¡¾Îó²îͨ¸æ¡¿Apache James¾Ü¾øÐ§ÀÍÎó²î(CVE-2024-37358)
Ðû²¼Ê±¼ä 2025-02-07Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Apache James¾Ü¾øÐ§ÀÍÎó²î | ||
CVE ID | CVE-2024-37358 | ||
Îó²îÀàÐÍ | ¾Ü¾øÐ§ÀÍ | ·¢Ã÷ʱ¼ä | 2025-02-07 |
Îó²îÆÀ·Ö | 8.6 | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Apache James£¨Java Apache Mail Enterprise Server£©ÊÇÒ»¸ö¿ªÔ´µÄÓʼþЧÀÍÆ÷£¬£¬£¬£¬£¬£¬Ö§³ÖSMTP¡¢IMAP ºÍ POP3 ÐÒé¡£¡£¡£Ëü»ùÓÚJava¿ª·¢£¬£¬£¬£¬£¬£¬¿ÉÀ©Õ¹²¢Ö§³ÖÄ£¿£¿£¿£¿£¿é»¯¼Ü¹¹£¬£¬£¬£¬£¬£¬ÊÊÓÃÓÚÆóÒµ¼¶Óʼþ´¦Öóͷ£¡£¡£¡£James ¾ß±¸Óʼþ´æ´¢¡¢Óû§ÖÎÀí¡¢Óʼþ¹ýÂ˵ȹ¦Ð§£¬£¬£¬£¬£¬£¬²¢¿É¼¯³ÉLDAP¡¢Êý¾Ý¿âµÈÍⲿϵͳ£¬£¬£¬£¬£¬£¬ÊÊÓÃÓÚ¹¹½¨×Ô½ç˵Óʼþ½â¾ö¼Æ»®¡£¡£¡£
2025Äê2ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½Apache¹Ù·½Ðû²¼ÁËCVE-2024-37358Îó²îͨ¸æ¡£¡£¡£¸ÃÎó²îÓ°ÏìApache James£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀÄÓÃIMAP×ÖÃæÁ¿£¨IMAP literals£©´¥·¢ÎÞÏÞÖÆµÄÄÚ´æ·ÖÅɺͳ¤Ê±¼äÅÌË㣬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©¡£¡£¡£¸ÃÎó²î¿É±»ÈÏÖ¤Óû§ºÍδÈÏÖ¤Óû§Ê¹Ó㬣¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂЧÀÍÆ÷×ÊÔ´ºÄ¾¡£¡£¡£¬£¬£¬£¬£¬£¬Ó°ÏìÕý³£ÓªÒµÔËÐС£¡£¡£