libsshЧÀͶËÈÏÖ¤ÈÆ¹ýÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-10-17

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-10933 £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


libssh 0.8.x - 0.8.3
libssh 0.7.x - 0.7.5

libssh 0.6.x


Îó²î¸ÅÊö


libssh 0.6 ¼°ÒÔÉϵİ汾 £¬£¬£¬£¬£¬£¬£¬ÔÚЧÀͶ˵ĴúÂëʵÏÖÖб£´æÉí·ÝÈÏÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£¡£ÔÚÏòЧÀͶËÈÏÖ¤µÄÁ÷³ÌÖÐ £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý½« SSH2_MSG_USERAUTH_REQUEST ÐÂÎÅÌæ»»Îª SSH2_MSG_USERAUTH_SUCCESS £¬£¬£¬£¬£¬£¬£¬¼´¿ÉÔÚÎÞÐèÈκÎÓÐÓÃÆ¾Ö¤µÄÇéÐÎÏÂÈÏÖ¤Àֳɣ¨½ØÍ¼À´×Ô Twitter Óû§ @svblxyz£©£º

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹¥»÷ÕßÀÖ³ÉʹÓôËÎó²î £¬£¬£¬£¬£¬£¬£¬¿ÉµÇÈëÄ¿µÄЧÀÍÆ÷½øÒ»²½¾ÙÐÐí§Òâ¶ñÒâ²Ù×÷¡£¡£¡£¡£¡£¡£¡£

ÁíÍâÖµµÃ˵Ã÷µÄÊÇ £¬£¬£¬£¬£¬£¬£¬OpenSSH Óë libssh ÊÇÁ½¸ö×ÔÁ¦µÄÏîÄ¿ £¬£¬£¬£¬£¬£¬£¬²¢ÇÒ OpenSSH ¹Ù·½Çå¾²ÍŶÓÏÖÔÚÒ²ÉÐδÐû²¼ÈκÎÓë´ËÎó²îÏà¹ØµÄÐÅÏ¢ £¬£¬£¬£¬£¬£¬£¬¹Ê OpenSSH Ó¦¸Ã²»ÊÜ´ËÎó²îÓ°Ïì¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC\EXP


ÐÞ¸´½¨Òé


libssh 0.8.x °æ±¾ÇëÉý¼¶µ½ 0.8.4
libssh 0.7.x °æ±¾ÇëÉý¼¶µ½ 0.7.6
https://www.libssh.org/2018/10/16/libssh-0-8-4-and-0-7-6-security-and-bugfix-release/
ÏÖÔÚ¸÷´ó¿¯ÐаæÖж¼ÔÝδ¶ÔÏìÓ¦package¾ÙÐиüР£¬£¬£¬£¬£¬£¬£¬ÏêϸÇéÐοÉÒÔ¹Ø×¢Ò»ÏÂÁ´½Ó
Debain
https://security-tracker.debian.org/tracker/CVE-2018-10933
ubuntu
https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-10933.html
opensuse
https://www.suse.com/security/cve/CVE-2018-10933/
redhat

¹Ù·½ÔÝδÐû²¼Í¨¸æ


²Î¿¼Á´½Ó


https://www.libssh.org/security/patches/stable-0.6_CVE-2018-10933.jmcd.patch01.txt
https://security.stackexchange.com/questions/195834/cve-2018-10933-bypass-ssh-authentication-libssh-vulnerability