Ãë¾àÁ¡ID |
25349 |
À§Çèµµ |
30 |
Æ÷Æ® |
5432 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
DB |
»ó¼¼¼³¸í |
¿ø°Ý È£½ºÆ®¿¡ ¼³Ä¡µÈ PostgreSQL ¹öÀüÀº 11.11 ÀÌÀü 11, 12.6 ÀÌÀü 12 ¶Ç´Â 13.2 ÀÌÀü 13ÀÔ´Ï´Ù. µû¶ó¼ ´ÙÀ½°ú °°Àº ¿©·¯ Ãë¾àÁ¡ÀÇ ¿µÇâÀ» ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù.
-13.2 ÀÌÀü, 12.6 ÀÌÀü ¹× 11.11 ÀÌÀü ¹öÀüÀÇ postgresql¿¡¼ Á¤º¸ À¯ÃâÀÌ ¹ß°ßµÇ¾ú½À´Ï´Ù. UPDATE ±ÇÇÑÀÌ ÀÖÁö¸¸ ƯÁ¤ ¿¿¡ ´ëÇÑ SELECT ±ÇÇÑÀÌ ¾ø´Â »ç¿ëÀÚ´Â °æ¿ì¿¡ µû¶ó ¿À·ù ¸Þ½ÃÁö¿¡¼ ÇØ´ç ¿ÀÇ °ªÀ» °ø°³ ÇÒ ¼ö ÀÖ´Â Äõ¸®¸¦ ÀÛ¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù. °ø°ÝÀÚ´Â ÀÌ °áÇÔÀ» »ç¿ëÇÏ¿© ¾²±â´Â Çã¿ëµÇÁö¸¸ ÀÐÀ» ¼ö´Â¾ø´Â ¿¿¡ ÀúÀåµÈ Á¤º¸¸¦ ¾òÀ» ¼ö ÀÖ½À´Ï´Ù. (CVE-2021-3393)
-13.2 ÀÌÀü, 12.6 ÀÌÀü, 11.11 ÀÌÀü ¹öÀüÀÇ PostgreSQL¿¡¼ °áÇÔÀÌ ¹ß°ßµÇ¾ú½À´Ï´Ù. ÀÌ °áÇÔÀº ÇÑ ¿¿¡ ´ëÇÑ SELECT ±ÇÇÑÀ» °¡Áø »ç¿ëÀÚ°¡ Å×À̺íÀÇ ¸ðµç ¿À» ¹ÝȯÇϴ Ư¼ö Äõ¸®¸¦ ¸¸µé ¼ö ÀÖµµ·Ï ÇÕ´Ï´Ù. ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇÑ °¡Àå Å« À§ÇùÀº ±â¹Ð¼ºÀÔ´Ï´Ù (CVE-2021-20229).
* Âü°í »çÀÌÆ®: https://www.postgresql.org/about/news/postgresql-132-126-1111-1016-9621-and-9525-released-2165/ https://access.redhat.com/security/cve/CVE-2021-20229 https://access.redhat.com/security/cve/CVE-2021-3393
* ¿µÇâ¹Þ´Â Ç÷§Æû: PostgreSQL 12.6 ÀÌÀüÀÇ 12.x ¹öÀüµé Any operating system Any version |
ÇØ°áÃ¥ |
PostgreSQL À¥ ÆäÀÌÁöÀÎ http://www.postgresql.org/download/¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â PostgreSQLÀÇ °¡Àå ÃֽŠ¹öÀü(12.6 ¶Ç´Â ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2021-3393,CVE-2021-20229 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|