¡¾·ì϶¹«¸æ¡¿Apache James»Ø¾ø·þÎñ·ì϶(CVE-2024-37358)
°ä²¼¹¦·ò 2025-02-07Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Apache James»Ø¾ø·þÎñ·ì϶ | ||
CVE ID | CVE-2024-37358 | ||
·ì϶ÀàÐÍ | »Ø¾ø·þÎñ | ·¢ÏÖ¹¦·ò | 2025-02-07 |
·ì϶ÆÀ·Ö | 8.6 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Apache James£¨Java Apache Mail Enterprise Server£©ÊÇÒ»¸ö¿ªÔ´µÄÓʼþ·þÎñÆ÷£¬Ö§³ÖSMTP¡¢IMAP ºÍ POP3 ºÍ̸¡£Ëü»ùÓÚJava¿ª·¢£¬¿ÉÀ©´ó²¢Ö§³ÖÄ£¿é»¯¼Ü¹¹£¬ºÏÓÃÓÚÆóÒµ¼¶Óʼþ´¦Öá£James ¾ß±¸Óʼþ´æ´¢¡¢Óû§ÖÎÀí¡¢Óʼþ¹ýÂ˵ÈÖ°ÄÜ£¬²¢¿É¼¯³ÉLDAP¡¢Êý¾Ý¿âµÈ±í²¿ÏµÍ³£¬ºÏÓÃÓÚ¹¹½¨×Ô½ç˵Óʼþ½â¾ö¹æ»®¡£
2025Äê2ÔÂ7ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Apache¹Ù·½°ä²¼ÁËCVE-2024-37358·ì϶²¼¸æ¡£¸Ã·ì϶ӰÏìApache James£¬¹¥»÷Õß¿ÉÀÄÓÃIMAP×ÖÃæÁ¿£¨IMAP literals£©´¥·¢ÎÞÏ޶ȵÄÄÚ´æ·ÖÅäºÍ³¤¹¦·òÍÆË㣬´Ó¶øµ¼Ö»ؾø·þÎñ£¨DoS£©¡£¸Ã·ì϶¿É±»ÈÏÖ¤Óû§ºÍδÈÏÖ¤Óû§ÀûÓ㬿ÉÄܵ¼Ö·þÎñÆ÷×ÊÔ´ºÄ¾¡£¬Ó°ÏìÕý³£ÒµÎñÔËÐС£


¾©¹«Íø°²±¸11010802024551ºÅ