¾ÅÓÎÀϸç

¾ÅÓÎÀϸç

¾ÅÓÎÀÏ¸ç¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¡¾Îó²îͨ¸æ¡¿LinuxϵͳpppdÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-8597£©

2020-03-09

 

Ò».  Îó²î¸ÅÊö

3ÔÂ6ÈÕ£¬US-CERTÐû²¼ÁËÒ»¸ö¹ØÓÚÓ°ÏìPPP daemon(pppd)Èí¼þµÄ±£´æ17ÄêÖ®¾ÃµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄͨ¸æ£¬Ó°ÏìÏÕЩËùÓлùÓÚLinuxµÄ²Ù×÷ϵͳÒÔ¼°ÍøÂç×°±¸¹Ì¼þ¡£¸ÃÎó²îΪջ»º³åÒç³öÎó²î(CVE-2020-8597)£¬CVSSÆÀ·ÖΪ9.8·Ö£»pppdÖеÄeap.cÔÚeap_requestºÍeap_responseº¯ÊýÖÐrhostname²ÎÊý±£´æ»º³åÇøÒç³ö£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß·¢ËͶñÒâαÔìµÄEAP°ü£¬¿ÉÔÚÊÜÓ°ÏìµÄϵͳÖÐÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£

pppdÈí¼þÊÇPoint-to-Point Protocol (PPP)µÄÒ»¸öʵÏÖ£¬PPPЭÒé¿ÉÒÔÔÚ½ÚµãÖ®¼ä¾ÙÐÐͨѶºÍÊý¾Ý´«Ê䣬Ö÷ÒªÓÃÓÚ½¨É軥ÁªÍøÅþÁ¬£¬ºÃ±È²¦ºÅÄ£¿é¡¢DSL¿í´øºÍVPN£¨ÐéÄâËùÓÐÍøÂ磩¡£pppdÊÇÒ»¸öÔÚÓ¦ÓòãÖеÄÊØ»¤Àú³Ì£¬Æä¹¦Ð§ÎªÊµÏÖpppÕ½ÂÔÐÔµÄÄÚÈÝ£¬°üÀ¨ËùÓмøÈ¨¡¢Ñ¹Ëõ/½âѹºÍ¼ÓÃÜ/½âÃܵÈÀ©Õ¹¹¦Ð§µÄ¿ØÖÆÐ­Òé¡£ÓÉÓÚpppdͨ³£ÒÔ¸ßȨÏÞÔËÐÐÇÒÓëÄÚºËÇý¶¯³ÌÐòÒ»ÆðÔË×÷£¬Òò´Ë¸ÃÎó²î¿ÉÄÜʹ¹¥»÷ÕßÒÔsystem»òrootȨÏÞÖ´ÐжñÒâ´úÂë¡£

²Î¿¼Á´½Ó£º

https://www.debian.org/security/2020/dsa-4632

https://thehackernews.com/2020/03/ppp-daemon-vulnerability.html

https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-8597.html

¶þ¡¢Ó°Ïì¹æÄ£

ÊÜÓ°Ïì°æ±¾

2.4.2 =< pppd =< 2.4.8

ÊÜÓ°ÏìµÄϵͳÓë×°±¸

Debian

Ubuntu

SUSE Linux

Fedora

NetBSD

Red Hat Enterprise Linux

Cisco CallManager

TP-LINK 

OpenWRT Embedded OS

Synology£¨DiskStation Manager¡¢VisualStation¡¢Router Manager£©

Èý¡¢Îó²î·À»¤

3.1 ×°Öò¹¶¡

ÏÖÔÚpppd¹Ù·½Ó벿·ÖLinuxϵͳÒÑÕë¶ÔÊÜÖ§³ÖµÄ²úÆ·Ðû²¼ÁËÐÞ¸´¸ÃÎó²îµÄÇå¾²²¹¶¡£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì×°ÖþÙÐзÀ»¤¡£

³§É̲úÆ· ÐÞ¸´°æ±¾ ²Î¿¼Á´½Ó
pppd 8d7970b8f3db727fe798b65f3377fe6787575426 https://github.com/paulusmack/ppp/commit/8d7970b8f3db727fe798b65f3377fe6787575426
Centos ppp 2.4.5-34 https://centos.pkgs.org/7/centos-updates-x86_64/ppp-2.4.5-34.el7_7.x86_64.rpm.html
Ubuntu 12.04 ESM (Precise Pangolin): released (2.4.5-5ubuntu1.3) https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-8597.html
Ubuntu 14.04 ESM (Trusty Tahr): released (2.4.5-5.1ubuntu2.3+esm1) https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-8597.html
Ubuntu 16.04 LTS (Xenial Xerus): released (2.4.7-1+2ubuntu1.16.04.2) https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-8597.html
Ubuntu 18.04 LTS (Bionic Beaver): released (2.4.7-2+2ubuntu1.2) https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-8597.html
Ubuntu 19.10 (Eoan Ermine): released (2.4.7-2+4.1ubuntu4.1) https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-8597.html
Ubuntu 20.04 (Focal Fossa): released (2.4.7-2+4.1ubuntu5)  https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-8597.html
debian 8 ppp 2.4.6-3.1+deb8u1  https://security-tracker.debian.org/tracker/source-package/ppp
debian 9 ppp 2.4.7-1+4+deb9u1  https://www.debian.org/security/2020/dsa-4632
debian 10 ppp 2.4.7-2+4.1+deb10u1  https://www.debian.org/security/2020/dsa-4632

×¢£º½¨ÒéʹÓÃyum¡¢aptµÈÈí¼þ°ü¹ÜÀí¹¤¾ß¾ÙÐÐ×°Öá£

ÉùÃ÷

±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£

¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾­¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼  

±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£

»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£

±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈë¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
  • Ìá½»µ½ÓÊÏä
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷

? 2025 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼