VxWorks¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ðû²¼Ê±¼ä 2019-07-31

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


1¡¢Åä¾°ÐÎò


Çå¾²Ñо¿Ö°Ô±ÔÚVxWorksÖз¢Ã÷ÁË11¸ö0dayÎó²î£¬£¬£¬VxWorksÊÇǶÈëʽװ±¸ÖÐʹÓÃ×îÆÕ±éµÄʵʱ²Ù×÷ϵͳ£¨RTOS£©Ö®Ò»£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚº½¿Õº½Ì죬£¬£¬¹ú·À£¬£¬£¬¹¤Òµ£¬£¬£¬Ò½ÁÆ£¬£¬£¬Æû³µµÈÁìÓò£¬£¬£¬È«ÇòÖÁÉÙ20ÒŲ́װ±¸Ê¹ÓÃʹÓÃVxWorks¡£¡£¡£¡£¡£ÕâЩÎó²î±»Í³³ÆÎªURGENT/11£¬£¬£¬ÓÉÓÚËüÃǹ²ÓÐ11¸ö£¬£¬£¬ÆäÖÐ6¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£

VxWorksÓÃ;ºÜÊÇÆÕ±é£¬£¬£¬ÀýÈçÍøÂçÉãÏñÍ·£¬£¬£¬ÍøÂç½»Á÷»ú£¬£¬£¬Â·ÓÉÆ÷£¬£¬£¬·À»ðǽ£¬£¬£¬VOIPµç»°£¬£¬£¬´òÓ¡»úºÍÊÓÆµ¾Û»á²úÆ·£¬£¬£¬ÒÔ¼°½»Í¨Ñ¶ºÅµÆ¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬VxWorks»¹±»Ö÷ҪϵͳʹÓ㬣¬£¬ÀýÈçSCADA£¬£¬£¬»ð³µ£¬£¬£¬µçÌݺ͹¤Òµ¿ØÖÆÆ÷£¬£¬£¬²¡È˼໤ÒÇ£¬£¬£¬ºË´Å¹²Õñ³ÉÏñÒÇÆ÷£¬£¬£¬ÎÀÐǵ÷ÖÆ½âµ÷Æ÷£¬£¬£¬ÉõÖÁÊÇ»ðÐÇ̽²âÆ÷¡£¡£¡£¡£¡£

2¡¢Îó²îÏêÇé


URGENT/11Îó²îÓ°Ïì×Ô6.5°æÒÔÉϵÄËùÓÐVxWorks°æ±¾¡£¡£¡£¡£¡£ÏÔÈ»ÔÚÒÑÍù13ÄêÖÐÐû²¼µÄËùÓÐVxWorks°æ±¾¶¼ÈÝÒ×Êܵ½¹¥»÷¡£¡£¡£¡£¡£

ÆäÖÐ6¸öÎó²î¿É´¥·¢Ô¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷£¬£¬£¬¶øÊ£ÏµÄÎó²î¿ÉÄܻᵼÖ¾ܾøÐ§ÀÍ£¬£¬£¬ÐÅϢй¶»òÂß¼­Îó²î¡£¡£¡£¡£¡£

Ô¶³ÌÖ´ÐдúÂëȱÏÝ£º


ÆÊÎöIPv4Ñ¡Ïîʱ¿ÍÕ»Òç³ö£¨CVE-2019-12256£©


ÓÉÓÚ¹ýʧ´¦Öóͷ£TCPµÄÖ¸Õë×ֶζøµ¼ÖµÄËĸöÄÚ´æËð»µÎó²î£¨CVE-2019-12255£¬£¬£¬CVE-2019-12260£¬£¬£¬CVE-2019-12261£¬£¬£¬CVE-2019-12263£©


ipdhcpcÖеÄDHCP Offer / ACKÆÊÎöÖеĶÑÒç³ö£¨CVE-2019-12257£©

DoS£¬£¬£¬ÐÅÏ¢×ß©ºÍÂß¼­È±ÏÝ£º


ͨ¹ýÃûÌùýʧµÄTCPÑ¡Ïî¾ÙÐÐTCPÅþÁ¬DoS£¨CVE-2019-12258£©


´¦Öóͷ£Î´¾­ÇëÇóµÄ·´ÏòARP»Ø¸´£¨Âß¼­È±ÏÝ£©£¨CVE-2019-12262£©


ipdhcpc DHCP¿Í»§¶Ë·ÖÅÉIPv4µÄÂß¼­È±ÏÝ£¨CVE-2019-12264£©


ÔÚIGMPÆÊÎöÖÐͨ¹ýNULLɨ³ýÒýÓõÄDoS£¨CVE-2019-12259£©


IGMPÐÅÏ¢×ß©ͨ¹ýIGMPv3ÌØ¶¨³ÉÔ±±¨¸æ£¨CVE-2019-12265£©

3¡¢ÐÞ¸´½¨Òé


VxWorksÒÑÌṩ²¹¶¡¸üУ¬£¬£¬¿ÉÔÚVxWorksÇå¾²ÖÐÐÄÐû²¼µÄWind River Security AlertÖÐÕÒµ½£º


https://www.windriver.com/security/
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/

4¡¢²Î¿¼Á´½Ó


https://www.windriver.com/security/
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
https://www.sonicwall.com/support/product-notification/?sol_id=190717234810906
https://security.business.xerox.com/en-us/