СÖ÷£¬¡°Ìì¾µ¡±Ç°À´ÎÊÕïÀ²~
Ðû²¼Ê±¼ä 2018-04-09
°Ù»¨Æë·Å¡¢ÍòÁø´¹ÌÐ
±¾¸ÃÊǸö̤ÇàÉÍ´º¡¢ÐÀÐÀÏòÈٵĺü¾½Ú
È»¶øÄþ¾²È¦È´Î´ÔøÏûÍ£
ÔÚ¾ÀúÁË¡°ÈÛ¶Ï¡±ºÍ¡°ÓÄÁ顱µÄÏ´Àñºó
ÿ¸öÍøÂçÄþ¾²È˶¼Ê±¿Ì¾¯Ìè×Å
ËæÊ±·ÀÓùÐÂÒ»ÂÖ¶ñÒâ¹¥»÷
Õâ²»
¶¶È¦Îª¶Ä¶øÉú©ɨÍŶӾͿªÆôÁË¡°Ìì¾µÎÊÕïģʽ¡±
¡ý¡ý¡ý
ÎÊÕïÒ»ºÅ£ºmemcache·Å´ó¹¥»÷
memcachedµÄ·þÎñÒì³£·¢°ü£¬µ¼ÖÂϵͳ×ÊÔ´½ôÕÅ£¬Õâô´óµÄÊý¾ÝÁ¿»á²»»á¶Ô´ËÍâÍøÂçÉ豸Ôì³ÉÓ°Ï죿
Òì³£·¢°ü£¬×ÊÔ´½ôÕÅ£¬·¢°üÄ¿µÄµØÖ·Ã÷È·£»¸Ã»¼Õß´æÔÚ±àºÅΪCVE-2018-1000115µÄMemcache Ïà¹ØÂ©¶´£¬Í¨¹ý¸Ã©¶´£¬Òѱ»ÓÃÓÚ·Å´ó¾Ü¾ø·þÎñ¹¥»÷È⼦£¬½¨Ò鼰ʱÅŲ顣
memcached·Å´ó¹¥»÷£¬ºÚ¿Íͨ¹ýÌØ¶¨µÄµÄIPµØÖ·ÏòÍøÕ¾µÄ»º´æ·þÎñÆ÷UDP¶Ë¿Ú11211£¬·¢³ö¼ÙÇëÇó£¬×îÖÕÒý·¢´ó¹æÄ£µÄ²¢·¢»ØÓ¦¡£¾ÝÍøÂçÄþ¾²¹«Ë¾·ÖÎö£¬Ö»ÐèÒªÉÙÁ¿µÄÁ¬½ÓÇëÇó¾Í¿ÉÒÔÇë·¢³ÉǧÉÏÍò´ÎµÄÍøÕ¾»ØÓ¦´ÎÊý£¬15±ÈÌØµÄÁ¬½ÓÇëÇó»áÒý·¢134KBµÄ»ØÓ¦£¬ÕâÖÖ¹¥»÷Ч¹û·Å´óÁË10000±¶£¡Êµ¼Ê²âÊÔÖУ¬ÉõÖÁ»¹ÄÜÒý·¢750KBµÄ»ØÓ¦£¬¹¥»÷Ч¹û·Å´óÁË51200±¶£¡
1.¼ì²âÊÇ·ñ´æÔڱȱàºÅΪCVE-2018-1000115µÄ©¶´£»
2.¼ì²âMemcacheÆäËüµÄÏà¹ØÂ©¶´£¬±£Ö¤Memcache·þÎñÕý³£ÔËÐС£
£¨½¨ÒéʹÓÃÌì¾µ´àÈõɨÃèÓë¹ÜÀíϵͳ£¬Éý¼¶ÖÁ60700151Éý¼¶°ü£©
×î¼òµ¥µÄÔ¤·À´ëÊ©ÊÇϵͳ·À»ðǽ£¬½ûÓûòÏÞÖÆ11211µÄUDP¶Ë¿ÚºÅ¡£ÓÉÓÚMemcached»º´æ·þÎñÆ÷ĬÈÏ¿ªÆô¼àÌýINADDR_ANYºÍUDP¹¦Ð§£¬ÏµÍ³¹ÜÀíÔ±¿ÉÒÔÔÚÅäÖÃÖйرÕUDP¡£
ÎÊÕï¶þºÅ£ºEximÈÎÒâÃüÁîÖ´ÐÐ
EximÔÚ´¦ÖÃÎļþµÄʱºò£¬ÔÚϵͳÖе¯³öÁ˼ÆËãÆ÷£¬ÕâÊÇÔõô»ØÊ£¿
ƾ¾ÝÏÖÓÐʱ¼äµã£¬¸Ã»¼ÕßÓ¦¸Ã´æÔÚ±àºÅΪCVE-2018-6789µÄ©¶´£¬Õâ¸ö©¶´¿ÉÒÔÈÃEximÖ´ÐÐÈÎÒâ´úÂ룬½¨Ò鼰ʱÅŲ顣
¸Ã©¶´Ô´ÓÚbase64½âÂ뺯ÊýÖеÄÒ»¸ö»º³åÇøÒç³öÎÊÌ⡣ͨÀýÏÂbase64±àÂëµÄ×Ö·û´®µÄ³¤¶ÈΪ4µÄ±¶Êý£¬µ«ÊÇÓпÉÄÜÔÚ´«Êä»òÕß¶ñÒâ½á¹¹µÄÇé¿öϵ¼Ö³¤¶È²»Îª4µÄ±¶Êý£¬ÖÂʹ³¤¶È¼ÆËã´íÎó¡£Í¨¹ý¸Ã©¶´£¬¹¥»÷Õß¿ÉÒÔÈÆ¹ý·À»¤»úÖÆÔÚÊÜÓ°ÏìµÄÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ´úÂë¡£Èô¹¥»÷ʵÑéʧ°ÜÈԿɵ¼Ö¾ܾø·þÎñ¡£
1. ¼ì²âÊÇ·ñ´æÔÚ±àºÅCVE-2018-6789©¶´£»
2. ¼ì²âEximÆäËüµÄÏà¹ØÂ©¶´£¬±£Ö¤Exim·þÎñÕý³£ÔËÐС£
£¨½¨ÒéʹÓÃÌì¾µ´àÈõɨÃèÓë¹ÜÀíϵͳ£¬Éý¼¶ÖÁ60700151Éý¼¶°ü£©
ÎÊÕïÈýºÅ£ºCisco¾Ü¾ø·þÎñ¹¥»÷
CiscoµÄ4786¶Ë¿Ú×ÜÄܽÓÊÕµ½Òì³£Êý¾Ý£¬ÓÐʱºòCisco»á¾Ü¾ø·þÎñ£¬ÓÐʱºò»áÔÚÈÕÖ¾Öп´µ½Ö´ÐзÇͨÀýÃüÁ
4786¶Ë¿ÚÊÇ˼¿Æ IOS ºÍ IOS-XE ϵͳ Smart Install ClientµÄ·þÎñ¶Ë¿Ú£¬¸Ã»¼ÕßÓ¦¸Ã»¼ÓбàºÅΪCVE-2018-0171µÄCiscoÏà¹ØÂ©¶´¡£
˼¿Æ IOS ºÍ IOS-XE ϵͳ Smart Install Client ´úÂëÖдæÔÚÒ»´¦»º³åÇøÕ»Òç³ö©¶´£¨CVE-2018-0171£©¡£¹¥»÷Õß¿ÉÒÔÔ¶³ÌÏò TCP 4786 ¶Ë¿Ú·¢ËÍÒ»¸ö¶ñÒâÊý¾Ý°ü£¬ÀûÓøÃ©¶´£¬´¥·¢Ä¿±êÉ豸µÄÕ»Òç³ö©¶´Ôì³ÉÉ豸¾Ü¾ø·þÎñ£¨DoS£©»òÔÚÔì³ÉÔ¶³ÌÃüÁîÖ´ÐУ¬¹¥»÷Õß¿ÉÒÔÔ¶³Ì¿ØÖÆÊܵ½Â©¶´Ó°ÏìµÄÍøÂçÉ豸¡£
1. ¼ì²âÊÇ·ñ´æÔÚ±àºÅCVE-018-0171µÄ©¶´£» 2. ¼ì²âCiscoÆäËüµÄÏà¹ØÂ©¶´£¬±£Ö¤Cisco·þÎñÕý³£ÔËÐС£
£¨½¨ÒéʹÓÃÌì¾µ´àÈõɨÃèÓë¹ÜÀíϵͳ£¬Éý¼¶ÖÁ60700151Éý¼¶°ü£©
ÎÊÕïËĺţºWeblogic·´ÐòÁл¯ÈÎÒâÃüÁîÖ´ÐÐ
Weblogic×î½ü×Ü»áÖ´ÐзÇÊÚȨÃüÁÊÇ·ñÓдëʩȷ¶¨È·ÈÏÊÇ·ñ´æÔÚ·´ÐòÁл¯Â©¶´£¿
ƾ¾ÝÃèÊö£¬ÓпÉÄÜ´æÔÚjava·´ÐòÁл¯Â©¶´£¬½¨Òé¶Ôjava·´ÐòÁл¯Ïà¹ØÂ©¶´½øÐÐÑéÖ¤£»
Java·´ÐòÁл¯ÊÇÖ¸°Ñ×Ö½ÚÐòÁлָ´ÎªJava¹¤¾ßµÄ¹ý³Ì£¬ObjectInputStreamÀàµÄreadObject()ÒªÁìÓÃÓÚ·´ÐòÁл¯¡£Ì»Â¶»ò¼ä½Ó̻¶·´ÐòÁл¯API£¬µ¼ÖÂÓû§¿ÉÒÔ²Ù×÷´«ÈëÊý¾Ý£¬¹¥»÷Õß¿ÉÒÔ¾«ÐĽṹ·´ÐòÁл¯¹¤¾ß²¢Ö´ÐжñÒâ´úÂë¡£
1.ÑéÖ¤java·´ÐòÁл¯Ïà¹ØÂ©¶´,±àºÅΪCVE-2016-0638¡¢CVE-2016-3510¡¢CVE-2017-10271¡¢CVE-2017-3248¡¢CVE-2015-4852¡¢CVE-2015-4852£»
2.¼ì²âweblogicÆäËüµÄÏà¹ØÂ©¶´£¬±£Ö¤weblogic·þÎñÕý³£ÔËÐС£
£¨½¨ÒéʹÓÃÌì¾µ´àÈõɨÃèÓë¹ÜÀíϵͳ£¬Éý¼¶ÖÁ60700151Éý¼¶°ü£¬Ê¹Óé¶´ÑéÖ¤¹¦Ð§£©
¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú©ɨ²úÎïÖÐÐÄ
¶¶È¦Îª¶Ä¶øÉú©ɨ²úÎïÖÐÐľ۽¹ÓÚÍøÂç×ʲú´àÈõÐÔÄþ¾²ÆÀ¹À¡¢¼ì²âºÍÐÞ¸´£»Ñз¢ÁËÕë¶ÔÄþ¾²·çÏÕ¸÷¸ö½×¶ÎµÄÄþ¾²²úÎï¼°·þÎñ£»²úÎï°üÂÞ£ºÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳ¡¢Ìì¾µwebÓ¦Óüì²âϵͳ¡¢Ìì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳ-¹¤¿Ø×¨Óð桢¹¤¿ØÎÞËðÆÀ¹Àϵͳ¡¢Â©¶´ÐÞ¸´¹ÜÀíϵͳ¡¢Ì쾵©¶´¹ÜÀíÆ½Ì¨¡¢¹¤¿ØÂ©¶´ÍÚ¾òϵͳ¡£
¶¶È¦Îª¶Ä¶øÉú´àÈõÐÔÆÀ¹ÀºÍ¹ÜÀí²úÎï×å