Cesanta Mongoose¶à¸öÎó²î
2017-11-01
×ÛÊö
ÍâµØÊ±¼ä2017Äê10ÔÂ31ÈÕ£¬TalosÍŶÓÐû²¼Á˶à¸ö¹ØÓÚCesanta MongooseµÄÎó²îͨ¸æ£¬º¸Ç´úÂëÖ´ÐУ¬¾Ü¾ø·þÎñµÈ¹²8¸öÎó²î£¬ÆäÖаüÀ¨¶à¸öCVSS 3.0ÆÀ·ÖΪ9.8·ÖµÄ¸ßΣÎó²î¡£Mongoose±»³ÆÎªGitHubÉÏ×îÊܽӴýµÄǶÈëÊ½ÍøÂç·þÎñÆ÷£¬ÏÖÔÚMongooseÒѾ¸üÐÂÐÞ¸´ÁËÏà¹ØÎó²î¡£
Ïà¹ØÁ´½Ó£º
https://cesanta.com/
https://www.talosintelligence.com/vulnerability_reports/#disclosed
ÊÜÓ°ÏìµÄ°æ±¾
l Cesanta Mongoose 6.8
²»ÊÜÓ°ÏìµÄ°æ±¾
l Cesanta Mongoose 6.9
Îó²îÐÅÏ¢
|
Îó²î |
CVE񅧏 |
CVSS 3.0ÆÀ·Ö |
|
Cesanta Mongoose Websocket Protocol Fragmented Packet Code Execution Vulnerability |
CVE-2017-2922 |
9.8 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
|
Cesanta Mongoose Websocket Protocol Packet Length Code Execution Vulnerability |
CVE-2017-2921 |
8.1 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
|
Cesanta Mongoose MQTT SUBSCRIBE Topic Length Information Leak |
CVE-2017-2895 |
8.2 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
|
Cesanta Mongoose MQTT SUBSCRIBE Multiple Topics Remote Code Execution |
CVE-2017-2894 |
9.8 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
|
Cesanta Mongoose MQTT SUBSCRIBE Command Denial Of Service |
CVE-2017-2893 |
7.5 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
|
Cesanta Mongoose MQTT Payload Length Remote Code Execution |
CVE-2017-2892 |
9.8 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
|
Cesanta Mongoose HTTP Server CGI Remote Code Execcution Vulnerability |
CVE-2017-2891 |
9.8 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
|
Cesanta Mongoose DNS Query Compressed Name Pointer Denial Of Service |
CVE-2017-2909 |
7.5 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
½â¾ö¼Æ»®
Moogoose¹Ù·½ÒѾ¸üÐÂ6.9°æ±¾ÐÞ¸´ÁËÕâЩÎó²î£¬ÇëÓû§¾¡¿ìÉý¼¶ÖÁ×îа汾¾ÙÐзÀ»¤¡£
²Î¿¼Á´½Ó£º
https://github.com/cesanta/mongoose
https://cesanta.com/download.html
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ





