VxWorks¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Ðû²¼Ê±¼ä 2019-07-31
1¡¢Åä¾°ÐÎò
VxWorksÓÃ;ºÜÊÇÆÕ±é£¬£¬£¬ÀýÈçÍøÂçÉãÏñÍ·£¬£¬£¬ÍøÂç½»Á÷»ú£¬£¬£¬Â·ÓÉÆ÷£¬£¬£¬·À»ðǽ£¬£¬£¬VOIPµç»°£¬£¬£¬´òÓ¡»úºÍÊÓÆµ¾Û»á²úÆ·£¬£¬£¬ÒÔ¼°½»Í¨Ñ¶ºÅµÆ¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬VxWorks»¹±»Ö÷ҪϵͳʹÓ㬣¬£¬ÀýÈçSCADA£¬£¬£¬»ð³µ£¬£¬£¬µçÌݺ͹¤Òµ¿ØÖÆÆ÷£¬£¬£¬²¡È˼໤ÒÇ£¬£¬£¬ºË´Å¹²Õñ³ÉÏñÒÇÆ÷£¬£¬£¬ÎÀÐǵ÷ÖÆ½âµ÷Æ÷£¬£¬£¬ÉõÖÁÊÇ»ðÐÇ̽²âÆ÷¡£¡£¡£¡£¡£
2¡¢Îó²îÏêÇé
ÆäÖÐ6¸öÎó²î¿É´¥·¢Ô¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷£¬£¬£¬¶øÊ£ÏµÄÎó²î¿ÉÄܻᵼÖ¾ܾøÐ§ÀÍ£¬£¬£¬ÐÅϢй¶»òÂß¼Îó²î¡£¡£¡£¡£¡£
Ô¶³ÌÖ´ÐдúÂëȱÏÝ£º
ÆÊÎöIPv4Ñ¡Ïîʱ¿ÍÕ»Òç³ö£¨CVE-2019-12256£©
ÓÉÓÚ¹ýʧ´¦Öóͷ£TCPµÄÖ¸Õë×ֶζøµ¼ÖµÄËĸöÄÚ´æËð»µÎó²î£¨CVE-2019-12255£¬£¬£¬CVE-2019-12260£¬£¬£¬CVE-2019-12261£¬£¬£¬CVE-2019-12263£©
DoS£¬£¬£¬ÐÅÏ¢×ß©ºÍÂ߼ȱÏÝ£º
ͨ¹ýÃûÌùýʧµÄTCPÑ¡Ïî¾ÙÐÐTCPÅþÁ¬DoS£¨CVE-2019-12258£©
´¦Öóͷ£Î´¾ÇëÇóµÄ·´ÏòARP»Ø¸´£¨Â߼ȱÏÝ£©£¨CVE-2019-12262£©
ipdhcpc DHCP¿Í»§¶Ë·ÖÅÉIPv4µÄÂ߼ȱÏÝ£¨CVE-2019-12264£©
ÔÚIGMPÆÊÎöÖÐͨ¹ýNULLɨ³ýÒýÓõÄDoS£¨CVE-2019-12259£©
3¡¢ÐÞ¸´½¨Òé
VxWorksÒÑÌṩ²¹¶¡¸üУ¬£¬£¬¿ÉÔÚVxWorksÇå¾²ÖÐÐÄÐû²¼µÄWind River Security AlertÖÐÕÒµ½£º
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
4¡¢²Î¿¼Á´½Ó
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
https://www.sonicwall.com/support/product-notification/?sol_id=190717234810906
https://security.business.xerox.com/en-us/