Libarchive´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-12-04

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-18408£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º7.5


Ó°Ïì°æ±¾


Libarchive°æ±¾ < 3.4.0£»£»£»£»£»


Îó²î¸ÅÊö


libarchiveÊÇÒ»¿î¶àÃûÌô浵ºÍѹËõ¿â¡£¡£¡£Libarchive±»ÖÚ¶àLinuxºÍBSDϵͳµÄÎļþºÍ°ü¹ÜÀíÆ÷ʹÓã¨Ä¬ÈϰüÀ¨ÔÚDebian£¬£¬ £¬£¬£¬Ubuntu£¬£¬ £¬£¬£¬Gentoo£¬£¬ £¬£¬£¬Arch Linux£¬£¬ £¬£¬£¬FreeBSDºÍNetBSD¿¯ÐаæÖУ©£¬£¬ £¬£¬£¬ÒÔ¼°±»OS X ºÍChrome OSµÄ×é¼þºÍ¹¤¾ßʹÓᣡ£¡£LibarchiveÖ§³Öʵʱ»á¼û¶àÖÖѹËõÎļþÃûÌ㬣¬ £¬£¬£¬ºÃ±È7z¡¢zip¡¢cpio¡¢pax¡¢rar¡¢cab¡¢uuencode£¬£¬ £¬£¬£¬±»Öڶ࿪·¢Õ߯ձéʹÓÃÔÚ×Ô¼ºµÄÈí¼þ²úÆ·ÖУ¬£¬ £¬£¬£¬Ò»Ð©Ñ¹ËõÈí¼þ¡¢Óʼþϵͳ¡¢ÎļþÖÎÀí¹¤¾ßÉõÖÁÇå¾²Èí¼þÓ¦ÓÃÖÐÒ²ÕûºÏÁËLibarchive´úÂë¡£¡£¡£


libarchive 3.4.0֮ǰ°æ±¾ÖУ¬£¬ £¬£¬£¬µ±·ºÆðijЩ½âÂëʧ°Ü£¨ARCHIVE_FAILED£©ÇéÐÎʱ£¬£¬ £¬£¬£¬archive_read_support_format_rar.cÎļþµÄarchive_read_format_rar_read_data()º¯Êý±£´æUAFÎó²î£¨use-after-free£©¡£¡£¡£¹¥»÷ÕßʹÓÃÈ«ÐĽṹµÄѹËõÎļþ£¬£¬ £¬£¬£¬´¥·¢Libarchive¿âµÄARCHIVE_FAILEDºó£¬£¬ £¬£¬£¬Ê¹ÓÃÎó²îÖ´ÐжñÒâ´úÂë¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£


ÐÞ¸´½¨Òé


1.ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬ £¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://github.com/libarchive/libarchive/commit/b8592ecba2f9e451e1f5cb7ab6dcee8b8e7b3f60£»£»£»£»£»


2.Linux¸÷¿¯ÐаæÇå¾²¸üÐÂÐÅÏ¢ÈçÏ£º

Debian£ºhttps://security-tracker.debian.org/tracker/CVE-2019-18408

Ubuntu£ºhttps://usn.ubuntu.com/4169-1/

Gentoo£ºhttps://bugs.gentoo.org/show_bug.cgi?id=CVE-2019-18408

ArchLinux£ºhttps://www.archlinux.org/packages/?sort=&q=libarchive&maintainer=&flagged=£»£»£»£»£»

3.¹Ø×¢ÆäËü¿ÉÄܺÏÈëÁËLibarchive¿âµÄÈí¼þÏà¹ØÍ¨¸æ£¬£¬ £¬£¬£¬ÈçÊÜÓ°Ïìʵʱ¸üС£¡£¡£


²Î¿¼Á´½Ó


http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201910-1468