¡¾Îó²îͨ¸æ¡¿Apache James¾Ü¾øÐ§ÀÍÎó²î(CVE-2024-37358)

Ðû²¼Ê±¼ä 2025-02-07

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Apache James¾Ü¾øÐ§ÀÍÎó²î

CVE   ID

CVE-2024-37358

Îó²îÀàÐÍ

¾Ü¾øÐ§ÀÍ

·¢Ã÷ʱ¼ä

2025-02-07

Îó²îÆÀ·Ö

8.6

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Apache James£¨Java Apache Mail Enterprise Server£©ÊÇÒ»¸ö¿ªÔ´µÄÓʼþЧÀÍÆ÷£¬£¬£¬£¬£¬£¬Ö§³ÖSMTP¡¢IMAP ºÍ POP3 ЭÒé¡£¡£¡£Ëü»ùÓÚJava¿ª·¢£¬£¬£¬£¬£¬£¬¿ÉÀ©Õ¹²¢Ö§³ÖÄ£¿£¿£¿ £¿£¿é»¯¼Ü¹¹£¬£¬£¬£¬£¬£¬ÊÊÓÃÓÚÆóÒµ¼¶Óʼþ´¦Öóͷ£¡£¡£¡£James ¾ß±¸Óʼþ´æ´¢¡¢Óû§ÖÎÀí¡¢Óʼþ¹ýÂ˵ȹ¦Ð§£¬£¬£¬£¬£¬£¬²¢¿É¼¯³ÉLDAP¡¢Êý¾Ý¿âµÈÍⲿϵͳ£¬£¬£¬£¬£¬£¬ÊÊÓÃÓÚ¹¹½¨×Ô½ç˵Óʼþ½â¾ö¼Æ»®¡£¡£¡£


2025Äê2ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½Apache¹Ù·½Ðû²¼ÁËCVE-2024-37358Îó²îͨ¸æ¡£¡£¡£¸ÃÎó²îÓ°ÏìApache James£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀÄÓÃIMAP×ÖÃæÁ¿£¨IMAP literals£©´¥·¢ÎÞÏÞÖÆµÄÄÚ´æ·ÖÅɺͳ¤Ê±¼äÅÌË㣬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©¡£¡£¡£¸ÃÎó²î¿É±»ÈÏÖ¤Óû§ºÍδÈÏÖ¤Óû§Ê¹Ó㬣¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂЧÀÍÆ÷×ÊÔ´ºÄ¾¡£¡£¡£¬£¬£¬£¬£¬£¬Ó°ÏìÕý³£ÓªÒµÔËÐС£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Apache James Server ¡Ü 3.7.5
3.8.0 ¡Ü Apache James Server ¡Ü 3.8.1


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÔÚ 3.7.6 ºÍ 3.8.2 °æ±¾ÖÐÐÞ¸´´ËÎÊÌ⣬£¬£¬£¬£¬£¬Í¨¹ýÏÞÖÆ¶Ô IMAP ×ÖÃæÁ¿µÄ²»µ±Ê¹Ó㬣¬£¬£¬£¬£¬ÒÔ½µµÍÎó²îΣº¦¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://james.apache.org/download.cgi#Apache_James_Server/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://lists.apache.org/thread/1pxsh11v5s3fkvhnqvkmlqwt3fgpcrqc
https://nvd.nist.gov/vuln/detail/CVE-2024-37358
https://github.com/apache/james-project/commit/6dd3ad9ea1f6a9bc887d2c7af3f5aa30a60ec769
https://github.com/apache/james-project/commit/b2f3c06edfd37b409121bf04c56a6f026048a77e