VxWorks¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ðû²¼Ê±¼ä 2019-07-31

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


1¡¢Åä¾°ÐÎò


Çå¾²Ñо¿Ö°Ô±ÔÚVxWorksÖз¢Ã÷ÁË11¸ö0dayÎó²î£¬£¬£¬£¬£¬VxWorksÊÇǶÈëʽװ±¸ÖÐʹÓÃ×îÆÕ±éµÄʵʱ²Ù×÷ϵͳ£¨RTOS£©Ö®Ò»£¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚº½¿Õº½Ì죬£¬£¬£¬£¬¹ú·À£¬£¬£¬£¬£¬¹¤Òµ£¬£¬£¬£¬£¬Ò½ÁÆ£¬£¬£¬£¬£¬Æû³µµÈÁìÓò£¬£¬£¬£¬£¬È«ÇòÖÁÉÙ20ÒŲ́װ±¸Ê¹ÓÃʹÓÃVxWorks¡£ ¡£¡£¡£ÕâЩÎó²î±»Í³³ÆÎªURGENT/11£¬£¬£¬£¬£¬ÓÉÓÚËüÃǹ²ÓÐ11¸ö£¬£¬£¬£¬£¬ÆäÖÐ6¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ ¡£¡£¡£

VxWorksÓÃ;ºÜÊÇÆÕ±é£¬£¬£¬£¬£¬ÀýÈçÍøÂçÉãÏñÍ·£¬£¬£¬£¬£¬ÍøÂç½»Á÷»ú£¬£¬£¬£¬£¬Â·ÓÉÆ÷£¬£¬£¬£¬£¬·À»ðǽ£¬£¬£¬£¬£¬VOIPµç»°£¬£¬£¬£¬£¬´òÓ¡»úºÍÊÓÆµ¾Û»á²úÆ·£¬£¬£¬£¬£¬ÒÔ¼°½»Í¨Ñ¶ºÅµÆ¡£ ¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬£¬VxWorks»¹±»Ö÷ҪϵͳʹÓ㬣¬£¬£¬£¬ÀýÈçSCADA£¬£¬£¬£¬£¬»ð³µ£¬£¬£¬£¬£¬µçÌݺ͹¤Òµ¿ØÖÆÆ÷£¬£¬£¬£¬£¬²¡È˼໤ÒÇ£¬£¬£¬£¬£¬ºË´Å¹²Õñ³ÉÏñÒÇÆ÷£¬£¬£¬£¬£¬ÎÀÐǵ÷ÖÆ½âµ÷Æ÷£¬£¬£¬£¬£¬ÉõÖÁÊÇ»ðÐÇ̽²âÆ÷¡£ ¡£¡£¡£

2¡¢Îó²îÏêÇé


URGENT/11Îó²îÓ°Ïì×Ô6.5°æÒÔÉϵÄËùÓÐVxWorks°æ±¾¡£ ¡£¡£¡£ÏÔÈ»ÔÚÒÑÍù13ÄêÖÐÐû²¼µÄËùÓÐVxWorks°æ±¾¶¼ÈÝÒ×Êܵ½¹¥»÷¡£ ¡£¡£¡£

ÆäÖÐ6¸öÎó²î¿É´¥·¢Ô¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷£¬£¬£¬£¬£¬¶øÊ£ÏµÄÎó²î¿ÉÄܻᵼÖ¾ܾøÐ§ÀÍ£¬£¬£¬£¬£¬ÐÅϢй¶»òÂß¼­Îó²î¡£ ¡£¡£¡£

Ô¶³ÌÖ´ÐдúÂëȱÏÝ£º


ÆÊÎöIPv4Ñ¡Ïîʱ¿ÍÕ»Òç³ö£¨CVE-2019-12256£©


ÓÉÓÚ¹ýʧ´¦Öóͷ£TCPµÄÖ¸Õë×ֶζøµ¼ÖµÄËĸöÄÚ´æËð»µÎó²î£¨CVE-2019-12255£¬£¬£¬£¬£¬CVE-2019-12260£¬£¬£¬£¬£¬CVE-2019-12261£¬£¬£¬£¬£¬CVE-2019-12263£©


ipdhcpcÖеÄDHCP Offer / ACKÆÊÎöÖеĶÑÒç³ö£¨CVE-2019-12257£©

DoS£¬£¬£¬£¬£¬ÐÅÏ¢×ß©ºÍÂß¼­È±ÏÝ£º


ͨ¹ýÃûÌùýʧµÄTCPÑ¡Ïî¾ÙÐÐTCPÅþÁ¬DoS£¨CVE-2019-12258£©


´¦Öóͷ£Î´¾­ÇëÇóµÄ·´ÏòARP»Ø¸´£¨Âß¼­È±ÏÝ£©£¨CVE-2019-12262£©


ipdhcpc DHCP¿Í»§¶Ë·ÖÅÉIPv4µÄÂß¼­È±ÏÝ£¨CVE-2019-12264£©


ÔÚIGMPÆÊÎöÖÐͨ¹ýNULLɨ³ýÒýÓõÄDoS£¨CVE-2019-12259£©


IGMPÐÅÏ¢×ß©ͨ¹ýIGMPv3ÌØ¶¨³ÉÔ±±¨¸æ£¨CVE-2019-12265£©

3¡¢ÐÞ¸´½¨Òé


VxWorksÒÑÌṩ²¹¶¡¸üУ¬£¬£¬£¬£¬¿ÉÔÚVxWorksÇå¾²ÖÐÐÄÐû²¼µÄWind River Security AlertÖÐÕÒµ½£º


https://www.windriver.com/security/
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/

4¡¢²Î¿¼Á´½Ó


https://www.windriver.com/security/
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
https://www.sonicwall.com/support/product-notification/?sol_id=190717234810906
https://security.business.xerox.com/en-us/