¡¾Îó²îͨ¸æ¡¿Apache Tomcat ¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-41079£©
Ðû²¼Ê±¼ä 2021-09-160x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-41079 | ʱ ¼ä | 2021-09-15 |
Àà ÐÍ | DoS | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé
TomcatÊÇÓÉApacheÈí¼þ»ù½ð»áÏÂÊôµÄJakartaÏîÄ¿¿ª·¢µÄÒ»¸öServletÈÝÆ÷£¬£¬£¬£¬£¬ÊµÏÖÁ˶ÔServletºÍJavaServer Page£¨"text-indent:28px;line-height:150%">2021Äê9ÔÂ15ÈÕ£¬£¬£¬£¬£¬ApacheÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´ÁËTomcatÖеÄÒ»¸ö¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2021-41079£©¡£¡£¡£¡£¡£¡£µ±Tomcat±»ÉèÖÃΪʹÓÃNIO+OpenSSL»òNIO2+OpenSSL¾ÙÐÐTLSʱ£¬£¬£¬£¬£¬¿ÉÒÔʹÓöñÒâÊý¾Ý°ü´¥·¢ÎÞÏÞÑ»·£¬£¬£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Apache Tomcat 10.0.0-M1 µ½ 10.0.2
Apache Tomcat 9.0.0-M1 µ½ 9.0.43
Apache Tomcat 8.5.0 µ½ 8.5.63
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¸ÃÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìµÄÓû§ÊµÊ±Éý¼¶¸üе½ÒÔϰ汾£º
Apache Tomcat 10.0.4 »ò¸ü¸ß°æ±¾
Apache Tomcat 9.0.44 »ò¸ü¸ß°æ±¾
Apache Tomcat 8.5.64 »ò¸ü¸ß°æ±¾
×¢£º¸ÃÎó²îÒÑÔÚApache Tomcat 10.0.3 °æ±¾£¨Ðû²¼Î´Í¨¹ý£©ÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://tomcat.apache.org/
0x03 ²Î¿¼Á´½Ó
http://mail-archives.apache.org/mod_mbox/www-announce/202109.mbox/%3Ce1079445-c7b5-c4b0-3155-85c4cfc839ea@apache.org%3E
https://tomcat.apache.org/download-10.cgi
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-09-16 | Ê×´ÎÐû²¼ |
0x05 Îĵµ¸½Â¼
CNVD£ºwww.cnvd.org.cn
CNNVD£ºwww.cnnvd.org.cn
CVE£ºcve.mitre.org
CVSS£ºwww.first.org
NVD£ºnvd.nist.gov
0x06 ¹ØÓÚ¼øºÚµ£±£Íø
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬»ñÈ¡¸ü¶à×ÊѶ£º