OpenSMTPDÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-02-26Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-8794£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
OpenSMTPDСÓÚ6.6.4p1°æ±¾
Îó²î¸ÅÊö
OpenBSDÊǼÓÄôóOpenBSDÏîÄ¿×éµÄÒ»Ì×¿çÆ½Ì¨µÄ¡¢»ùÓÚBSDµÄÀàUNIX²Ù×÷ϵͳ¡£¡£OpenSMTPDÊÇOpenBSDÍŶӿª·¢µÄÒ»¸öÃâ·ÑµÄЧÀÍÆ÷¶ËSMTPÐÒéʵÏÖ£¬£¬£¬£¬Í¨¹ýRFC5321½ç˵£¬£¬£¬£¬Ò²ÊÇOpenBSDÏîÄ¿µÄÒ»²¿·Ö¡£¡£
Çå¾²Ñо¿Ö°Ô±ÔÚÓʼþЧÀÍÆ÷OpenSMTPDÖз¢Ã÷Ò»¸öеÄÑÏÖØÎó²î£¨CVE-2020-8794£©£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔ¶³ÌʹÓøÃÎó²îÒÔrootÓû§Éí·ÝÔËÐÐShellÏÂÁî¡£¡£OpenSMTPDÓ¦ÓÃÔÚ¶à¸ö»ùÓÚUnixµÄϵͳÉÏ£¬£¬£¬£¬°üÀ¨FreeBSD¡¢NetBSD¡¢macOS¡¢Linux£¨Alpine¡¢Arch¡¢Debian¡¢Fedora¡¢CentOS£©¡£¡£
¸ÃÎó²îÓ°ÏìÁËOpenSMTPDµÄĬÈÏ×°Ö㬣¬£¬£¬Ñо¿Ö°Ô±Ö¸³ö¸ÃÎÊÌâÊÇÔÚ2015Äê12ÔÂÒýÈëµÄ£¬£¬£¬£¬µ«Ö»ÓÐÔÚ2018Äê5ÔÂÖ®ºóÐû²¼µÄOpenSMTPD°æ±¾ÉϲſÉÒÔʹÓÃËüÒÔrootÌØÈ¨Ö´ÐдúÂë¡£¡£ÔÚÒÔǰµÄ°æ±¾ÖУ¬£¬£¬£¬shellÏÂÁî¿ÉÒÔ×÷Ϊ·ÇrootÏÂÁîÔËÐС£¡£
Îó²îÑéÖ¤
Ñо¿Ö°Ô±³Æ½«ÓÚ2ÔÂ26ÈÕÐû²¼PoC£¬£¬£¬£¬²¢ÇÒÒѾÔÚÄ¿½ñµÄOpenBSD6.6¡¢OpenBSD5.9¡¢Debian10¡¢Debian11ºÍFedora31ÉÏÀֳɲâÊÔ£¬£¬£¬£¬¡£¡£
ÐÞ¸´½¨Òé
OpenSMTPD 6.6.4p1ÖÐÒѾÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì×°ÖøüУºhttps://www.mail-archive.com/misc@opensmtpd.org/msg04888.html¡£¡£
²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/new-critical-rce-bug-in-openbsd-smtp-server-threatens-linux-distros/


¾©¹«Íø°²±¸11010802024551ºÅ