¡¾Çå¾²Íþвͨ¸æ¡¿¿ªÔ´Ñ¹Ëõ¿âLibarchive´úÂëÖ´ÐÐÎó²î£¨CVE-2019-18408£©
2019-11-06
×ÛÊö
¿ËÈÕ£¬ÔÚDebian£¬Ubuntu£¬GentooµÈ¿¯ÐаæµÄÇå¾²¸üÐÂÖÐÅû¶ÁËÒ»¸öĬÈϰüÀ¨µÄ¿âLibarchiveÖб£´æµÄ´úÂëÖ´ÐÐÎó²î£¨CVE-2019-18408£©¡£
LibarchiveÊÇÒ»¸ö¿ªÔ´Ñ¹Ëõ¿â£¬ÒòÆäÄܹ»»á¼û´ó×ÚѹËõÎļþÃûÌöø±»ÆÕ±éʹÓã¬Ä¬ÈϰüÀ¨ÔÚDebian£¬Ubuntu£¬Gentoo£¬Arch Linux£¬FreeBSDºÍNetBSD¿¯ÐаæÖС£Ò»Ð©³£ÓõÄÏÂÁîÐй¤¾ßÈçtar cpio zcatµÈҲʹÓõ½libarchive¡£
ÔÚijЩARCHIVE_FAILEDÇéÐÎÏ£¬3.4.0°æ±¾Ç°libarchiveµÄarchive_read_support_format_rar.cÖб£´æUAF (ÊͷźóʹÓÃ)Îó²î¡£¹¥»÷ÕßʹÓÃÈ«ÐĽṹµÄѹËõÎļþ£¬µ±ÊÜÓ°ÏìÓû§Ê¹ÓÃLibarchive»òÕß°üÀ¨LibarchiveµÄÈí¼þ¶ÁÈ¡ÕâЩ¶ñÒâѹËõÎļþʱ£¬¿ÉÄܻᱻִÐдúÂë¡£
ÉÏÖÜ£¬¼¸¸öLinuxºÍFreeBSD¿¯ÐаæÒÑÐû²¼Ïà¹Ø¸üÐÂÐÞ¸´ÁË´ËÎó²î¡£ÁíÍâÖµµÃÇìÐÒµÄÊÇ£¬ËäÈ»LibarchiveÒ²±»°üÀ¨ÔÚMac OS XºÍWindows 10ÖУ¬¿ÉÊÇ´Ë´ÎÎó²î²¢Î´Ó°Ïìµ½ÕâÁ½ÖÖ²Ù×÷ϵͳ¡£
²Î¿¼Á´½Ó£º
https://www.zdnet.com/article/libarchive-vulnerability-can-lead-to-code-execution-on-linux-freebsd-netbsd/#ftag=RSSbaffb68
ÊÜÓ°Ïì²úÆ·°æ±¾
l LibarchiveVersion < 3.4.0
²»ÊÜÓ°Ïì²úÆ·°æ±¾
l Libarchive Version == 3.4.0£¨×îУ©
½â¾ö¼Æ»®
LibarchiveÍŶÓÒÑÌṩÐÞ¸´Á˸ÃÎó²îµÄ×îа汾£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìǰÍùÒÔÏÂÁ´½ÓÏÂÔØ²¢¸üС£
https://github.com/libarchive/libarchive/releases/tag/v3.4.0
¸÷¿¯ÐаæÇå¾²¸üÐÂÐÅÏ¢Ïê¼û£º
l Debian£ºhttps://security-tracker.debian.org/tracker/CVE-2019-18408
l Ubuntu£ºhttps://usn.ubuntu.com/4169-1/
l Gentoo£ºhttps://bugs.gentoo.org/show_bug.cgi?id=CVE-2019-18408
l Arch Linux£ºhttps://www.archlinux.org/packages/?sort=&q=libarchive&maintainer=&flagged=
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
±±¾©ÉñÖÝAG¹«Ë¾ÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖÝAG¹«Ë¾ÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ





