¡¾Îó²îͨ¸æ¡¿Rsync »º³åÇøÒç³öÎó²î(CVE-2024-12084)
Ðû²¼Ê±¼ä 2025-01-17Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Rsync »º³åÇøÒç³öÎó²î | ||
CVE ID | CVE-2024-12084 | ||
Îó²îÀàÐÍ | »º³åÇøÒç³ö | ·¢Ã÷ʱ¼ä | 2025-01-17 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
rsyncÊÇÒ»ÖÖ³£ÓõÄÎļþͬ²½ºÍ´«Ê乤¾ß£¬Ö§³Ö¸ßЧµÄÔöÁ¿±¸·Ý¡£Í¨¹ý½ÏÁ¿Ô´ºÍÄ¿µÄÎļþµÄ²î±ð£¬rsyncÖ»´«Êä¸ü»Ú¸ÄµÄ²¿·Ö£¬´Ó¶ø½ÚÔ¼´ø¿íºÍʱ¼ä¡£ËüÖ§³ÖÍâµØºÍÔ¶³ÌÎļþ´«Ê䣬³£ÓÃÓÚ±¸·Ý¡¢Í¬²½ºÍ°²ÅÅʹÃü¡£
2025Äê1ÔÂ17ÈÕ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼¯ÍÅVSRC¼à²âµ½RsyncÐû²¼Ç徲ͨ¸æ£¬È·ÈÏÆä·þÎñ¶ËÀú³ÌRsyncd±£´æ»º³åÇøÒç³öÎó²î£¨CVE-2024-12084£©¡£Îó²î¼¶±ðΪÑÏÖØ£¬CVSSÆÀ·ÖΪ9.8·Ö£¬¸ÃÎó²îÔ´ÓÚrsyncÊØ»¤Àú³ÌÖÐδ׼ȷ´¦Öóͷ£¹¥»÷Õß¿ØÖƵÄУÑéºÍ³¤¶È£¨s2length£©¡£µ±MAX_DIGEST_LENÁè¼ÝÀο¿µÄSUM_LENGTH£¨16×Ö½Ú£©Ê±£¬¹¥»÷Õß¿ÉÒÔÔÚsum2»º³åÇøÖÐдÈëÔ½½çÊý¾Ý£¬´Ó¶ø´¥·¢¶ÑÄÚ´æÒç³öÎÊÌâ¡£
³ýÁË»º³åÇøÒç³öÎó²î£¨CVE-2024-12084£©Í⣬Rsync»¹±£´æÒÔÏÂÎó²î£º
ÐÅϢй¶Îó²î£¨CVE-2024-12085£©£ºrsyncÊØ»¤Àú³Ì±£´æÐÅϢй¶Îó²î£¬¹¥»÷Õß¿Éͨ¹ý²Ù¿ØУÑéºÍ³¤¶È£¨s2length£©£¬Òý·¢Óëδ³õʼ»¯ÄÚ´æµÄ½ÏÁ¿£¬Öð×Ö½Úй¶ջÊý¾Ý¡£Îó²î¼¶±ðΪ¸ßΣ£¬CVSSÆÀ·ÖΪ7.5·Ö¡£
Îļþй¶Îó²î£¨CVE-2024-12086£©£ºrsync±£´æÎļþй¶Îó²î£¬¹¥»÷Õ߿ɽṹУÑéºÍ£¬Öð×Ö½Úö¾Ù¿Í»§¶Ëí§ÒâÎļþÄÚÈÝ¡£Îó²î¼¶±ðΪÖÐΣ£¬CVSSÆÀ·ÖΪ6.1·Ö¡£
·¾¶±éÀúÎó²î£¨CVE-2024-12087£©£ºrsync±£´æ·¾¶±éÀúÎó²î£¬¶ñÒâ·þÎñÆ÷¿ÉʹÓ÷ûºÅÁ´½ÓÈƹý£¬½«ÎļþдÈë¿Í»§¶ËµÄ·ÇÄ¿µÄĿ¼¡£Îó²î¼¶±ðΪÖÐΣ£¬CVSSÆÀ·ÖΪ6.5·Ö¡£
·¾¶±éÀúÎó²î£¨CVE-2024-12088£©£ºrsyncÔÚʹÓÃ`--safe-links`Ñ¡Ïîʱδ׼ȷÑéÖ¤·ûºÅÁ´½ÓÄ¿µÄ£¬µ¼Ö·¾¶±éÀúÎó²î£¬¿ÉÄܽ«ÎļþдÈë·ÇÔ¤ÆÚĿ¼¡£Îó²î¼¶±ðΪÖÐΣ£¬CVSSÆÀ·ÖΪ6.5·Ö¡£
·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þÎó²î£¨CVE-2024-12747£©£ºrsync±£´æ·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þÎó²î£¬¹¥»÷Õß¿ÉʹÓÃʱ»úÈƹýĬÈÏÐÐΪ£¬Ð¹Â¶Ãô¸ÐÐÅÏ¢²¢¿ÉÄܵ¼ÖÂȨÏÞÌáÉý¡£Îó²î¼¶±ðΪÖÐΣ£¬CVSSÆÀ·ÖΪ5.6·Ö¡£
ÆäÖУ¬»º³åÇøÒç³öÎó²î£¨CVE-2024-12084£©ÓëÐÅϢй¶Îó²î£¨CVE-2024-12085£©¿ÉÍŽáʹÓ㬹¥»÷Õß¿ÉÄÜʵÏÖÔ¶³Ì´úÂëÖ´ÐС£
¶þ¡¢Ó°Ïì¹æÄ£
CVE-2024-12747£¨·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þÎó²î£©£ºRsync < 3.4.0
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚ¸ÃÎó²îÒѾÐÞ¸´£¬Ç뾡¿ìÏÂÔز¢Éý¼¶ÖÁ×îа汾