Memcached ´úÂëÎÊÌâÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-05-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-11596£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º7.5


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾memcached 1.5.14֮ǰ°æ±¾


Îó²î¸ÅÊö


MemcachedÊÇÃÀ¹ú²¼À³µÂ-·Æ×ÈÅÉ´ä¿Ë£¨Brad Fitzpatrick£©Èí¼þ¿ª·¢ÕßµÄÒ»Ì׸ßÐÔÄܵÄÂþÑÜʽÄڴ湤¾ß»º´æÏµÍ³¡£¡£¡£¸Ãϵͳͨ¹ýÔÚÄÚ´æÖлº´æÊý¾ÝºÍ¹¤¾ßÀ´ïÔÌ­¶ÁÈ¡Êý¾Ý¿âµÄ´ÎÊý£¬£¬£¬£¬£¬£¬´Ó¶øÌá¸ßÍøÕ¾»á¼ûËÙÂÊ¡£¡£¡£


memcached 1.5.14֮ǰ°æ±¾Öеġ®lru mode¡¯ºÍ¡®lru temp_ttl¡¯ÏÂÁîÖб£´æ´úÂëÎÊÌâÎó²î¡£¡£¡£¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·µÄ´úÂ뿪·¢Àú³ÌÖб£´æÉè¼Æ»òʵÏÖ²»µ±µÄÎÊÌâ¡£¡£¡£ 


Îó²îÑéÖ¤


EXP£ºhttps://github.com/memcached/memcached/issues/474¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º


https://github.com/memcached/memcached/commit/d35334f368817a77a6bd1f33c6a5676b2c402c02¡£¡£¡£ 


²Î¿¼Á´½Ó


http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201904-1303