ÔÆ´æ´¢ÀûÓÃԽȨ½Ó¼ûºÍÎļþÉÏ´«·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-11-18

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


¾Ýͳ¼Æ £¬Ê¹ÓùúÄÚÖ÷Á÷³§ÉÌÔÆ´æ´¢·þÎñµÄ°²×¿APPÊýÁ¿Îª4148¸ö¡£³éÑù¼ì²âÁ˾ÖÏÔʾ £¬ÊÜ´Ë·ì϶ӰÏìµÄÀûÓñÈÀý´ï70%¡£


·ì϶¸ÅÊö


ÔÆ´æ´¢ÊÇÔÆÍÆËã»ù´¡ÉÏÑÓ³¤ºÍÑÜÉú·¢Õ¹³öÀ´µÄиÅÏë £¬×ÛºÏѡȡɢ²¼Ê½´¦Öᢲ¢Ðд¦ÖúÍÍø¸ñÍÆËãµÈ¼¿Á© £¬½«ÍøÂçÖÐ·ÖÆçÀàÐ͵Ĵ洢É豸ͨ¹ýÀûÓÃÈí¼þ¼¯ÖÐÆðÀ´Ð­Í¬¹¤×÷ £¬¶Ô±íÌṩͳһµÄÊý¾Ý´æ´¢ºÍÒµÎñ½Ó¼ûÖ°ÄÜ¡£ÔÆ´æ´¢ÔÚÒÆ¶¯APP¡¢ÍøÒ³°æ·¨Ê½¡¢APPÓ×·¨Ê½£¨ÒÔϼò³ÆÔÆ´æ´¢ÀûÓ㩵ȳ¡¾°µÃµ½ÁË¿í·ºÀûÓá£Óû§½Ó¼ûÔÆ´æ´¢Êý¾Ýʱ £¬½øÐÐÊðÃûÒªÇóµÄÃÜÔ¿ÓÐÓÀÔ¼ûÜÔ¿ºÍһʱÃÜÔ¿Á½ÖÖ·½Ê½¡£


ÔÆ´æ´¢ÀûÓÃÓÉÓÚÅäÖò»µ± £¬´æÔÚԽȨ½Ó¼ûºÍÎļþÉÏ´«·ì϶£ºÊ¹ÓÃһʱÃÜÔ¿½øÐÐÎļþÉÏ´«µÄÔÆ´æ´¢ÀûÓà £¬²»×ã¶ÔÎļþ£¨´æ´¢Í°£©½Ó¼û»òÉÏ´«õè¾¶£¨´æ´¢Í°£©µÄȨÏÞÏÞ¶È £¬µ¼ÖÂÎļþ£¨´æ´¢Í°£©Ô½È¨½Ó¼û»òÎļþÉÏ´«·ì϶£»Ê¹ÓÃÓÀÔ¼ûÜԿΪÎļþÉÏ´«ÒªÇóÊðÃûµÄÔÆ´æ´¢ÀûÓà £¬²»×ã¶ÔÓÀÔ¼ûÜÔ¿µÄ±ØÒª±£»¤ £¬²úÉúËÁÒâõè¾¶Îļþ£¨´æ´¢Í°£©µÄԽȨ½Ó¼ûºÍÎļþÉÏ´«·ì϶¡£¹¥»÷ÕßÀûÓÃÉÏÊö·ì϶ £¬Í¨¹ýÔÆ´æ´¢ÀûÓÃÆÆ½â»òÍøÂç×¥°ü»ñµÃÓÀÔ¼ûÜÔ¿»òһʱÃÜÔ¿ £¬ÊµÏÖ¶ÔÔÆ´æ´¢ÖеÄÎļþÊý¾ÝµÄÇÔÈ¡ £¬ÉõÖÁ´Û¸ÄÓû§±£ÁôÔÚÔÆ´æ´¢ÖеÄÊý¾ÝÎļþ¡£


·ì϶ÑéÖ¤


ÔÝÎÞEXP/POC¡£


½¨¸´½¨Òé


Ŀǰ¹Ù·½ÉÐδ°ä²¼·ì϶½¨¸´²¹¶¡¡£


һʱ½¨¸´½¨Ò飺


½¨ÒéÔÆ´æ´¢ÀûÓÿª·¢ÕßѡȡÈçÏ·½Ê½½¨¸´·ì϶£º


1¡¢Ñ¡È¡Ò»Ê±ÊðÃûÉÏ´«ÎļþµÄÔÆ´æ´¢ÀûÓãºÆ¾¾ÝÒµÎñ³¡¾°½«·þÎñ¶ËÌìÉúµÄһʱÃÜԿȨÏÞ¸üÐÂÖÁ×îÓ× £¬ÏÞÔìÎļþµÄÉÏ´«õè¾¶ºÍÉÏ´«µÄÖ¸±ê´æ´¢Í° £¬È¥³ý¶ÁÎļþ¡¢Áд洢Ͱ¡¢ÁжÔÏ󡢸²¸ÇÎļþµÈ·ÇÒµÎñ±ØÒªÈ¨ÏÞ¡£


2¡¢Ñ¡È¡ÓÀÔ¼ûÜÔ¿ÊðÃûÉÏ´«ÎļþµÄÔÆ´æ´¢ÀûÓ㺸üпͻ§¶ËºÍ·þÎñ¶ËÉÏ´«Âß¼­ £¬¸ÄΪÓÃ×îÓ×ȨÏÞµÄһʱÃÜÔ¿·½Ê½»òÕßPUT·½Ê½½øÐÐÉÏ´«¡£


²Î¿¼Á´½Ó


https://www.cnvd.org.cn/webinfo/show/5291