¡¾Íþвͨ¸æ¡¿OpenSMTPDÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î(CVE-2020-8794)
2020-02-24
×ÛÊö
ÍâµØÊ±¼ä2ÔÂ24ÈÕ£¬À´×ÔÇå¾²¹«Ë¾QualysµÄÑо¿Ö°Ô±ÔÚ¹ûÕæÓʼþ×éÖÐÐû²¼ÁËOpenSMTPD Öб£´æµÄÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î CVE-2020-8794 ¡£
OpenSMTPD £¨Ò²³ÆÎªOpenBSD SMTP·þÎñÆ÷£©ÊÇ OpenBSD ÏîÄ¿µÄÒ»²¿·Ö£¬Ò»¸öÃâ·ÑµÄ·þÎñÆ÷¶ËSMTPÐÒéʵÏÖ£¬Í¨¹ýRFC5321½ç˵¡£
CVE-2020-8794 ÊÇÒ»¸öÔ½½ç¶ÁÈ¡Îó²î£¬¿É±»Ô¶³ÌʹÓã¬ÀֳɵÄʹÓÿɵ¼Ö¹¥»÷ÕßÒÔ root Éí·ÝÖ´ÐÐ×¢Èëµ½ envelope ÎļþÖеÄí§ÒâÏÂÁî¡£
¾ÝÑо¿Ö°Ô±ÌåÏÖ£¬ËûÃÇÕë¶Ô´ËÎó²î¿ª·¢ÁËÒ»¸ö¼òÆÓµÄÎó²îʹÓóÌÐò£¬²¢ÒÑÔÚOpenBSD 6.6¡¢OpenBSD 5.9¡¢Debian 10£¨Îȹ̰棩¡¢Debian 11£¨²âÊ԰棩ºÍFedora 31 ÉÏÀÖ³ÉʹÓá£
²Î¿¼Á´½Ó£º
https://www.openwall.com/lists/oss-security/2020/02/24/5
ÊÜÓ°Ïì²úÆ·°æ±¾
- OpenSMTPD < 6.6.4p1
²»ÊÜÓ°Ïì²úÆ·°æ±¾
- OpenSMTPD = 6.6.4p1
½â¾ö¼Æ»®
¹Ù·½ÒѾÐû²¼Ð°汾ÐÞ¸´Á˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶µ½Ð°汾¾ÙÐзÀ»¤¡£
ÏÂÔØµØµã£º
https://github.com/OpenSMTPD/OpenSMTPD/releases
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

¾ÅÓÎÀϸçÔÆ







