¡¾Îó²îͨ¸æ¡¿Rsync »º³åÇøÒç³öÎó²î(CVE-2024-12084)

Ðû²¼Ê±¼ä 2025-01-17

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Rsync »º³åÇøÒç³öÎó²î

CVE   ID

CVE-2024-12084

Îó²îÀàÐÍ

»º³åÇøÒç³ö

·¢Ã÷ʱ¼ä

2025-01-17

Îó²îÆÀ·Ö

9.8

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


rsyncÊÇÒ»ÖÖ³£ÓõÄÎļþͬ²½ºÍ´«Ê乤¾ß£¬£¬£¬£¬£¬£¬£¬Ö§³Ö¸ßЧµÄÔöÁ¿±¸·Ý¡£¡£¡£¡£¡£Í¨¹ý½ÏÁ¿Ô´ºÍÄ¿µÄÎļþµÄ²î±ð£¬£¬£¬£¬£¬£¬£¬rsyncÖ»´«Êä¸ü»Ú¸ÄµÄ²¿·Ö£¬£¬£¬£¬£¬£¬£¬´Ó¶ø½ÚÔ¼´ø¿íºÍʱ¼ä¡£¡£¡£¡£¡£ËüÖ§³ÖÍâµØºÍÔ¶³ÌÎļþ´«Ê䣬£¬£¬£¬£¬£¬£¬³£ÓÃÓÚ±¸·Ý¡¢Í¬²½ºÍ°²ÅÅʹÃü¡£¡£¡£¡£¡£


2025Äê1ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½RsyncÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬È·ÈÏÆäЧÀͶËÀú³ÌRsyncd±£´æ»º³åÇøÒç³öÎó²î£¨CVE-2024-12084£©¡£¡£¡£¡£¡£Îó²î¼¶±ðΪÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8·Ö£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚrsyncÊØ»¤Àú³ÌÖÐδ׼ȷ´¦Öóͷ£¹¥»÷Õß¿ØÖƵÄУÑéºÍ³¤¶È£¨s2length£©¡£¡£¡£¡£¡£µ±MAX_DIGEST_LENÁè¼ÝÀο¿µÄSUM_LENGTH£¨16×Ö½Ú£©Ê±£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚsum2»º³åÇøÖÐдÈëÔ½½çÊý¾Ý£¬£¬£¬£¬£¬£¬£¬´Ó¶ø´¥·¢¶ÑÄÚ´æÒç³öÎÊÌâ¡£¡£¡£¡£¡£


³ýÁË»º³åÇøÒç³öÎó²î£¨CVE-2024-12084£©Í⣬£¬£¬£¬£¬£¬£¬Rsync»¹±£´æÒÔÏÂÎó²î£º


ÐÅϢй¶Îó²î£¨CVE-2024-12085£©£ºrsyncÊØ»¤Àú³Ì±£´æÐÅϢй¶Îó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý²Ù¿ØÐ£ÑéºÍ³¤¶È£¨s2length£©£¬£¬£¬£¬£¬£¬£¬Òý·¢Óëδ³õʼ»¯ÄÚ´æµÄ½ÏÁ¿£¬£¬£¬£¬£¬£¬£¬Öð×Ö½Úй¶ջÊý¾Ý¡£¡£¡£¡£¡£Îó²î¼¶±ðΪ¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.5·Ö¡£¡£¡£¡£¡£


Îļþй¶Îó²î£¨CVE-2024-12086£©£ºrsync±£´æÎļþй¶Îó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽṹУÑéºÍ£¬£¬£¬£¬£¬£¬£¬Öð×Ö½Úö¾Ù¿Í»§¶Ëí§ÒâÎļþÄÚÈÝ¡£¡£¡£¡£¡£Îó²î¼¶±ðΪÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ6.1·Ö¡£¡£¡£¡£¡£


·¾¶±éÀúÎó²î£¨CVE-2024-12087£©£ºrsync±£´æÂ·¾¶±éÀúÎó²î£¬£¬£¬£¬£¬£¬£¬¶ñÒâЧÀÍÆ÷¿ÉʹÓ÷ûºÅÁ´½ÓÈÆ¹ý£¬£¬£¬£¬£¬£¬£¬½«ÎļþдÈë¿Í»§¶ËµÄ·ÇÄ¿µÄĿ¼¡£¡£¡£¡£¡£Îó²î¼¶±ðΪÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ6.5·Ö¡£¡£¡£¡£¡£


·¾¶±éÀúÎó²î£¨CVE-2024-12088£©£ºrsyncÔÚʹÓÃ`--safe-links`Ñ¡Ïîʱδ׼ȷÑéÖ¤·ûºÅÁ´½ÓÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬µ¼Ö·¾¶±éÀúÎó²î£¬£¬£¬£¬£¬£¬£¬¿ÉÄܽ«ÎļþдÈë·ÇÔ¤ÆÚĿ¼¡£¡£¡£¡£¡£Îó²î¼¶±ðΪÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ6.5·Ö¡£¡£¡£¡£¡£


·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þÎó²î£¨CVE-2024-12747£©£ºrsync±£´æ·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃʱ»úÈÆ¹ýĬÈÏÐÐΪ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶Ãô¸ÐÐÅÏ¢²¢¿ÉÄܵ¼ÖÂȨÏÞÌáÉý¡£¡£¡£¡£¡£Îó²î¼¶±ðΪÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ5.6·Ö¡£¡£¡£¡£¡£


ÆäÖУ¬£¬£¬£¬£¬£¬£¬»º³åÇøÒç³öÎó²î£¨CVE-2024-12084£©ÓëÐÅϢй¶Îó²î£¨CVE-2024-12085£©¿ÉÁªºÏʹÓ㬣¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


CVE-2024-12084£¨»º³åÇøÒç³öÎó²î£©£º3.2.7=
CVE-2024-12085£¨ÐÅϢй¶Îó²î£©£ºRsync < 3.4.0
CVE-2024-12086£¨Îļþй¶Îó²î£©£ºRsync < 3.4.0
CVE-2024-12087£¨Â·¾¶±éÀúÎó²î£©£ºRsync < 3.4.0
CVE-2024-12088£¨Â·¾¶±éÀúÎó²î£©£ºRsync < 3.4.0

CVE-2024-12747£¨·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þÎó²î£©£ºRsync < 3.4.0


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


ÏÖÔÚ¸ÃÎó²îÒѾ­ÐÞ¸´£¬£¬£¬£¬£¬£¬£¬Ç뾡¿ìÏÂÔØ²¢Éý¼¶ÖÁ×îа汾


ÏÂÔØÁ´½Ó£º
https://rsync.samba.org/download.html


3.2 ÔÝʱ²½·¥


CVE-2024-12084 (»º³åÇøÒç³öÎó²î)£¬£¬£¬£¬£¬£¬£¬½ûÓÃSHA*Ö§³Ö£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÒÔϱàÒëÑ¡ÏCFLAGS=-DDISABLE_SHA512_DIGEST ºÍ CFLAGS=-DDISABLE_SHA256_DIGEST¡£¡£¡£¡£¡£
CVE-2024-12085 (ÐÅϢй¶Îó²î)£¬£¬£¬£¬£¬£¬£¬±àÒëʱʹÓà -ftrivial-auto-var-init=zero£¬£¬£¬£¬£¬£¬£¬½«Õ»ÄÚÈݳõʼ»¯ÎªÁ㣬£¬£¬£¬£¬£¬£¬ÒÔ±ÜÃâÐÅϢй¶¡£¡£¡£¡£¡£
CVE-2024-12086 (Îļþй¶Îó²î)£¬£¬£¬£¬£¬£¬£¬ÏÞÖÆ¶Ô¿Í»§¶ËÎļþÄÚÈݵĻá¼û£¬£¬£¬£¬£¬£¬£¬È·±£Ð§ÀÍÆ÷½öÄܹ»»á¼ûÊÚȨµÄÎļþ¡£¡£¡£¡£¡£
CVE-2024-12087 (·¾¶±éÀúÎó²î)£¬£¬£¬£¬£¬£¬£¬½ûÓÃ--inc-recursiveÑ¡Ïî»òÇ¿»¯·ûºÅÁ´½ÓÑéÖ¤£¬£¬£¬£¬£¬£¬£¬È·±£ÎļþдÈë½öÏÞÓÚÄ¿µÄĿ¼ÄÚ¡£¡£¡£¡£¡£
CVE-2024-12088 (·¾¶±éÀúÎó²î)£¬£¬£¬£¬£¬£¬£¬ÔöÇ¿¶Ô--safe-linksÑ¡ÏîÏ·ûºÅÁ´½ÓÄ¿µÄµÄÑéÖ¤£¬£¬£¬£¬£¬£¬£¬×èֹ·¾¶±éÀúÎó²îµÄ±¬·¢¡£¡£¡£¡£¡£
CVE-2024-12747 (·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þÎó²î)£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÔöÇ¿·ûºÅÁ´½Ó´¦Öóͷ£ÖеľºÌ¬Ìõ¼þ±£»£»£» £»£»£»¤£¬£¬£¬£¬£¬£¬£¬×èÖ¹¹¥»÷ÕßÈÆ¹ýĬÈÏÐÐΪ²¢Ð¹Â¶Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.openwall.com/lists/oss-security/2025/01/14/3
https://kb.cert.org/vuls/id/952657
https://nvd.nist.gov/vuln/detail/cve-2024-12084
https://nvd.nist.gov/vuln/detail/CVE-2024-12085
https://nvd.nist.gov/vuln/detail/CVE-2024-12086
https://nvd.nist.gov/vuln/detail/CVE-2024-12087
https://nvd.nist.gov/vuln/detail/CVE-2024-12088
https://nvd.nist.gov/vuln/detail/CVE-2024-12747
https://download.samba.org/pub/rsync/NEWS