•ืœืœ ืึท ื˜ื™ื™ืœ ืคื•ืŸ ื–ืฉื•ืง ืคื™ืงืกื™ื–. ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืคึฟืึทืจ ืฆื•ื•ื™ื™ึทื’ 9.4 ื•ื•ืขื˜ ื“ื•ื™ืขืจืŸ ื‘ื™ื– ื“ืขืฆืขืžื‘ืขืจ 2019, 9.5 ื‘ื™ื– ื™ืื ื•ืืจ 2021, 9.6 ื‘ื™ื– ืกืขืคื˜ืขืžื‘ืขืจ 2021, 10 ื‘ื™ื– ืืงื˜ืื‘ืขืจ 2022, 11 ื‘ื™ื– ื ืื•ื•ืขืžื‘ืขืจ 2023.

ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืขืก ืคืึทืจืจื™ื›ื˜ืŸ ืžืขืจ ื•ื•ื™ 60 ื‘ืึทื’ื– ืื•ืŸ ืขืœื™ืžื™ื ื™ืจืŸ ืคื™ืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–:

  • ืฆื•ื•ื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (CVE-2019-10127, CVE-2019-10128) ื–ืขื ืขืŸ ืกืคึผืขืฆื™ืคื™ืฉ ืฆื• ื“ื™ Windows ืคึผืœืึทื˜ืคืึธืจืžืข ืื•ืŸ ื“ืขืจืฉื™ื™ึทื ืขืŸ ืื™ืŸ ื™ื ืกื˜ืึธืœืขืจื– ืคึฟื•ืŸ EnterpriseDB ืื•ืŸ BigSQL, ื•ื•ืึธืก ื”ืึธื‘ืŸ ื ื™ืฉื˜ ื‘ืึทืฉื˜ื™ืžื˜ ืฆื•ื ืขืžืขืŸ ืึทืงืกืขืก ืจืขื›ื˜ ืฆื• ื“ื™ ื“ืึทื˜ืŸ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ, ื•ื•ืึธืก ืขืจืœื•ื™ื‘ื˜ ืงื™ื™ืŸ ืึทื ืคึผืจื™ื•ื•ื™ืœื“ื–ืฉื“ Windows ื‘ืึทื ื™ืฆืขืจ ืฆื• ืึธื ื”ื™ื™ื‘ืŸ. ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืื•ื™ืฃ PostgreSQL ืกืขืจื•ื•ื™ืก ืžื“ืจื’ื”.
  • ื“ื™ CVE-2019-10129 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืืจื•ื™ืก ืื™ืŸ PostgreSQL 11 ืื•ืŸ ืึทืœืึทื•ื– ืึท ื‘ืึทื ื™ืฆืขืจ ืฆื• ืœื™ื™ืขื ืขืŸ ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ื–ื›ึผืจื•ืŸ ื’ืขื‘ื™ื˜ืŸ ืคื•ืŸ ืึท ืกืขืจื•ื•ืขืจ ืคึผืจืึธืฆืขืก ื“ื•ืจืš ืฉื™ืงืŸ ืึท ืกืคึผืขืฆื™ืขืœ ืงืจืึทืคื˜ืขื“ INSERT ื‘ืขื˜ืŸ ืฆื• ืึท ืคึผืึทืจื˜ื™ืฉืึทื ื“ ื˜ื™ืฉ.
  • ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ CVE-2019-10130 ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืœื™ื™ืขื ืขืŸ ื“ื™ ื•ื•ืึทืœื•ืขืก ืคื•ืŸ ืจืขืงืึธืจื“ืก ืฆื• ื•ื•ืึธืก ืึทืงืกืขืก ืื™ื– ืœื™ืžื™ื˜ืขื“.

ืคืึทืจืคืขืกื˜ื™ืงื˜ ื‘ืึทื’ื– ืึทืจื™ื™ึทื ื ืขืžืขืŸ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืงืึธืจื•ืคึผืฆื™ืข ื•ื•ืขืŸ ืขืงืกืึทืงื™ื•ื˜ื™ื ื’ "ALTER TABLE" ืื•ื™ืฃ ืึท ืคึผืึทืจื˜ื™ืฉืึทื ื“ ื˜ื™ืฉ, ืกืขืจื•ื•ืขืจ ืงืจืึทืš ื•ื•ืขืŸ ืึท ื˜ืขื•ืช ืึทืงืขืจื– ื•ื•ืขืŸ ื˜ืจื™ื™ื ื’ ืฆื• ืจืึทื˜ืขื•ื•ืขืŸ ื“ื™ ืœื•ื™ืคึฟืขืจ ืฆื•ื•ื™ืฉืŸ ื˜ืจืึทื ืกืึทืงื˜ื™ืึธืŸ ืงืึทืžื™ืฅ, ืคืึธืจืฉื˜ืขืœื•ื ื’ ืคึผืจืึธื‘ืœืขืžืก ื•ื•ืขืŸ ืจืึธื•ืœื™ื ื’ ืฆื•ืจื™ืง ื˜ืจืึทื ื–ืึทืงืฉืึทื ื– ื™ื ื•ื•ืึทืœื•ื•ื™ื ื’ ืึท ื’ืจื•ื™ืก ื ื•ืžืขืจ ืคื•ืŸ ื˜ื™ืฉืŸ, ืคืขืœืŸ ืคื•ืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื“ื™. "ืฉืึทืคึฟืŸ ื˜ื™ืฉ ืื•ื™ื‘ ื ื™ื˜" ืื•ื™ืกื“ืจื•ืง ื™ื’ื–ื™ืกืฅ .. ื•ื•ื™ ื•ื™ืกืคื™ืจืŸ ..", ื–ื›ึผืจื•ืŸ ืœื™ืงืก.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’