libssh·þÎñ¶ËÈÏÖ¤ÈÆ¹ý·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-10-17·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-10933£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
libssh 0.7.x - 0.7.5
libssh 0.6.x
·ì϶¸ÅÊö
¹¥»÷Õ߳ɹ¦ÀûÓô˷ì϶£¬¿ÉµÇÈëÖ¸±ê·þÎñÆ÷½øÒ»²½½øÐÐËÁÒâ¶ñÒâ²Ù×÷¡£
Áí±íÖµµÃ×¢Ã÷µÄÊÇ£¬OpenSSH Óë libssh ÊÇÁ½¸ö¶ÀÁ¢µÄÏîÄ¿£¬²¢ÇÒ OpenSSH ¹Ù·½°²È«ÍŶÓĿǰҲÉÐδ°ä²¼ÈκÎÓë´Ë·ì϶ÓйصÄÐÅÏ¢£¬¹Ê OpenSSH Ó¦¸Ã²»ÊÜ´Ë·ì϶ӰÏì¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC\EXP
½¨¸´½¨Òé
libssh 0.7.x °æ±¾ÇëÉý¼¶µ½ 0.7.6
https://www.libssh.org/2018/10/16/libssh-0-8-4-and-0-7-6-security-and-bugfix-release/
Ŀǰ¸÷´ó¿¯ÐаæÖж¼ÔÝδ¶ÔÏàÓ¦package½øÐиüУ¬¾ßÌåÇé¿öÄܹ»¹Ø×¢Ò»ÏÂÁ´½Ó
Debain
https://security-tracker.debian.org/tracker/CVE-2018-10933
ubuntu
https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-10933.html
opensuse
https://www.suse.com/security/cve/CVE-2018-10933/
redhat
¹Ù·½ÔÝδ°ä²¼¹«¸æ
²Î¿¼Á´½Ó
https://security.stackexchange.com/questions/195834/cve-2018-10933-bypass-ssh-authentication-libssh-vulnerability


¾©¹«Íø°²±¸11010802024551ºÅ