Exim Mail Server 5Ô¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-05-070x00 ·ì϶¸ÅÊö
EximÊÇÓɽ£ÇÅ´óѧ¿ª·¢µÄÐÂÎÅ´«Êä´úÀí£¨MTA£©£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒª±»¹¹½¨ÔÚÀàUnix²Ù×÷ϵͳÉÏ·¢Ëͺͽӹܵç×ÓÓʼþ¡£¡£¡£¡£¡£¡£¡£¡£ºÃ±È£¬£¬£¬£¬£¬£¬£¬£¬ËüÒÑԤװÔÚLinux¿¯Ðа棨ÈçDebian£©ÉÏ¡£¡£¡£¡£¡£¡£¡£¡£EximÄܹ»´¦ÖôóÁ¿»¥ÁªÍøÁ÷Á¿£¬£¬£¬£¬£¬£¬£¬£¬ÆäʹÓü«¶È¿í·º¡£¡£¡£¡£¡£¡£¡£¡£
2021Äê05ÔÂ04ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Qualys¹«¿ªÅû¶ÁËEximÓʼþ·þÎñÆ÷ÖеÄ21¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý×éºÏÀûÓÃÕâЩ·ì϶½øÐÐδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©£¬£¬£¬£¬£¬£¬£¬£¬»ñµÃrootÓû§È¨ÏÞºÍÈä³æÊ½ºáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

MTAÊǹ¥»÷Õ߸ÐÐËÖµÄÖ¸±ê£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃÇͨ³£¿£¿£¿£¿£¿£Äܹ»Í¨¹ýInternet½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬Ò»µ©±»ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¾ÍÄܹ»Åú¸ÄÓʼþ·þÎñÆ÷Éϵĵç×ÓÓʼþÉèÖ㬣¬£¬£¬£¬£¬£¬£¬²¢ÔÚÖ¸±êÓʼþ·þÎñÆ÷ÉÏ´´½¨ÐÂÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£È¥Ä꣬£¬£¬£¬£¬£¬£¬£¬EximÖеķìÏ¶Ôø³ÉΪAPTµÄÖ¸±ê¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝShodanµÄËÑË÷£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°Ô¼ÄªÓÐ400Íǫ̀Exim·þÎñÆ÷Ö±½Ó¶³öÔÚ»¥ÁªÍøÉÏ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÚ±¾´Î¹«¿ªµÄ21¸ö·ì϶ÖУ¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ10¸öÄܹ»±»Ô¶³ÌÀûÓᣡ£¡£¡£¡£¡£¡£¡£¹ÌÈ»Qualys²¢Î´°ä²¼ÈÎºÎÆëÈ«µÄ·ì϶Poc£¬£¬£¬£¬£¬£¬£¬£¬µ«ÆäÖдóÎÞÊý¶¼Äܹ»ÔÚĬÈÏÅäÖûò³£¼ûÅäÖÃÖб»ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶»áÓ°ÏìEximÓÚ2004ÄêÖ®ºó¿ª·¢µÄËùÓа汾£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý×éºÏÀûÓÃÕâЩ·ì϶»ñµÃ³õʼ½Ó¼ûȨÏÞ¡¢Ôì³ÉÈ䳿ÀûÓá¢È¨ÏÞÌáÉý¡¢×°Ö÷¨Ê½¡¢Åú¸ÄÊý¾Ý²¢´´½¨ÐÂÕË»§¡£¡£¡£¡£¡£¡£¡£¡£
21 Nails EximÖУ¬£¬£¬£¬£¬£¬£¬£¬10¸ö¿ÉÔ¶³ÌÀûÓõķì϶Ϊ£º
CVE-2020-28017£ºreceive_add_recipient£¨£©ÖеÄÕûÊýÒç³ö
CVE-2020-28020£ºreceive_msg£¨£©ÖеÄÕûÊýÒç³ö
CVE-2020-28023£ºÔÚsmtp_setup_msg£¨£©ÖжÁȡԽ½ç
CVE-2020-28021£ºÔÚspoolÍ·ÎļþÖÐ×¢ÈëÐÂÐÐ
CVE-2020-28022£ºextract_option£¨£©ÖжÑÔ½½ç¶ÁÈ¡ºÍдÈë
CVE-2020-28026£ºspool_read_header£¨£©ÖеÄÐнضϺÍ×¢Èë
CVE-2020-28019£ºBDATÃýÎóºóÎÞ·¨³ÁÖú¯ÊýÖ¸Õë
CVE-2020-28024£ºsmtp_ungetc£¨£©ÖеĶѻº³åÇøÏÂÒç
CVE-2020-28018£ºÔÚtls-openssl.cÖÐUse-after-free
CVE-2020-28025£ºÔÚpdkim_finish_bodyhash£¨£©ÖжÑÔ½½ç¶ÁÈ¡
21 Nails EximÖУ¬£¬£¬£¬£¬£¬£¬£¬11¸ö±¾µØÀûÓõķì϶Ϊ£º
CVE-2020-28007£ºEximÈÕ־Ŀ¼ÖеÄÁ´½Ó¹¥»÷
CVE-2020-28008£ºEximµÄspoolĿ¼Öеĸ÷À๥»÷
CVE-2020-28014£ºËÁÒâÎļþ´´½¨ºÍ¿ÚÁî¹¥»÷
CVE-2021-27216£ºÉ¾³ýËÁÒâÎļþ
CVE-2020-28011£ºqueue_run£¨£©ÖеĶѻº³åÇøÒç³ö
CVE-2020-28010£ºmain()ÖеĶÑÔ½½çд²Ù×÷
CVE-2020-28013£ºparse_fix_phrase£¨£©ÖеĶѻº³åÇøÒç³ö
CVE-2020-28016£ºparse_fix_phrase()ÖеĶÑÔ½½çдÈë
CVE-2020-28015£ºÔÚspoolÍ·ÎļþÖÐ×¢ÈëÐÂÐÐ
CVE-2020-28012£ºÌØÈ¨¹Ü·¶ÌȱִÐÐʱ¹Ø¹ØµÄ±êÖ¾
CVE-2020-28009£ºget_stdinput£¨£©ÖеÄÕûÊýÒç³ö
ÔÚÕâЩ·ì϶ÖУ¬£¬£¬£¬£¬£¬£¬£¬CVE-2020-28018ÊÇ×îÑϳÁµÄ·ì϶֮һ£¬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇExim·þÎñÆ÷ÊÇÓÃOpenSSL¹¹½¨µÄ£»£»£»£»£»ÈôÊÇSTARTTLSºÍPIPELINING£¨Ä¬ÈÏ£©±»ÆôÓ㻣»£»£»£»ÈôÊÇX_PIPE_CONNECT±»½ûÓã¨Exim 4.94֮ǰµÄĬÈÏÉèÖã©£¬£¬£¬£¬£¬£¬£¬£¬Ëü¾ÍÄܹ»±»ÀûÓᣡ£¡£¡£¡£¡£¡£¡£ÁíÒ»¸öÖµÍ×ÌùÐĵķì϶ÊÇCVE-2020-28020£¬£¬£¬£¬£¬£¬£¬£¬ËüÊÇÒ»¸öÕûÊýÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓÃËüÒÔ ¡°exim ¡±Óû§Éí·ÝÖ´ÐÐËÁÒâºÅÁî²¢¿ú̽Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ëü´æÔÚÓÚreceive_msg£¨£©º¯ÊýÖУ¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÖ°ÄÜ׳´ó£¬£¬£¬£¬£¬£¬£¬£¬µ«Ò²ÊÇ21¸ö·ì϶ÖÐ×îÄÑÀûÓõġ£¡£¡£¡£¡£¡£¡£¡£¶øµ±CVE-2020-28021ÓëÆäËü·ì϶×éºÏÀûÓÃʱ£¬£¬£¬£¬£¬£¬£¬£¬¾¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÔÚspoolÍ·ÎļþÖÐ×¢ÈëÐÂÐУ¬£¬£¬£¬£¬£¬£¬£¬²¢ÒÔrootÉí·ÝÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò
2004ÄêÖ®ºó¿ª·¢µÄËùÓа汾
0x02 ´ëÖý¨Òé
QualysµÄ×êÑÐÈËÔ±ºÍExim¹Ù·½¾ù°ä²¼ÁËÓйز¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£ÖÁÓÚ¸÷ÀàLinux¿¯Ðа棬£¬£¬£¬£¬£¬£¬£¬×î¿í·ºÊ¹Óõģ¨CentOS¡¢RHELºÍSuSE£©£¬£¬£¬£¬£¬£¬£¬£¬ÒÑ¾ÍÆ³öÁ˽¨¸´·¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£DebianÔÚ ¡°oldstable¡±£¨´úºÅStretch£©¡¢¡°stable¡±£¨Buster£©»ò ¡°Still-in-development¡±£¨Sid£©°æ±¾Öв»´æÔÚÕâЩ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¶ø¡°unstable¡±£¨Bullseye£©°æ±¾Ôò´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÇÒĿǰÉÐ佨¸´¡£¡£¡£¡£¡£¡£¡£¡£
Óйطì϶µÄ½¨¸´²½Öè»ò²¹¶¡½¨Òé²Î¿¼Qualys°ä²¼µÄ°²È«Õ÷ѯ£º
https://www.qualys.com/2021/05/04/21nails/21nails.txt
0x03 ²Î¿¼Á´½Ó
https://www.qualys.com/2021/05/04/21nails/21nails.txt
https://threatpost.com/exim-security-linux-mail-server-takeovers/165894/
http://www.exim.org/
0x04 ¹¦·òÏß
2021-05-04 Qualys¹«¿ªÅû¶·ì϶
2021-05-07 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ