Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | OpenSSL CMSÄ£¿£¿£¿£¿£¿éÕ»»º³åÇøÒç³öÎó²î |
CVE ID | CVE-2025-15467 |
Îó²îÀàÐÍ | Õ»»º³åÇøÒç³ö | ·¢Ã÷ʱ¼ä | 2026-1-30 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
OpenSSLÊÇÒ»¸öÆÕ±éʹÓõĿªÔ´¼ÓÃܿ⣬£¬£¬ÌṩʵÏÖÇ徲ͨѶÐÒéµÄ¹¤¾ßºÍ¿â£¬£¬£¬Ö§³Ö¶àÖÖ¼ÓÃÜËã·¨£¬£¬£¬°üÀ¨¶Ô³Æ¼ÓÃÜ¡¢·Ç¶Ô³Æ¼ÓÃÜ¡¢¹þÏ£Ëã·¨ºÍÊý×ÖÖ¤Êé´¦Öóͷ£µÈ¡£¡£¡£¡£ËüÊÇÐí¶à»¥ÁªÍøÐÒ飨ÈçSSL/TLS£©ºÍÓ¦ÓóÌÐòµÄ»ù´¡×é¼þ£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚWebЧÀÍÆ÷¡¢µç×ÓÓʼþ¡¢ÐéÄâ˽ÈËÍøÂ磨VPN£©µÈÁìÓò¡£¡£¡£¡£OpenSSLÒÔÆä¸ßЧ¡¢ÎÞаºÍǿʢµÄ¹¦Ð§³ÉΪ¿ªÔ´¼ÓÃܽâ¾ö¼Æ»®µÄÐÐÒµ±ê×¼£¬£¬£¬²¢Ìṩ¿ª·¢ÕßÓѺõÄAPI½Ó¿ÚÓÃÓÚ¼ÓÃܲÙ×÷ºÍÇ徲ͨѶ¡£¡£¡£¡£
2026Äê1ÔÂ30ÈÕ£¬£¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½OpenSSLÖеÄÒ»¸ö¸ßΣջ»º³åÇøÒç³öÎó²î£¬£¬£¬±£´æÓÚÆÊÎöCMS£¨¼ÓÃÜÐÂÎÅÓï·¨£©AuthEnvelopedData½á¹¹Ê±¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚOpenSSLÔÚ´¦Öóͷ£Ê¹ÓÃAEAD¼ÓÃÜËã·¨£¨ÈçAES-GCM£©µÄÐÂÎÅʱ£¬£¬£¬Î´¶ÔASN.1²ÎÊýÖеijõʼ»¯ÏòÁ¿£¨IV£©³¤¶È¾ÙÐÐУÑ飬£¬£¬Ö±½Ó½«Æä¸´ÖƵ½Àο¿¾ÞϸµÄÕ»»º³åÇøÖУ¬£¬£¬µ¼ÖÂÕ»Òç³ö¡£¡£¡£¡£ÓÉÓÚ¸ÃÀú³Ì±¬·¢ÔÚÉí·ÝÑéÖ¤ºÍÍêÕûÐÔУÑé֮ǰ£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½á¹¹ÌØÖÆµÄ¶ñÒâCMSÐÂÎÅ£¬£¬£¬Ê¹Ó󬳤IVÖµ´¥·¢Òç³ö¡£¡£¡£¡£´ËÎó²î¿ÉÄܵ¼ÖÂЧÀÍÍ߽⣬£¬£¬´Ó¶øÒý·¢¾Ü¾øÐ§ÀÍ£¨DoS£©¹¥»÷£¬£¬£¬ÉõÖÁÔÚijЩÇéÐÎÏ£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÕ»Òç³öʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/openssl/openssl/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2025-15467/https://openssl-library.org/news/secadv/20260127.txt/