English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25349
À§Çèµµ 30
Æ÷Æ® 5432
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í ¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ PostgreSQL ¹öÀüÀº 11.11 ÀÌÀü 11, 12.6 ÀÌÀü 12 ¶Ç´Â 13.2 ÀÌÀü 13ÀÔ´Ï´Ù. µû¶ó¼­ ´ÙÀ½°ú °°Àº ¿©·¯ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù.

-13.2 ÀÌÀü, 12.6 ÀÌÀü ¹× 11.11 ÀÌÀü ¹öÀüÀÇ postgresql¿¡¼­ Á¤º¸ À¯ÃâÀÌ ¹ß°ßµÇ¾ú½À´Ï´Ù.
UPDATE ±ÇÇÑÀÌ ÀÖÁö¸¸ ƯÁ¤ ¿­¿¡ ´ëÇÑ SELECT ±ÇÇÑÀÌ ¾ø´Â »ç¿ëÀÚ´Â °æ¿ì¿¡ µû¶ó ¿À·ù ¸Þ½ÃÁö¿¡¼­ ÇØ´ç ¿­ÀÇ °ªÀ» °ø°³ ÇÒ ¼ö ÀÖ´Â Äõ¸®¸¦ ÀÛ¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù. °ø°ÝÀÚ´Â ÀÌ °áÇÔÀ» »ç¿ëÇÏ¿© ¾²±â´Â Çã¿ëµÇÁö¸¸ ÀÐÀ» ¼ö´Â¾ø´Â ¿­¿¡ ÀúÀåµÈ Á¤º¸¸¦ ¾òÀ» ¼ö ÀÖ½À´Ï´Ù.
(CVE-2021-3393)

-13.2 ÀÌÀü, 12.6 ÀÌÀü, 11.11 ÀÌÀü ¹öÀüÀÇ PostgreSQL¿¡¼­ °áÇÔÀÌ ¹ß°ßµÇ¾ú½À´Ï´Ù. ÀÌ °áÇÔÀº ÇÑ ¿­¿¡ ´ëÇÑ SELECT ±ÇÇÑÀ» °¡Áø »ç¿ëÀÚ°¡ Å×À̺íÀÇ ¸ðµç ¿­À» ¹ÝȯÇϴ Ư¼ö Äõ¸®¸¦ ¸¸µé ¼ö ÀÖµµ·Ï ÇÕ´Ï´Ù.
ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇÑ °¡Àå Å« À§ÇùÀº ±â¹Ð¼ºÀÔ´Ï´Ù (CVE-2021-20229).

* Âü°í »çÀÌÆ®:
https://www.postgresql.org/about/news/postgresql-132-126-1111-1016-9621-and-9525-released-2165/
https://access.redhat.com/security/cve/CVE-2021-20229
https://access.redhat.com/security/cve/CVE-2021-3393

* ¿µÇâ¹Þ´Â Ç÷§Æû:
PostgreSQL 12.6 ÀÌÀüÀÇ 12.x ¹öÀüµé
Any operating system Any version
ÇØ°áÃ¥ PostgreSQL À¥ ÆäÀÌÁöÀÎ http://www.postgresql.org/download/¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â PostgreSQLÀÇ °¡Àå ÃֽŠ¹öÀü(12.6 ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2021-3393,CVE-2021-20229 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)