OpenBSD¶à¸ö°²È«·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2019-12-06

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-19521 £¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-19520 £¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-19522 £¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-19519 £¬£¬£¬£¬ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


OpenBSD 6.5

OpenBSD 6.6


·ì϶¸ÅÊö


OpenBSDÊǼÓÄôóOpenBSDÏîÄ¿×éµÄÒ»Ì×¿çÆ½Ì¨µÄ¡¢»ùÓÚBSDµÄÀàUNIX²Ù×÷ϵͳ £¬£¬£¬£¬ £¬´æÔÚÈçÏÂËĸö¸ßΣ°²È«·ì϶£º

CVE-2019-19521£ºÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶ £¬£¬£¬£¬ £¬¹¥»÷Õ߿ɽèÖú-schallengeÓû§ÃûÀûÓø÷ìÏ¶ÈÆ¹ýÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£


CVE-2019-19520£ºxlockÖеı¾µØÌáȨ·ì϶ £¬£¬£¬£¬ £¬¸Ã·ì϶ԴÓÚxenocara/lib/mesa/src/loader/loader.cÎļþûÓÐÕýÈ·´¦ÖÃdlopen¡£¡£¡£¡£¡£±¾µØ¹¥»÷Õß¿Éͨ¹ýÌá½»LIBGL_DRIVERS_PATH»·¾³±äÁ¿ÀûÓø÷ì϶»ñÈ¡¡°auth¡±×éµÄȨÏÞ¡£¡£¡£¡£¡£


CVE-2019-19522£º¾­ÓÉS/KeyºÍYubiKeyµÄ±¾µØÌáȨ·ì϶ £¬£¬£¬£¬ £¬ÓÉÓÚ¶Ôͨ¹ý·ÇĬÈÏÅäÖá°S/Key¡±ºÍ¡°YubiKey¡±µÄÊÚȨ»úÔì²Ù×÷²»ÕýÈ· £¬£¬£¬£¬ £¬Òò¶ø¾ßÓÓ×°auth¡±×éȨÏ޵ı¾µØ¹¥»÷Õß¿ÉÄÜ»ñÈ¡ root Óû§µÄÆëȫȨÏÞ¡£¡£¡£¡£¡£


CVE-2019-19519£ºsu Öеı¾µØÌáÈ¡·ì϶ £¬£¬£¬£¬ £¬ÓÉÓÚ su µÄÆäÖÐÒ»¸öÖØÒªº¯ÊýÖдæÔÚÒ»¸öÂß¼­ÃýÎó £¬£¬£¬£¬ £¬µ¼Ö±¾µØ¹¥»÷Õß¿ÉÄÜͨ¹ýÀûÓà su µÄ¨CL Ñ¡ÏîʵÏÖËÁÒâÓû§µÄµÇ¼Àࣨͨ³£²»Ô̺¬ root£©¡£¡£¡£¡£¡£±¾µØ¹¥»÷Õß¿ÉÄÜÀûÓà su µÄ¨CL Ñ¡Ï¡°Ò»ÏòÑ­»· £¬£¬£¬£¬ £¬Ö±µ½ÊäÈëÕýÈ·µÄÓû§ÃûÃÜÂë×éºÏΪֹ¡±£©ÒÔ×Ô¼ºµÄÉí·ÝµÇ¼µ«Ê¹ÓõÄÊÇÆäËüÓû§µÄµÇ¼ÀࣨÈôÊǹ¥»÷Õß²»ÔÚ¡°wheel¡±×éÖÐÔòÊÇrootµÄµÇ¼Àࣩ £¬£¬£¬£¬ £¬ÓÉÓÚ¸ÃÀà±äÁ¿Ö»ÉèÖÃÒ»´Î²¢ÇÒ²»»á³ÁÖᣡ£¡£¡£¡£


·ì϶ÑéÖ¤


POC£ºhttps://www.qualys.com/2019/12/04/cve-2019-19521/authentication-vulnerabilities-openbsd.txt?_ga=2.58244398.587934852.1575530822-682141427.1570559125¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶ £¬£¬£¬£¬ £¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.openbsd.org/errata66.html¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2019/12/openbsd-authentication-vulnerability.html