OpenSMTPDÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-02-26Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-8794£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
OpenSMTPDСÓÚ6.6.4p1°æ±¾
Îó²î¸ÅÊö
OpenBSDÊǼÓÄôóOpenBSDÏîÄ¿×éµÄÒ»Ì×¿çÆ½Ì¨µÄ¡¢»ùÓÚBSDµÄÀàUNIX²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£¡£OpenSMTPDÊÇOpenBSDÍŶӿª·¢µÄÒ»¸öÃâ·ÑµÄЧÀÍÆ÷¶ËSMTPÐÒéʵÏÖ£¬£¬£¬£¬£¬Í¨¹ýRFC5321½ç˵£¬£¬£¬£¬£¬Ò²ÊÇOpenBSDÏîÄ¿µÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£¡£¡£
Çå¾²Ñо¿Ö°Ô±ÔÚÓʼþЧÀÍÆ÷OpenSMTPDÖз¢Ã÷Ò»¸öеÄÑÏÖØÎó²î£¨CVE-2020-8794£©£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔ¶³ÌʹÓøÃÎó²îÒÔrootÓû§Éí·ÝÔËÐÐShellÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£OpenSMTPDÓ¦ÓÃÔÚ¶à¸ö»ùÓÚUnixµÄϵͳÉÏ£¬£¬£¬£¬£¬°üÀ¨FreeBSD¡¢NetBSD¡¢macOS¡¢Linux£¨Alpine¡¢Arch¡¢Debian¡¢Fedora¡¢CentOS£©¡£¡£¡£¡£¡£¡£¡£¡£
¸ÃÎó²îÓ°ÏìÁËOpenSMTPDµÄĬÈÏ×°Ö㬣¬£¬£¬£¬Ñо¿Ö°Ô±Ö¸³ö¸ÃÎÊÌâÊÇÔÚ2015Äê12ÔÂÒýÈëµÄ£¬£¬£¬£¬£¬µ«Ö»ÓÐÔÚ2018Äê5ÔÂÖ®ºóÐû²¼µÄOpenSMTPD°æ±¾ÉϲſÉÒÔʹÓÃËüÒÔrootÌØÈ¨Ö´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÒÔǰµÄ°æ±¾ÖУ¬£¬£¬£¬£¬shellÏÂÁî¿ÉÒÔ×÷Ϊ·ÇrootÏÂÁîÔËÐС£¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
Ñо¿Ö°Ô±³Æ½«ÓÚ2ÔÂ26ÈÕÐû²¼PoC£¬£¬£¬£¬£¬²¢ÇÒÒѾÔÚÄ¿½ñµÄOpenBSD6.6¡¢OpenBSD5.9¡¢Debian10¡¢Debian11ºÍFedora31ÉÏÀֳɲâÊÔ£¬£¬£¬£¬£¬¡£¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
OpenSMTPD 6.6.4p1ÖÐÒѾÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì×°ÖøüУºhttps://www.mail-archive.com/misc@opensmtpd.org/msg04888.html¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/new-critical-rce-bug-in-openbsd-smtp-server-threatens-linux-distros/


¾©¹«Íø°²±¸11010802024551ºÅ