Zip SlipÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-06-06Îó²î±àºÅ
CVE-2018-8008
CVE-2018-8009
CVE-2018-1261
CVE-2018-1263
CVE-2018-1002200
CVE-2018-1002201
CVE-2018-1002202
CVE-2018-1002203
CVE-2018-1002204
CVE-2018-1002205
CVE-2018-1002206
CVE-2018-1002207
Îó²î¼¶±ð
ÑÏÖØ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
Zip SlipÎó²î ¡°í§ÒâÎļþÁýÕÖ¡±ºÍ¡°Ä¿Â¼±éÀú¡±ÎÊÌâµÄÁ¬Ïµ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö¹¥»÷Õß¿ÉÒÔ½«Îļþ½âѹËõµ½Õý³£½âѹËõ·¾¶Ö®Íâ²¢ÁýÕÖÃô¸ÐÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÈçÒªº¦OS¿â»òЧÀÍÆ÷ÉèÖÃÎļþ¡£¡£¡£¡£¡£ËäȻʹÓü¸ÖÖ±à³ÌÓïÑÔ±àдµÄ¿âÒÑÖª»áÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬ÀýÈçJavaScript£¬£¬£¬£¬£¬£¬£¬£¬Python£¬£¬£¬£¬£¬£¬£¬£¬Ruby£¬£¬£¬£¬£¬£¬£¬£¬.NET£¬£¬£¬£¬£¬£¬£¬£¬GoºÍGroovy£¬£¬£¬£¬£¬£¬£¬£¬µ«Õâ¸öÎÊÌâÖ÷ÒªÓ°ÏìJavaÉú̬ϵͳ¡£¡£¡£¡£¡£
Zip SlipÎó²îÊÇÔÚ±àÂëÆ÷¡¢²å¼þºÍ¿âʵÏÖ½âѹ¹éµµÎļþµÄÀú³ÌÖеÄÒ»¸öÎÊÌâ¡£¡£¡£¡£¡£ Ðí¶à´ò°üÃûÌ㬣¬£¬£¬£¬£¬£¬£¬°üÀ¨tar£¬£¬£¬£¬£¬£¬£¬£¬jar£¬£¬£¬£¬£¬£¬£¬£¬war£¬£¬£¬£¬£¬£¬£¬£¬cpio£¬£¬£¬£¬£¬£¬£¬£¬apk£¬£¬£¬£¬£¬£¬£¬£¬rarºÍ7z¶¼»áÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÕâ¸üÏñÊÇÂß¼ÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇÌØ¶¨µÄ±àÂë¹ýʧ¡£¡£¡£¡£¡£
¶à¸ö´óÐ͹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨Google¡¢Oracle¡¢IBM¡¢Apache¡¢ÑÇÂíÑ·µÈÔÚÄÚµÄÊýǧ¸öÏîÄ¿ÊÜÓ°Ï죨¼û£ºhttps://github.com/snyk/zip-slip-vulnerability£©¡£¡£¡£¡£¡£ËäÈ»£¬£¬£¬£¬£¬£¬£¬£¬ÕâÖÖÀàÐ͵ÄÎó²îÔçÒѱ£´æ£¬£¬£¬£¬£¬£¬£¬£¬µ«×î½üËüÒѾÔÚ¸ü¶àµÄÏîÄ¿ºÍ¿âÖÐÌåÏÖ³öÀ´¡£¡£¡£¡£¡£
ÊÜÓ°ÏìµÄ¿âºÍÏîÄ¿£º
ÊÜÓ°ÏìµÄ¿â£º
ÊÜÓ°ÏìµÄÏîÄ¿£º
Îó²îÐÎò
Zip SlipÊÇĿ¼±éÀúµÄÒ»ÖÖÐÎʽ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý´Ó´ò°üÎļþÖÐÌáÈ¡ÎļþÀ´Ê¹Óᣡ£¡£¡£¡£ Ŀ¼±éÀúÎó²îµÄÌõ¼þÊǹ¥»÷Õß¿ÉÒÔ»á¼ûÎļþϵͳÖÐÓ¦¸ÃפÁôµÄÄ¿µÄÎļþ¼ÐÖ®ÍâµÄ²¿·ÖÎļþϵͳ¡£¡£¡£¡£¡£ È»ºó£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÁýÕÖ¿ÉÖ´ÐÐÎļþ²¢Ô¶³ÌŲÓÃËüÃÇ£¬£¬£¬£¬£¬£¬£¬£¬»òÕßÆÚ´ýϵͳ»òÓû§Å²ÓÃËüÃÇ£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖÊܺ¦Õß»úеÉϵÄÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£¡£¡£´ËÎó²î»¹¿ÉÄÜͨ¹ýÁýÕÖÉèÖÃÎļþ»òÆäËûÃô¸Ð×ÊÔ´¶øÔì³ÉË𺦣¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜ»áÔÚ¿Í»§¶Ë£¨Óû§£©»úеºÍЧÀÍÆ÷ÉÏÊܵ½¹¥»÷¡£¡£¡£¡£¡£
Ò²¾ÍÊÇ˵£¬£¬£¬£¬£¬£¬£¬£¬Zip SlipÊÇ¡°í§ÒâÎļþÁýÕÖ¡±ºÍ¡°Ä¿Â¼±éÀú¡±ÎÊÌâµÄÁ¬Ïµ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö¹¥»÷Õß¿ÉÒÔ½«Îļþ½âѹËõµ½Õý³£½âѹËõ·¾¶Ö®Íâ²¢ÁýÕÖÃô¸ÐÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÈçÒªº¦OS¿â»òЧÀÍÆ÷ÉèÖÃÎļþ¡£¡£¡£¡£¡£
Îó²îPOC£ºhttps://github.com/snyk/zip-slip-vulnerability/tree/master/archives
ʹÓôËÎó²îÐèÒªµÄÁ½¸ö²¿·ÖÊDz»Ö´ÐÐÑéÖ¤¼ì²éµÄ¶ñÒâ¹éµµºÍÌáÈ¡´úÂë¡£¡£¡£¡£¡£ÈÃÎÒÃÇÒÀ´ÎÉó²éÕâÁ½²¿·Ö¡£¡£¡£¡£¡£Ê×ÏÈ£¬£¬£¬£¬£¬£¬£¬£¬zipÎļþµÄÄÚÈÝÔÚÌáȡʱÐèÒªÓÐÒ»¸ö»ò¶à¸öÍÑÀëÄ¿µÄĿ¼µÄÎļþ¡£¡£¡£¡£¡£ÔÚÏÂÃæµÄÀý×ÓÖУ¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ¿ÉÒÔ¿´µ½Ò»¸özipÎļþµÄÄÚÈÝ¡£¡£¡£¡£¡£ËüÓÐÁ½¸öÎļþ£¬£¬£¬£¬£¬£¬£¬£¬Ò»¸ögood.shÎļþ½«±»½âѹËõµ½Ä¿µÄĿ¼ÖУ¬£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öevil.shÎļþÕýÔÚʵÑé±éÀúĿ¼Ê÷ÒÔ·¿ª¸ùĿ¼£¬£¬£¬£¬£¬£¬£¬£¬È»ºó½«ÎļþÌí¼Óµ½tmpĿ¼ÖС£¡£¡£¡£¡£µ±ÄúʵÑécd .. ÔÚ¸ùĿ¼ÖÐʱ£¬£¬£¬£¬£¬£¬£¬£¬ÈÔÈ»»á·¢Ã÷×Ô¼ºÎ»ÓÚ¸ùĿ¼ÖУ¬£¬£¬£¬£¬£¬£¬£¬Òò´Ë¶ñÒâ·¾¶¿ÉÄܰüÀ¨¶à¸ö¼¶±ðµÄĿ¼ ../ ÔÚʵÑé±éÀúÃô¸ÐÎļþ֮ǰ£¬£¬£¬£¬£¬£¬£¬£¬ÓиüºÃµÄʱ»úµÖ´ï¸ùĿ¼¡£¡£¡£¡£¡£
Õâ¸özipÎļþµÄÄÚÈݱØÐèÊÖ¹¤ÖÆ×÷¡£¡£¡£¡£¡£Ö»¹Üzip¹æ·¶ÔÊÐí£¬£¬£¬£¬£¬£¬£¬£¬µµ°¸½¨É蹤¾ßͨ³£²»ÔÊÐíÓû§Ê¹ÓÃÕâЩ·¾¶Ìí¼ÓÎļþ¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÌØ¶¨µÄ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÕâЩ·¾¶½¨ÉèÎļþºÜÈÝÒס£¡£¡£¡£¡£
ÄúÐèҪʹÓôËÎó²îµÄµÚ¶þ¼þÊÂÊÇʹÓÃÄú×Ô¼ºµÄ´úÂë»ò¿âÀ´ÌáÈ¡¹éµµÎļþ¡£¡£¡£¡£¡£½âѹËõ´úÂëºöÂÔ´æµµÖÐÎļþ·¾¶µÄÑé֤ʱ±£´æ´ËÎó²î¡£¡£¡£¡£¡£ÏÂÃæÊÇÒ»¸öÒ×Êܹ¥»÷µÄ´úÂëÆ¬¶ÏµÄʾÀý£¨ÒÔJavaÏÔʾµÄʾÀý£©¡£¡£¡£¡£¡£
½â¾ö²½·¥
ÒÑÐÞ¸´µÄ¿âºÍÏîÄ¿Á´½Ó¼û£ºhttps://github.com/snyk/zip-slip-vulnerability
²Î¿¼×ÊÁÏ
https://github.com/snyk/zip-slip-vulnerability
http://7xkk1o.com1.z0.glb.clouddn.com/technical-whitepaper.pdf#page=8&zoom=auto,-99,199
https://github.com/snyk/zip-slip-vulnerability/tree/master/archives


¾©¹«Íø°²±¸11010802024551ºÅ