OpenSMTPDÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-02-26Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-8794£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
OpenSMTPDСÓÚ6.6.4p1°æ±¾
Îó²î¸ÅÊö
OpenBSDÊǼÓÄôóOpenBSDÏîÄ¿×éµÄÒ»Ì×¿çÆ½Ì¨µÄ¡¢»ùÓÚBSDµÄÀàUNIX²Ù×÷ϵͳ¡£¡£¡£¡£OpenSMTPDÊÇOpenBSDÍŶӿª·¢µÄÒ»¸öÃâ·ÑµÄЧÀÍÆ÷¶ËSMTPÐÒéʵÏÖ£¬£¬Í¨¹ýRFC5321½ç˵£¬£¬Ò²ÊÇOpenBSDÏîÄ¿µÄÒ»²¿·Ö¡£¡£¡£¡£
Çå¾²Ñо¿Ö°Ô±ÔÚÓʼþЧÀÍÆ÷OpenSMTPDÖз¢Ã÷Ò»¸öеÄÑÏÖØÎó²î£¨CVE-2020-8794£©£¬£¬¹¥»÷Õß¿ÉÒÔÔ¶³ÌʹÓøÃÎó²îÒÔrootÓû§Éí·ÝÔËÐÐShellÏÂÁî¡£¡£¡£¡£OpenSMTPDÓ¦ÓÃÔÚ¶à¸ö»ùÓÚUnixµÄϵͳÉÏ£¬£¬°üÀ¨FreeBSD¡¢NetBSD¡¢macOS¡¢Linux£¨Alpine¡¢Arch¡¢Debian¡¢Fedora¡¢CentOS£©¡£¡£¡£¡£
¸ÃÎó²îÓ°ÏìÁËOpenSMTPDµÄĬÈÏ×°Ö㬣¬Ñо¿Ö°Ô±Ö¸³ö¸ÃÎÊÌâÊÇÔÚ2015Äê12ÔÂÒýÈëµÄ£¬£¬µ«Ö»ÓÐÔÚ2018Äê5ÔÂÖ®ºóÐû²¼µÄOpenSMTPD°æ±¾ÉϲſÉÒÔʹÓÃËüÒÔrootÌØÈ¨Ö´ÐдúÂë¡£¡£¡£¡£ÔÚÒÔǰµÄ°æ±¾ÖУ¬£¬shellÏÂÁî¿ÉÒÔ×÷Ϊ·ÇrootÏÂÁîÔËÐС£¡£¡£¡£
Îó²îÑéÖ¤
Ñо¿Ö°Ô±³Æ½«ÓÚ2ÔÂ26ÈÕÐû²¼PoC£¬£¬²¢ÇÒÒѾÔÚÄ¿½ñµÄOpenBSD6.6¡¢OpenBSD5.9¡¢Debian10¡¢Debian11ºÍFedora31ÉÏÀֳɲâÊÔ£¬£¬¡£¡£¡£¡£
ÐÞ¸´½¨Òé
OpenSMTPD 6.6.4p1ÖÐÒѾÐÞ¸´Á˸ÃÎó²î£¬£¬½¨ÒéÓû§¾¡¿ì×°ÖøüУºhttps://www.mail-archive.com/misc@opensmtpd.org/msg04888.html¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/new-critical-rce-bug-in-openbsd-smtp-server-threatens-linux-distros/


¾©¹«Íø°²±¸11010802024551ºÅ