Jackson-databind ·´ÐòÁл¯Îó²î £¨CVE-2017-15095£©
2017-11-02
×ÛÊö
±±¾©Ê±¼ä2017Äê11ÔÂ2ÈÕ£¬JacksonÕë¶Ô·´ÐòÁл¯Îó²î£¨CVE-2017-7525£©±£´æÒÅÁôÎÊÌ⣬Ðû²¼ÁËjackson-databind·´ÐòÁл¯Îó²î(CVE-2017-15095)¼°ÆäÏà¹ØÐÅÏ¢£¬¸ÃÎó²î×÷ΪCVE-2017-7525µÄºóÐø£¬ÐÎòÁ˸ü¶àÕë¶Ôjackson-databindµÄ·´ÐòÁл¯Îó²î¹¥»÷¡£
7Ô·ݣ¬¾ÅÓÎÀÏ¸ç¿Æ¼¼Ñо¿Ô±·¢Ã÷·´ÐòÁл¯Â© ¶´£¨CVE-2017-7525£©Ó°Ïìjackson-databind£¬¸ÃÎó²î½«Î£ÏÕµÄÀà¼ÓÈëºÚÃûµ¥¿ÉÒÔ»ñµÃ»º½â£¬¹Ù·½ËæºóÐû²¼Í¨¸æ£¬²¢Ðû²¼ÁËJackson 2.8.9°æ±¾¡£
µ«ÔÚºóÐøµÄ2.9.1°æ±¾ÖУ¬¾ÅÓÎÀÏ¸ç¿Æ¼¼Ñо¿Ô±ÈÔÈ»·¢Ã÷ÁËÀàËÆµÄÎÊÌ⣬ÐèÒª½«¸ü¶àΣÏÕµÄÀàÒÔºÚÃûµ¥µÄ·½·¨¾ÙÐÐÆÁÕÏ¡£¸ÃÐÅÏ¢»ñµÃJackson¹Ù·½¼òÖ±ÈÏ£¬²¢¾öÒéÐû²¼ÐµÄͨ¸æËµÃ÷£¬´ËÎó²îCVE±àºÅΪCVE-2017-15095¡£
˼Á¿µ½Ïà¹ØÇå¾²ÐÔ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼µÄÆÊÎö½«ÔÚ¹Ù·½²¹¶¡Ðû²¼ºóͨ¸æ£¬Çë¸÷È˹Ø×¢Ïà¹ØÐÅÏ¢¡£
Ïà¹ØÁ´½Ó£º
http://www.openwall.com/lists/oss-security/2017/11/02/3
ÊÜÓ°ÏìµÄ°æ±¾
Jackson version <= 2.9.2
½â¾ö¼Æ»®
Jackson¹Ù·½¼´½«Ðû²¼Ð°汾½â¾ö¸ÃÎÊÌ⣬ÇëÓû§Ò»Á¬¹Ø×¢²¢ÊµÊ±¸üÐÂÀ´¾ÙÐзÀ»¤¡£
²Î¿¼Á´½Ó£º
https://github.com/FasterXML/jackson-databind/releases
¹Ù·½Ò²ÌṩÁ˹ØÓÚCVE-2017-7525ÓëCVE-2017-15095µÄÔÝʱ·À»¤²½·¥£¬Çë²Î¿¼Á´½Ó£º
https://bugzilla.redhat.com/show_bug.cgi?id=1462702#c12
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ





