Ó×Ö÷ £¬¡°Ìì¾µ¡±Ç°À´ÎÊÕïÀ²~

°ä²¼¹¦·ò 2018-04-09


°Ù»¨Æë·Å¡¢ÍòÁø´¹ÌÐ

±¾¸ÃÊǸö̤ÇàÉÍ´º¡¢ÐÀÐÀÏòÈٵĺü¾½Ú

È»¶ø°²È«È¦È´Î´ÔøÏûÍ£

ÔÚ¾­ÀúÁË¡°ÈÛ¶Ï¡±ºÍ¡°¹í»ê¡±µÄÏ´Àñºó

ÿ¸öÍøÂ簲ȫÈ˶¼Ê±¿Ì¾¯Ìè×Å

ËæÊ±·ÀÓùÐÂÒ»ÂÖ¶ñÒâ¹¥»÷

 

Õâ²»

±¦ÔËÀ³¹Ù·½ÍøÕ¾Â©É¨ÍŶӾͿªÆôÁË¡°Ìì¾µÎÊÕïģʽ¡±

¡ý¡ý¡ý




ÎÊÕïÒ»ºÅ£ºmemcache·Å´ó¹¥»÷


²¡ÇéÃèÊö

 

memcachedµÄ·þÎñÒì³£·¢°ü £¬µ¼ÖÂϵͳ×ÊÔ´ÑÏÖØ £¬Õâô´óµÄÊý¾ÝÁ¿»á²»»á¶Ô´ËÍâÍøÂçÉ豸Ôì³ÉÓ°Ï죿

 

³õ²½Õï¶Ï

 

Òì³£·¢°ü £¬×ÊÔ´ÑÏÖØ £¬·¢°üÖ÷ÕŵØÖ·Ã÷È· £»¸Ã»¼Õß´æÔÚ±àºÅΪCVE-2018-1000115µÄMemcache Óйطì϶ £¬Í¨¹ý¸Ã·ì϶ £¬Òѱ»ÓÃÓÚ·Å´ó»Ø¾ø·þÎñ¹¥»÷È⼦ £¬½¨ÒéʵʱÅŲé¡£


²¡ÇéµÀÀí

 

memcached·Å´ó¹¥»÷ £¬ºÚ¿Íͨ¹ýÌØ¶¨µÄµÄIPµØÖ·ÏòÍøÕ¾µÄ»º´æ·þÎñÆ÷UDP¶Ë¿Ú11211 £¬·¢³ö¼ÙÒªÇó £¬×îÖÕÒý·¢´ó¹æÄ£µÄ²¢·¢»¹Ó¦¡£¾ÝÍøÂ簲ȫ¹«Ë¾·ÖÎö £¬Ö»±ØÒªÉÙÁ¿µÄÏνÓÒªÇó¾ÍÄܹ»Çë·¢³ÉǧÉÏÍò´ÎµÄÍøÕ¾»ØÓ¦´ÎÊý £¬15±ÈÌØµÄÏνÓÒªÇó»áÒý·¢134KBµÄ»ØÓ¦ £¬ÕâÖÖ¹¥»÷³ÉЧ·Å´óÁË10000±¶£¡ÏÖʵ²âÊÔÖÐ £¬ÉõÖÁ»¹ÄÜÒý·¢750KBµÄ»ØÓ¦ £¬¹¥»÷³ÉЧ·Å´óÁË51200±¶£¡


²¡Çé´¦·½

 

1.¼ì²âÊÇ·ñ´æÔڱȱàºÅΪCVE-2018-1000115µÄ·ì϶ £»

2.¼ì²âMemcacheÆäËüµÄÓйطì϶ £¬±£ÕÏMemcache·þÎñÕý³£ÔËÐС£

£¨½¨ÒéʹÓÃÌì¾µ´àÈõɨÃèÓëÖÎÀíϵͳ £¬Éý¼¶ÖÁ60700151Éý¼¶°ü£©


»º½â´ëÊ©

 

×îµ¥Ò»µÄÔ¤·À´ëÊ©ÊÇϵͳ·À»ðǽ £¬½ûÓûòÏÞ¶È11211µÄUDP¶Ë±êÓï¡£ÓÉÓÚMemcached»º´æ·þÎñÆ÷ĬÈÏ¿ªÆô¼àÌýINADDR_ANYºÍUDPÖ°ÄÜ £¬ÏµÍ³ÖÎÀíÔ±Äܹ»ÔÚÅäÖÃÖйعØUDP¡£



ÎÊÕï¶þºÅ£ºEximËÁÒâºÅÁîÖ´ÐÐ


²¡ÇéÃèÊö

 

EximÔÚ´¦ÖÃÎļþµÄʱ³½ £¬ÔÚϵͳÖе¯³öÁËÍÆËãÆ÷ £¬ÕâÊÇÔõô»ØÊ£¿


³õ²½Õï¶Ï

 

ƾ¾ÝÏÖÓй¦·òµã £¬¸Ã»¼ÕßÓ¦¸Ã´æÔÚ±àºÅΪCVE-2018-6789µÄ·ì϶ £¬Õâ¸ö·ì϶Äܹ»ÈÃEximÖ´ÐÐËÁÒâ´úÂë £¬½¨ÒéʵʱÅŲé¡£


²¡ÇéµÀÀí

 

¸Ã·ì϶ԴÓÚbase64½âÂ뺯ÊýÖеÄÒ»¸ö»º³åÇøÒç³öÎÊÌ⡣ͨÀýÏÂbase64±àÂëµÄ×Ö·û´®µÄ³¤¶ÈΪ4µÄ±¶Êý £¬µ«ÊÇÓпÉÄÜÔÚ´«Êä»òÕß¶ñÒâ»ú¹ØµÄÇé¿öϵ¼Ö³¤¶È²»Îª4µÄ±¶Êý £¬ÒÔÖÁ³¤¶ÈÍÆËãÃýÎó¡£Í¨¹ý¸Ã·ì϶ £¬¹¥»÷ÕßÄܹ»Èƹý·À»¤»úÔìÔÚÊÜÓ°ÏìµÄÀûÓ÷¨Ê½¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£Èô¹¥»÷³¢ÊÔʧ°ÜÈԿɵ¼Ö»ؾø·þÎñ¡£

 

²¡Çé´¦·½

 

1. ¼ì²âÊÇ·ñ´æÔÚ±àºÅCVE-2018-6789·ì϶ £»

2. ¼ì²âEximÆäËüµÄÓйطì϶ £¬±£ÕÏExim·þÎñÕý³£ÔËÐС£

£¨½¨ÒéʹÓÃÌì¾µ´àÈõɨÃèÓëÖÎÀíϵͳ £¬Éý¼¶ÖÁ60700151Éý¼¶°ü£©



ÎÊÕïÈýºÅ£ºCisco»Ø¾ø·þÎñ¹¥»÷


²¡ÇéÃèÊö

 

CiscoµÄ4786¶Ë¿Ú×ÜÄܽӹܵ½Òì³£Êý¾Ý £¬ÓÐʱ³½Cisco»á»Ø¾ø·þÎñ £¬ÓÐʱ³½»áÔÚÈÕÖ¾Öп´µ½Ö´Ðм«¶È¹æºÅÁ

 

³õ²½Õï¶Ï

 

4786¶Ë¿ÚÊÇ˼¿Æ IOS ºÍ IOS-XE ϵͳ Smart Install ClientµÄ·þÎñ¶Ë¿Ú £¬¸Ã»¼ÕßÓ¦¸Ã»¼ÓбàºÅΪCVE-2018-0171µÄCiscoÓйطì϶¡£

 

²¡ÇéµÀÀí

 

˼¿Æ IOS ºÍ IOS-XE ϵͳ Smart Install Client ´úÂëÖдæÔÚÒ»´¦»º³åÇøÕ»Òç¶Âí½Å£¨CVE-2018-0171£©¡£¹¥»÷ÕßÄܹ»Ô¶³ÌÏò TCP 4786 ¶Ë¿Ú·¢ËÍÒ»¸ö¶ñÒâÊý¾Ý°ü £¬ÀûÓø÷ì϶ £¬´¥·¢Ö¸±êÉ豸µÄÕ»Òç¶Âí½ÅÔì³ÉÉ豸»Ø¾ø·þÎñ£¨DoS£©»òÔÚÔì³ÉÔ¶³ÌºÅÁîÖ´ÐÐ £¬¹¥»÷ÕßÄܹ»Ô¶³Ì½ÚÔìÊܵ½·ì϶ӰÏìµÄÍøÂçÉ豸¡£

 

²¡Çé´¦·½

 

1. ¼ì²âÊÇ·ñ´æÔÚ±àºÅCVE-018-0171µÄ·ì϶ £» 2. ¼ì²âCiscoÆäËüµÄÓйطì϶ £¬±£ÕÏCisco·þÎñÕý³£ÔËÐС£

£¨½¨ÒéʹÓÃÌì¾µ´àÈõɨÃèÓëÖÎÀíϵͳ £¬Éý¼¶ÖÁ60700151Éý¼¶°ü£©



ÎÊÕïËĺţºWeblogic·´ÐòÁл¯ËÁÒâºÅÁîÖ´ÐÐ


²¡ÇéÃèÊö

 

Weblogic×î½ü×Ü»áÖ´ÐзÇÊÚȨºÅÁî £¬ÊÇ·ñÓз¨×ÓÈ·¶¨È·ÈÏÊÇ·ñ´æÔÚ·´ÐòÁл¯·ì϶£¿

 

³õ²½Õï¶Ï

 

ƾ¾ÝÃèÊö £¬ÓпÉÄÜ´æÔÚjava·´ÐòÁл¯·ì϶ £¬½¨Òé¶Ôjava·´ÐòÁл¯Óйطì϶½øÐÐÑéÖ¤ £»


²¡ÇéµÀÀí

 

Java·´ÐòÁл¯ÊÇÖ¸°Ñ×Ö½ÚÐòÁи´Ô­ÎªJava¶ÔÏóµÄ¹ý³Ì £¬ObjectInputStreamÀàµÄreadObject()²½ÖèÓÃÓÚ·´ÐòÁл¯¡£Â¶³ö»ò¼ä½Ó¶³ö·´ÐòÁл¯API £¬µ¼ÖÂÓû§Äܹ»²Ù×÷´«ÈëÊý¾Ý £¬¹¥»÷ÕßÄܹ»¾«ÐÄ»ú¹Ø·´ÐòÁл¯¶ÔÏó²¢Ö´ÐжñÒâ´úÂë¡£


²¡Çé´¦·½

 

1.ÑéÖ¤java·´ÐòÁл¯Óйطì϶,±àºÅΪCVE-2016-0638¡¢CVE-2016-3510¡¢CVE-2017-10271¡¢CVE-2017-3248¡¢CVE-2015-4852¡¢CVE-2015-4852 £»

2.¼ì²âweblogicÆäËüµÄÓйطì϶ £¬±£ÕÏweblogic·þÎñÕý³£ÔËÐС£

£¨½¨ÒéʹÓÃÌì¾µ´àÈõɨÃèÓëÖÎÀíϵͳ £¬Éý¼¶ÖÁ60700151Éý¼¶°ü £¬Ê¹Ó÷ì϶ÑéÖ¤Ö°ÄÜ£©

 

¹ØÓÚ±¦ÔËÀ³¹Ù·½ÍøÕ¾Â©É¨²úÆ·ÖÐÐÄ

 

±¦ÔËÀ³¹Ù·½ÍøÕ¾Â©É¨²úÆ·ÖÐÐľ۽¹ÓÚÍøÂç×ʲú´àÈõÐÔ°²È«ÆÀ¹À¡¢¼ì²âºÍ½¨¸´ £»Ñз¢ÁËÕë¶Ô°²È«·çÏÕ¸÷¸ö½×¶ÎµÄ°²È«²úÆ·¼°·þÎñ £»²úÆ·Ô̺¬£ºÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ¡¢Ìì¾µwebÀûÓüì²âϵͳ¡¢Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ-¹¤¿Ø×¨Óð桢¹¤¿ØÎÞËðÆÀ¹Àϵͳ¡¢·ì϶½¨¸´ÖÎÀíϵͳ¡¢Ìì¾µ·ì϶ÖÎÀíÆ½Ì¨¡¢¹¤¿Ø·ì϶ÍÚ¾òϵͳ¡£

 


±¦ÔËÀ³¹Ù·½ÍøÕ¾´àÈõÐÔÆÀ¹ÀºÍÖÎÀí²úÆ·×å


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾