ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ื™ Squid 4.8 ืคึผืจืึทืงืกื™ ืกืขืจื•ื•ืขืจ ืžื™ื˜ ื“ื™ ื™ืœื™ืžืึทื ื™ื™ืฉืึทืŸ ืคื•ืŸ ืึท ืงืจื™ื˜ื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™

ืืจื•ื™ืก ืงืขืจืขืงื˜ื™ื•ื• ืคึผืจืึทืงืกื™ ืžืขืœื“ื•ื ื’ ื˜ื™ื ื˜ืคื™ืฉ 4.8, ื•ื•ืึธืก ืคืึทืจืคืขืกื˜ื™ืงื˜ 5 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–. ืื™ื™ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2019-12527) ืขืก ืึทืœืึทื•ื– ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืžื™ื˜ ื“ื™ ืจืขื›ื˜ ืคื•ืŸ ื“ื™ ืกืขืจื•ื•ืขืจ ืคึผืจืึธืฆืขืก.

ื“ื™ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืึท ื–ืฉื•ืง ืื™ืŸ ื“ื™ ื”ื˜ื˜ืคึผ ื‘ืึทืกื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื”ืึทื ื“ืœืขืจ ืื•ืŸ ืึทืœืึทื•ื– ืึท ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ืฆื• ื–ื™ื™ืŸ ื˜ืจื™ื’ืขืจื“ ื•ื•ืขืŸ ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ืกืคึผืขืฆื™ืขืœ ืงืจืึทืคื˜ืขื“ ืงืจืึทื“ืขื ื˜ืฉืึทืœื– ื•ื•ืขืŸ ืึทืงืกืขืกื™ื ื’ ืกืงื•ื•ื™ื“ ืงืึทืฉ
ืคืึทืจื•ื•ืึทืœื˜ืขืจ ืึธื“ืขืจ ืึท ื’ืขื‘ื•ื™ื˜-ืื™ืŸ ืคื˜ืคึผ ื’ื™ื™ื˜ื•ื•ื™ื™. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืกื˜ืึทืจื˜ื™ื ื’ ืžื™ื˜ ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ Squid 4.0.23. ื•ื•ื™ ืึท ื•ื•ืึธืจืงืึทืจืึธื•ื ื“ ืคึฟืึทืจ ื‘ืœืึทืงื™ื ื’ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ืื™ืจ ืงืขื ืขืŸ ืจื™ื‘ื™ืœื“ ื˜ื™ื ื˜ืคื™ืฉ ืžื™ื˜ ื“ื™ "--disable-auth-basic" ืึธืคึผืฆื™ืข ืึธื“ืขืจ ื“ื™ืกื™ื™ื‘ืึทืœ ืึทืงืกืขืก ืฆื• ื‘ืึทื“ื™ื ื•ื ื’ืก ื•ื•ืึธืก ื ื•ืฆืŸ HTTP ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื™ืŸ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ:

ืึทืงืœ ืคื˜ืคึผ ืคึผืจืึธื˜ืึธ ืคื˜ืคึผ
ื”ื˜ื˜ืคึผ_ืึทืงืกืขืก ืœื™ื™ืงืขื ืขืŸ ืคื˜ืคึผ
ื”ื˜ื˜ืคึผ_ืึทืงืกืขืก ืœื™ื™ืงืขื ืขืŸ ืคืึทืจื•ื•ืึทืœื˜ืขืจ

ื“ื™ ืื ื“ืขืจืข ื“ืจื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืงืขื ืขืŸ ืคื™ืจืŸ ืฆื• ืึท ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ ื•ื•ืขืŸ ืžืึทื ื™ืคึผื™ืึทืœื™ื™ื˜ื™ื ื’ cachemgr.cgi, HTTP Digest ืึธื“ืขืจ HTTP Basic ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ. ื“ื™ ืจื•ืขืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืึทืœืึทื•ื– ืงืจื™ื™ึทื–-ืคึผืœืึทืฅ ืกืงืจื™ืคึผื˜ื™ื ื’ ื“ื•ืจืš cachemgr.cgi.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’