¡¾·ì϶¹«¸æ¡¿Rsync »º³åÇøÒç¶Âí½Å(CVE-2024-12084)

°ä²¼¹¦·ò 2025-01-17

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

Rsync »º³åÇøÒç¶Âí½Å

CVE   ID

CVE-2024-12084

·ì϶ÀàÐÍ

»º³åÇøÒç³ö

·¢ÏÖ¹¦·ò

2025-01-17

·ì϶ÆÀ·Ö

9.8

·ì϶µÈ¼¶

ÑϳÁ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


rsyncÊÇÒ»ÖÖ³£ÓõÄÎļþͬ²½ºÍ´«Ê乤¾ß£¬£¬£¬£¬£¬£¬£¬Ö§³Ö¸ßЧµÄÔöÁ¿±¸·Ý¡£¡£¡£¡£¡£ ¡£Í¨¹ý±ÈÁ¦Ô´ºÍÖ¸±êÎļþµÄ²î¾à£¬£¬£¬£¬£¬£¬£¬rsyncÖ»´«Êä¸ü»Ú¸ÄµÄ²¿ÃÅ£¬£¬£¬£¬£¬£¬£¬´Ó¶ø½Ú¼ó´ø¿íºÍ¹¦·ò¡£¡£¡£¡£¡£ ¡£ËüÖ§³Ö±¾µØºÍÔ¶³ÌÎļþ´«Ê䣬£¬£¬£¬£¬£¬£¬³£ÓÃÓÚ±¸·Ý¡¢Í¬²½ºÍ²¿Êð¹¤×÷¡£¡£¡£¡£¡£ ¡£


2025Äê1ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯Íż¯ÍÅVSRC¼à²âµ½Rsync°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬È·ÈÏÆä·þÎñ¶Ë¹ý³ÌRsyncd´æÔÚ»º³åÇøÒç¶Âí½Å£¨CVE-2024-12084£©¡£¡£¡£¡£¡£ ¡£·ì϶¼¶±ðΪÑϳÁ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8·Ö£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ԴÓÚrsyncÊØ»¤¹ý³ÌÖÐδÕýÈ·´¦Öù¥»÷Õß½ÚÔìµÄУÑéºÍ³¤¶È£¨s2length£©¡£¡£¡£¡£¡£ ¡£µ±MAX_DIGEST_LEN³¬¹ý¹Ì¶¨µÄSUM_LENGTH£¨16×Ö½Ú£©Ê±£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÔÚsum2»º³åÇøÖÐдÈëÔ½½çÊý¾Ý£¬£¬£¬£¬£¬£¬£¬´Ó¶ø´¥·¢¶ÑÄÚ´æÒç³öÎÊÌâ¡£¡£¡£¡£¡£ ¡£


³ýÁË»º³åÇøÒç¶Âí½Å£¨CVE-2024-12084£©±í£¬£¬£¬£¬£¬£¬£¬Rsync»¹´æÔÚÒÔÏ·ì϶£º


ÐÅϢй¶·ì϶£¨CVE-2024-12085£©£ºrsyncÊØ»¤¹ý³Ì´æÔÚÐÅϢй¶·ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý²Ù¿ØÐ£ÑéºÍ³¤¶È£¨s2length£©£¬£¬£¬£¬£¬£¬£¬Òý·¢Óëδ³õʼ»¯ÄÚ´æµÄ±ÈÁ¦£¬£¬£¬£¬£¬£¬£¬Öð×Ö½Úй¶ջÊý¾Ý¡£¡£¡£¡£¡£ ¡£·ì϶¼¶±ðΪ¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.5·Ö¡£¡£¡£¡£¡£ ¡£


Îļþй¶·ì϶£¨CVE-2024-12086£©£ºrsync´æÔÚÎļþй¶·ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɻú¹ØÐ£ÑéºÍ£¬£¬£¬£¬£¬£¬£¬Öð×Ö½Úö¾Ù¿Í»§¶ËËÁÒâÎļþÄÚÈÝ¡£¡£¡£¡£¡£ ¡£·ì϶¼¶±ðΪÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ6.1·Ö¡£¡£¡£¡£¡£ ¡£


õè¾¶±éÀú·ì϶£¨CVE-2024-12087£©£ºrsync´æÔÚõè¾¶±éÀú·ì϶£¬£¬£¬£¬£¬£¬£¬¶ñÒâ·þÎñÆ÷¿ÉÀûÓ÷ûºÅÁ´½ÓÈÆ¹ý£¬£¬£¬£¬£¬£¬£¬½«ÎļþдÈë¿Í»§¶ËµÄ·ÇÖ¸±êĿ¼¡£¡£¡£¡£¡£ ¡£·ì϶¼¶±ðΪÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ6.5·Ö¡£¡£¡£¡£¡£ ¡£


õè¾¶±éÀú·ì϶£¨CVE-2024-12088£©£ºrsyncÔÚʹÓÃ`--safe-links`Ñ¡ÏîʱδÕýÈ·ÑéÖ¤·ûºÅÁ´½ÓÖ¸±ê£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂõè¾¶±éÀú·ì϶£¬£¬£¬£¬£¬£¬£¬¿ÉÄܽ«ÎļþдÈë·ÇÔ¤ÆÚĿ¼¡£¡£¡£¡£¡£ ¡£·ì϶¼¶±ðΪÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ6.5·Ö¡£¡£¡£¡£¡£ ¡£


·ûºÅÁ´½Ó¾ºÌ¬Ç°Ìá·ì϶£¨CVE-2024-12747£©£ºrsync´æÔÚ·ûºÅÁ´½Ó¾ºÌ¬Ç°Ìá·ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓûúÓöÈÆ¹ýĬÈÏÐÐΪ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¼ûô¸ÐÐÅÏ¢²¢¿ÉÄܵ¼ÖÂȨÏÞÌáÉý¡£¡£¡£¡£¡£ ¡£·ì϶¼¶±ðΪÖÐΣ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ5.6·Ö¡£¡£¡£¡£¡£ ¡£


ÆäÖУ¬£¬£¬£¬£¬£¬£¬»º³åÇøÒç¶Âí½Å£¨CVE-2024-12084£©ÓëÐÅϢй¶·ì϶£¨CVE-2024-12085£©¿É½áºÏÀûÓ㬣¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£ ¡£


¶þ¡¢Ó°ÏìÁìÓò


CVE-2024-12084£¨»º³åÇøÒç¶Âí½Å£©£º3.2.7=
CVE-2024-12085£¨ÐÅϢй¶·ì϶£©£ºRsync < 3.4.0
CVE-2024-12086£¨Îļþй¶·ì϶£©£ºRsync < 3.4.0
CVE-2024-12087£¨õè¾¶±éÀú·ì϶£©£ºRsync < 3.4.0
CVE-2024-12088£¨õè¾¶±éÀú·ì϶£©£ºRsync < 3.4.0

CVE-2024-12747£¨·ûºÅÁ´½Ó¾ºÌ¬Ç°Ìá·ì϶£©£ºRsync < 3.4.0


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


Ŀǰ¸Ã·ì϶ÒѾ­½¨¸´£¬£¬£¬£¬£¬£¬£¬Ç뾡¿ìÏÂÔØ²¢Éý¼¶ÖÁ×îа汾


ÏÂÔØÁ´½Ó£º
https://rsync.samba.org/download.html


3.2 һʱ´ëÊ©


CVE-2024-12084 (»º³åÇøÒç¶Âí½Å)£¬£¬£¬£¬£¬£¬£¬½ûÓÃSHA*Ö§³Ö£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÒÔϱàÒëÑ¡ÏCFLAGS=-DDISABLE_SHA512_DIGEST ºÍ CFLAGS=-DDISABLE_SHA256_DIGEST¡£¡£¡£¡£¡£ ¡£
CVE-2024-12085 (ÐÅϢй¶·ì϶)£¬£¬£¬£¬£¬£¬£¬±àÒëʱʹÓà -ftrivial-auto-var-init=zero£¬£¬£¬£¬£¬£¬£¬½«Õ»ÄÚÈݳõʼ»¯ÎªÁ㣬£¬£¬£¬£¬£¬£¬ÒÔÔ¤·ÀÐÅϢй¶¡£¡£¡£¡£¡£ ¡£
CVE-2024-12086 (Îļþй¶·ì϶)£¬£¬£¬£¬£¬£¬£¬Ï޶ȶԿͻ§¶ËÎļþÄÚÈݵĽӼû£¬£¬£¬£¬£¬£¬£¬È·±£·þÎñÆ÷½ö¿ÉÄܽӼûÊÚȨµÄÎļþ¡£¡£¡£¡£¡£ ¡£
CVE-2024-12087 (õè¾¶±éÀú·ì϶)£¬£¬£¬£¬£¬£¬£¬½ûÓÃ--inc-recursiveÑ¡Ïî»òÇ¿»¯·ûºÅÁ´½ÓÑéÖ¤£¬£¬£¬£¬£¬£¬£¬È·±£ÎļþдÈë½öÏÞÓÚÖ¸±êĿ¼ÄÚ¡£¡£¡£¡£¡£ ¡£
CVE-2024-12088 (õè¾¶±éÀú·ì϶)£¬£¬£¬£¬£¬£¬£¬¼ÓÇ¿¶Ô--safe-linksÑ¡ÏîÏ·ûºÅÁ´½ÓÖ¸±êµÄÑéÖ¤£¬£¬£¬£¬£¬£¬£¬Ô¤·Àõè¾¶±éÀú·ì϶µÄ²úÉú¡£¡£¡£¡£¡£ ¡£
CVE-2024-12747 (·ûºÅÁ´½Ó¾ºÌ¬Ç°Ìá·ì϶)£¬£¬£¬£¬£¬£¬£¬Í¨¹ý¼ÓÇ¿·ûºÅÁ´½Ó´¦ÖÃÖеľºÌ¬Ç°Ìá± £»£»£»£»£» £»£»£»¤£¬£¬£¬£¬£¬£¬£¬Ô¤·À¹¥»÷ÕßÈÆ¹ýĬÈÏÐÐΪ²¢Ð¹Â¼ûô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£ ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£ ¡£¬£¬£¬£¬£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬£¬£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£¡£ ¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬£¬£¬£¬£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬£¬£¬£¬£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬£¬£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬£¬£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£ ¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£¡£¡£ ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£ ¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£ ¡£


3.4 ²Î¿¼Á´½Ó


https://www.openwall.com/lists/oss-security/2025/01/14/3
https://kb.cert.org/vuls/id/952657
https://nvd.nist.gov/vuln/detail/cve-2024-12084
https://nvd.nist.gov/vuln/detail/CVE-2024-12085
https://nvd.nist.gov/vuln/detail/CVE-2024-12086
https://nvd.nist.gov/vuln/detail/CVE-2024-12087
https://nvd.nist.gov/vuln/detail/CVE-2024-12088
https://nvd.nist.gov/vuln/detail/CVE-2024-12747
https://download.samba.org/pub/rsync/NEWS