OpenSMTPDÔ¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-02-26·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-8794£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
OpenSMTPDÓ×ÓÚ6.6.4p1°æ±¾
·ì϶¸ÅÊö
OpenBSDÊǼÓÄôóOpenBSDÏîÄ¿×éµÄÒ»Ì×¿çÆ½Ì¨µÄ¡¢»ùÓÚBSDµÄÀàUNIX²Ù×÷ϵͳ¡£OpenSMTPDÊÇOpenBSDÍŶӿª·¢µÄÒ»¸öÃâ·ÑµÄ·þÎñÆ÷¶ËSMTPºÍ̸ʵÏÖ£¬Í¨¹ýRFC5321½ç˵£¬Ò²ÊÇOpenBSDÏîÖ÷ÕÅÒ»²¿ÃÅ¡£
°²È«×êÑÐÈËÔ±ÔÚÓʼþ·þÎñÆ÷OpenSMTPDÖз¢ÏÖÒ»¸öеÄÑϳÁ·ì϶£¨CVE-2020-8794£©£¬¹¥»÷ÕßÄܹ»Ô¶³ÌÀûÓø÷ì϶ÒÔrootÓû§Éí·ÝÔËÐÐShellºÅÁî¡£OpenSMTPDÀûÓÃÔÚ¶à¸ö»ùÓÚUnixµÄϵͳÉÏ£¬Ô̺¬FreeBSD¡¢NetBSD¡¢macOS¡¢Linux£¨Alpine¡¢Arch¡¢Debian¡¢Fedora¡¢CentOS£©¡£
¸Ã·ì϶ӰÏìÁËOpenSMTPDµÄĬÈÏ×°Öã¬×êÑÐÈËÔ±Ö¸³ö¸ÃÎÊÌâÊÇÔÚ2015Äê12ÔÂÒýÈëµÄ£¬µ«Ö»ÓÐÔÚ2018Äê5ÔÂÖ®ºó°ä²¼µÄOpenSMTPD°æ±¾ÉÏÄÜÁ¦¹»ÀûÓÃËüÒÔrootÌØÈ¨Ö´ÐдúÂë¡£ÔÚÒÔǰµÄ°æ±¾ÖУ¬shellºÅÁîÄܹ»×÷Ϊ·ÇrootºÅÁîÔËÐС£
·ì϶ÑéÖ¤
×êÑÐÈËÔ±³Æ½«ÓÚ2ÔÂ26ÈÕ°ä²¼PoC£¬²¢ÇÒÒѾÔÚµ±Ç°µÄOpenBSD6.6¡¢OpenBSD5.9¡¢Debian10¡¢Debian11ºÍFedora31Éϳɹ¦²âÊÔ£¬¡£
½¨¸´½¨Òé
OpenSMTPD 6.6.4p1ÖÐÒѾ½¨¸´Á˸÷ì϶£¬½¨ÒéÓû§¾¡¿ì×°ÖøüУºhttps://www.mail-archive.com/misc@opensmtpd.org/msg04888.html¡£
²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/new-critical-rce-bug-in-openbsd-smtp-server-threatens-linux-distros/


¾©¹«Íø°²±¸11010802024551ºÅ