E2fsprogs Ô¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-01-14·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-5188£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
E2fsprogs 1.43.3 - 1.45.4
·ì϶¸ÅÊö
˼¿ÆTalos×êÑÐÍŶÓÅû¶ÎļþϵͳÖÎÀí¹¤¾ßE2fsprogsÖеÄRCE·ì϶¡£E2fsprogsÊÇÒ»×éÓÃÓÚÓëext2¡¢ext3ºÍext4Îļþϵͳ½»»¥µÄʵÓ÷¨Ê½£¬¸ÃÈí¼þ±»ÊÓΪLinuxºÍÀàUnix²Ù×÷ϵͳµÄ±Ø±¸Èí¼þ£¬Ä¬ÈÏÔÚ´óÎÞÊýLinux¿¯ÐаæÖгö³§¸½´ø¡£
¸Ã·ì϶£¨CVE-2019-5188£©´æÔÚÓÚE2fsprogs e2fsck rehash.cÎļþµÄmutate_name()º¯ÊýÖУ¬¹¥»÷Õß¿ÉÀûÓÃÌØÔìµÄext4Ŀ¼´¥·¢²Ö¿âÔ½½çдÈ룬´Ó¶øµ¼Ö´úÂëÖ´ÐС£¹¥»÷Õß±ØÒª·ÛËé·ÖÇøÀ´´¥·¢´Ë·ì϶¡£
·ì϶ÑéÖ¤
POC£ºhttps://talosintelligence.com/vulnerability_reports/TALOS-2019-0973¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttp://e2fsprogs.sourceforge.net/¡£
²Î¿¼Á´½Ó
https://blog.talosintelligence.com/2020/01/e2fsprogs-remote-code-execution-vuln-jan-2020.html


¾©¹«Íø°²±¸11010802024551ºÅ