Intel Wi-FiÇý¶¯·ì϶·ÖÎö
°ä²¼¹¦·ò 2021-04-27Intel Wi-FiоƬ¿í·ºÀûÓÃÓÚÓ×ÎұʼDZ¾µçÄÔ²úÆ·£¬ÈçThinkPad¡¢Dell±Ê¼Ç±¾µÈ¡£2020Ä꣬ZDI×éÖ¯Åû¶ÁËIntelÎÞÏßÍø¿¨WindowsÇý¶¯·¨Ê½ÖдæÔÚCVE-2020-0557 ºÍ CVE-2020-0558·ì϶¡£ÆäÖУ¬CVE-2020-0557µÄCVSS v3.0ÆÀ·ÖΪ 8.1 ·Ö£¬CVE-2020-0558µÄCVSS v3.0ÆÀ·ÖΪ 8.2 ·Ö¡£Í¨¹ýÕâÁ½¸ö·ì϶£¬¹¥»÷ÕßÄܹ»ÔÚÊܺ¦ÕßµçÄÔÖÐÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£
| ·ì϶±àºÅ | Ó°ÏìµÄÎÞÏßÍø¿¨ | Ó°ÏìÇý¶¯ |
| CVE-2020-0557 | AC 7265 Rev D¡¢AC 3168¡¢AC 8265ºÍAC8260 | Intel PROSet/Wireless WiFi Software 21.70֮ǰ°æ±¾ |
| CVE-2020-0558 | AC8265 | Intel PROSet/Wireless WiFi Software 21.70֮ǰ°æ±¾ |
CVE-2020-0558·ì϶·ÖÎö
1¡¢·ì϶µÀÀí
µ±APÈȵ㴦ÖÃAssocReqʱ£¬»áŲÓÃprvhPanClientSaveAssocRespº¯Êý±£ÁôAssocReqÖ¡ÖÐSSIDµÄÖµ£¬ÔÚ´¦ÖÃSSIDµÄ¹ý³ÌÖУ¬»áŲÓÃparse_ieº¯Êý´ÓÊý¾ÝÖ¡ÖÐÈ¡³össidµÄTLV½á¹¹£¬²¢Å²ÓÃmemcpy_sº¯Êý½«ssidµÄÄÚÈݸ´Ôìµ½Ö¸±ê»º³åÇø¡£ÔÚŲÓÃmemcpy_sº¯ÊýµÄʱ³½£¬ÃýÎóµØÊ¹ÓÃssidµÄlength×÷ΪÊý¾Ý¸´Ô쳤¶È£¬µ±ssidµÄ³¤¶È´óÓÚÖ¸±ê»º³åÇøµÄ³¤¶Èʱ£¬»áµ¼Ö»º³åÇøÒç³ö¡£º¯ÊýŲÓÃͼÈçÏÂËùʾ£º

2¡¢ÎÊÌâ´úÂë
ŲÓÃparse_ieº¯Êý´ÓÊý¾ÝÖ¡ÖÐÈ¡³össidµÄTLV½á¹¹£¬²¢Å²ÓÃmemcpy_sº¯Êý½«ssidµÄÄÚÈݸ´Ôìµ½Ö¸±ê»º³åÇø¡£ÔÚŲÓÃmemcpy_sº¯ÊýµÄʱ³½£¬ÃýÎóµØÊ¹ÓÃssidµÄlength×÷ΪÊý¾Ý¸´Ô쳤¶È£¬µ±ssidµÄ³¤¶È´óÓÚÖ¸±ê»º³åÇøµÄ³¤¶Èʱ£¬»áµ¼Ö»º³åÇøÒç³ö¡£±ÉÈËͼÖУ¬¹¥»÷ÕßÄܹ»½ÚÔì*(v8+1)µÄÖµ£¬Äܹ»¿½±´³¬³¤µÄÊý¾Ý¸´Ôìµ½Ö¸±êµØÖ·ÖУ¬´Ó¶øµ¼Ö»º³åÇøÒç³ö¡£ÈçÏÂͼËùʾ£º

3¡¢·ì϶½¨¸´
а汾µÄ´úÂëÖÐʹÓÃosalMemoryCopyº¯Êý´úÌæÁËÔÀ´µÄmemcpy_sº¯Êý£¬Áí±í°ÑSSID¿½±´µÄ×î´ó³¤¶ÈÇ¿ÔìÉèΪ32×Ö½Ú£¬ÕâÑù¾ÍÔ¤·ÀÁË»º´æÇøÒç³öµÄÎÊÌâ¡£ÈçÏÂͼËùʾ£º

CVE-2020-0557·ì϶·ÖÎö
1¡¢·ì϶µÀÀí
µ±APÈȵ㴦ÖÃAssocReqʱ£¬»áŲÓÃprvhPanClientSaveAssocRespº¯Êý´¦ÖÃAssocReqÖ¡ÖеÄÊý¾Ý£¬ÆäÖÐÔÚº¯ÊýÖлáŲÓÃprvGoVifClientAssocStoreSupportedChannelsº¯ÊýÀ´´¦Öü°±£ÁôÒªÇó¶Ëͨ·ÐÅÏ¢£¬ÕâÆäÖÐprvGoVifClientAssocStoreSupportedChannelsº¯Êý»áÑ»·Å²ÓÃutilRegulatoryClassToChannelListÀ´´¦ÖÃRegulatoryClass£¨¹ÜÔìÒªÇó£©ÐÅÏ¢¡£ÓÉÓÚÔÚÑ»·´¦ÖÃûÓÐ˼¿¼Ö¸±êµÄÆ«ÒÆÊÇ·ñÔ½½ç£¬µ±APÈȵã½Ó¹Üµ½AssocReqÊý¾ÝÖ¡ÖÐRegulatoryClassÐÅÏ¢µ¥ÔªÓжà¸öÐÅ·Êý¾Ýʱ»áµ¼ÖÂÔ½½çд¡£º¯ÊýŲÓÃͼÈçÏÂͼËùʾ£º

2¡¢ÎÊÌâ´úÂë
prvGoVifClientAssocStoreSupportedChannelsº¯Êý£¬ÈçÏÂͼËùʾ£º


3¡¢·ì϶½¨¸´
ÔÚа汾 ÍÆ½øÁ˶Ե±Ç°indexµÄÅжϣ¬ÈôÊÇindex´óÓÚ255ÔòÍ˳öÑ»·¡£ÈçÏÂͼËùʾ£º

4¡¢·ì϶ÑéÖ¤
²Î¿¼Á´½Ó£º
¡¾1¡¿https://www.thezdi.com/blog/2020/5/4/analyzing-a-trio-of-remote-code-execution-bugs-in-intel-wireless-adapters
GA»Æ½ð¼×»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©
ADLab³ÉÁ¢ÓÚ1999Ä꣬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£½ØÖ¹Ä¿Ç°£¬ADLabÒÑͨ¹ýCVEÀۼư䲼°²È«·ì϶½ü1100¸ö£¬Í¨¹ý CNVD/CNNVDÀۼư䲼°²È«·ì϶1000Óà¸ö£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº¸Ç²Ù×÷ϵͳÓëÀûÓÃϵͳ°²È«×êÑÓ×¢ÖÇÄÜÖն˰²È«×êÑÓ×¢ÎïÁªÍøÖÇÄÜÉ豸°²È«×êÑÓ×¢Web°²È«×êÑÓ×¢¹¤¿ØÏµÍ³°²È«×êÑÓ×¢ÔÆ°²È«×êÑС£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£



¾©¹«Íø°²±¸11010802024551ºÅ