Apache HTTP Server¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-08-11

0x00 ·ì϶¸ÅÊö



²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Ó°ÏìÁìÓò

Apache HTTP Server

CVE-2020-9490

DOS

¸ßΣ

ÊÇ

Apache HTTP Server 2.4.20-2.4.43

CVE-2020-11984

BO

ÖÐΣ

ÊÇ

Apache HTTP Server 2.4.32-2.4.43

CVE-2020-11993

DOS

ÖÐΣ

ÊÇ

Apache HTTP Server 2.4.20-2.4.43


0x01 ·ì϶ÏêÇé


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


2020Äê8ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬£¬Apache¹Ù·½°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËApache HTTP ServerÖеÄÁ½¸ö»Ø¾ø·þÎñ·ì϶£¨CVE-2020-9490/CVE-2020-11993£©ºÍÒ»¸ö»º³åÇøÒç¶Âí½Å£¨CVE-2020-11984£©£¬£¬£¬£¬£¬£¬£¬¾ßÌåÐÅÏ¢ÈçÏ£º

Apache HTTP Server HTTP/2»Ø¾ø·þÎñ·ì϶£¨CVE-2020-9490£©

¸Ã·ì϶ԴÓÚÔÚHTTP/2ÒªÇóÖÐͨ¹ý»ú¹Ø¡¯Cache-Digest¡¯Öµ¿ÉÔì³É·þÎñ±ÀÀ££¬£¬£¬£¬£¬£¬£¬µ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£¡£ ¡£¡£¿£¿£¿£¿£¿£¿£¿ÉһʱÅú¸Ä¡°H2Push off¡±À´»º½â¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£

Apache HTTP Server HTTP/2»º³åÇøÒç¶Âí½Å£¨CVE-2020-11984£©

mod_proxy_uwsgiÊÇApacheµÄÒ»¸ö·þÎñÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬ÖØÒªÌṩ¶ÔuwsgiºÍ̸µÄÖ§³Ö¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã·ì϶ԴÓÚmod_proxy_uwsgiÖдæÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÐÅϢй¶»òÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£ ¡£¡£

Apache HTTP Server HTTP/2»Ø¾ø·þÎñ·ì϶£¨CVE-2020-11993£©

¸Ã·ì϶ԴÓÚApache°æ±¾2.4.20ÖÁ2.4.43ΪHTTP2Ä£¿£¿£¿£¿£¿£¿£¿éºÍijЩÁ÷Á¿±ßԵģʽÆôÓøú×Ù/µ÷ÊÔʱ£¬£¬£¬£¬£¬£¬£¬ÔÚÃýÎóµÄÏνÓÉÏÖ´ÐÐÁËÈÕÖ¾¼Í¼Óï¾ä£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö²¢·¢Ê¹ÓÃÄÚ´æ³Ø£¬£¬£¬£¬£¬£¬£¬½µµÍ·¨Ê½Óë²Ù×÷ϵͳµÄ»úÄÜ¡£¡£¡£¡£¡£¡£ ¡£¡£¿£¿£¿£¿£¿£¿£¿ÉһʱÔÚ¡°info¡±ÉÏÅäÖÃmod_http2µÄLogLevelÀ´»º½â¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£


0x02 ´ëÖý¨Òé


¹Ù·½ÒѰ䲼×îа汾£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º

https://httpd.apache.org/download.cgi


0x03 ÓйØÐÂÎÅ


https://www.tenable.com/plugins/nessus/139436


0x04 ²Î¿¼Á´½Ó


https://httpd.apache.org/security/vulnerabilities_24.html


0x05 ¹¦·òÏß


2020-08-07 Apache°ä²¼°²È«²¼¸æ

2020-08-11 VSRC°ä²¼·ì϶¹«¸æ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website