OpenSMTPDÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-02-26

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-8794£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


OpenSMTPDСÓÚ6.6.4p1°æ±¾


Îó²î¸ÅÊö


OpenBSDÊǼÓÄôóOpenBSDÏîÄ¿×éµÄÒ»Ì×¿çÆ½Ì¨µÄ¡¢»ùÓÚBSDµÄÀàUNIX²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£OpenSMTPDÊÇOpenBSDÍŶӿª·¢µÄÒ»¸öÃâ·ÑµÄЧÀÍÆ÷¶ËSMTPЭÒéʵÏÖ£¬£¬£¬Í¨¹ýRFC5321½ç˵£¬£¬£¬Ò²ÊÇOpenBSDÏîÄ¿µÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£


Çå¾²Ñо¿Ö°Ô±ÔÚÓʼþЧÀÍÆ÷OpenSMTPDÖз¢Ã÷Ò»¸öеÄÑÏÖØÎó²î£¨CVE-2020-8794£©£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔ¶³ÌʹÓøÃÎó²îÒÔrootÓû§Éí·ÝÔËÐÐShellÏÂÁî¡£¡£¡£¡£¡£¡£OpenSMTPDÓ¦ÓÃÔÚ¶à¸ö»ùÓÚUnixµÄϵͳÉÏ£¬£¬£¬°üÀ¨FreeBSD¡¢NetBSD¡¢macOS¡¢Linux£¨Alpine¡¢Arch¡¢Debian¡¢Fedora¡¢CentOS£©¡£¡£¡£¡£¡£¡£


¸ÃÎó²îÓ°ÏìÁËOpenSMTPDµÄĬÈÏ×°Ö㬣¬£¬Ñо¿Ö°Ô±Ö¸³ö¸ÃÎÊÌâÊÇÔÚ2015Äê12ÔÂÒýÈëµÄ£¬£¬£¬µ«Ö»ÓÐÔÚ2018Äê5ÔÂÖ®ºóÐû²¼µÄOpenSMTPD°æ±¾ÉϲſÉÒÔʹÓÃËüÒÔrootÌØÈ¨Ö´ÐдúÂë¡£¡£¡£¡£¡£¡£ÔÚÒÔǰµÄ°æ±¾ÖУ¬£¬£¬shellÏÂÁî¿ÉÒÔ×÷Ϊ·ÇrootÏÂÁîÔËÐС£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


Ñо¿Ö°Ô±³Æ½«ÓÚ2ÔÂ26ÈÕÐû²¼PoC£¬£¬£¬²¢ÇÒÒѾ­ÔÚÄ¿½ñµÄOpenBSD6.6¡¢OpenBSD5.9¡¢Debian10¡¢Debian11ºÍFedora31ÉÏÀֳɲâÊÔ£¬£¬£¬¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


OpenSMTPD 6.6.4p1ÖÐÒѾ­ÐÞ¸´Á˸ÃÎó²î£¬£¬£¬½¨ÒéÓû§¾¡¿ì×°ÖøüУºhttps://www.mail-archive.com/misc@opensmtpd.org/msg04888.html¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/new-critical-rce-bug-in-openbsd-smtp-server-threatens-linux-distros/