OpenSMTPDÔ¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-02-26

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-8794£¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


OpenSMTPDÓ×ÓÚ6.6.4p1°æ±¾


·ì϶¸ÅÊö


OpenBSDÊǼÓÄôóOpenBSDÏîÄ¿×éµÄÒ»Ì×¿çÆ½Ì¨µÄ¡¢»ùÓÚBSDµÄÀàUNIX²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£¡£OpenSMTPDÊÇOpenBSDÍŶӿª·¢µÄÒ»¸öÃâ·ÑµÄ·þÎñÆ÷¶ËSMTPºÍ̸ʵÏÖ£¬£¬£¬£¬ £¬£¬Í¨¹ýRFC5321½ç˵£¬£¬£¬£¬ £¬£¬Ò²ÊÇOpenBSDÏîÖ÷ÕÅÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£¡£


°²È«×êÑÐÈËÔ±ÔÚÓʼþ·þÎñÆ÷OpenSMTPDÖз¢ÏÖÒ»¸öеÄÑϳÁ·ì϶£¨CVE-2020-8794£©£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÄܹ»Ô¶³ÌÀûÓø÷ì϶ÒÔrootÓû§Éí·ÝÔËÐÐShellºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£OpenSMTPDÀûÓÃÔÚ¶à¸ö»ùÓÚUnixµÄϵͳÉÏ£¬£¬£¬£¬ £¬£¬Ô̺¬FreeBSD¡¢NetBSD¡¢macOS¡¢Linux£¨Alpine¡¢Arch¡¢Debian¡¢Fedora¡¢CentOS£©¡£¡£¡£¡£¡£¡£¡£¡£


¸Ã·ì϶ӰÏìÁËOpenSMTPDµÄĬÈÏ×°Ö㬣¬£¬£¬ £¬£¬×êÑÐÈËÔ±Ö¸³ö¸ÃÎÊÌâÊÇÔÚ2015Äê12ÔÂÒýÈëµÄ£¬£¬£¬£¬ £¬£¬µ«Ö»ÓÐÔÚ2018Äê5ÔÂÖ®ºó°ä²¼µÄOpenSMTPD°æ±¾ÉÏÄÜÁ¦¹»ÀûÓÃËüÒÔrootÌØÈ¨Ö´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÒÔǰµÄ°æ±¾ÖУ¬£¬£¬£¬ £¬£¬shellºÅÁîÄܹ»×÷Ϊ·ÇrootºÅÁîÔËÐС£¡£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


×êÑÐÈËÔ±³Æ½«ÓÚ2ÔÂ26ÈÕ°ä²¼PoC£¬£¬£¬£¬ £¬£¬²¢ÇÒÒѾ­ÔÚµ±Ç°µÄOpenBSD6.6¡¢OpenBSD5.9¡¢Debian10¡¢Debian11ºÍFedora31Éϳɹ¦²âÊÔ£¬£¬£¬£¬ £¬£¬¡£¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


OpenSMTPD 6.6.4p1ÖÐÒѾ­½¨¸´Á˸÷ì϶£¬£¬£¬£¬ £¬£¬½¨ÒéÓû§¾¡¿ì×°ÖøüУºhttps://www.mail-archive.com/misc@opensmtpd.org/msg04888.html¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/new-critical-rce-bug-in-openbsd-smtp-server-threatens-linux-distros/