E2fsprogs Ô¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-01-14

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5188£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


E2fsprogs 1.43.3 - 1.45.4


·ì϶¸ÅÊö


˼¿ÆTalos×êÑÐÍŶÓÅû¶ÎļþϵͳÖÎÀí¹¤¾ßE2fsprogsÖеÄRCE·ì϶¡£E2fsprogsÊÇÒ»×éÓÃÓÚÓëext2¡¢ext3ºÍext4Îļþϵͳ½»»¥µÄʵÓ÷¨Ê½£¬¸ÃÈí¼þ±»ÊÓΪLinuxºÍÀàUnix²Ù×÷ϵͳµÄ±Ø±¸Èí¼þ£¬Ä¬ÈÏÔÚ´óÎÞÊýLinux¿¯ÐаæÖгö³§¸½´ø¡£


¸Ã·ì϶£¨CVE-2019-5188£©´æÔÚÓÚE2fsprogs e2fsck rehash.cÎļþµÄmutate_name()º¯ÊýÖУ¬¹¥»÷Õß¿ÉÀûÓÃÌØÔìµÄext4Ŀ¼´¥·¢²Ö¿âÔ½½çдÈ룬´Ó¶øµ¼Ö´úÂëÖ´ÐС£¹¥»÷Õß±ØÒª·ÛËé·ÖÇøÀ´´¥·¢´Ë·ì϶¡£


·ì϶ÑéÖ¤


POC£ºhttps://talosintelligence.com/vulnerability_reports/TALOS-2019-0973¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttp://e2fsprogs.sourceforge.net/¡£


²Î¿¼Á´½Ó


https://blog.talosintelligence.com/2020/01/e2fsprogs-remote-code-execution-vuln-jan-2020.html