E2fsprogs Ô¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-01-14

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5188£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬ £¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


E2fsprogs 1.43.3 - 1.45.4


Îó²î¸ÅÊö


˼¿ÆTalosÑо¿ÍŶÓÅû¶ÎļþϵͳÖÎÀí¹¤¾ßE2fsprogsÖеÄRCEÎó²î¡£¡£¡£¡£¡£¡£E2fsprogsÊÇÒ»×éÓÃÓÚÓëext2¡¢ext3ºÍext4Îļþϵͳ½»»¥µÄÊÊÓóÌÐò£¬£¬ £¬£¬£¬£¬¸ÃÈí¼þ±»ÊÓΪLinuxºÍÀàUnix²Ù×÷ϵͳµÄ±Ø±¸Èí¼þ£¬£¬ £¬£¬£¬£¬Ä¬ÈÏÔÚ´ó´ó¶¼Linux¿¯ÐаæÖгö³§¸½´ø¡£¡£¡£¡£¡£¡£


¸ÃÎó²î£¨CVE-2019-5188£©±£´æÓÚE2fsprogs e2fsck rehash.cÎļþµÄmutate_name()º¯ÊýÖУ¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÌØÖÆµÄext4Ŀ¼´¥·¢¿ÍÕ»Ô½½çдÈ룬£¬ £¬£¬£¬£¬´Ó¶øµ¼Ö´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¹¥»÷ÕßÐè񻮮Ëð·ÖÇøÀ´´¥·¢´ËÎó²î¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


POC£ºhttps://talosintelligence.com/vulnerability_reports/TALOS-2019-0973¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬ £¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttp://e2fsprogs.sourceforge.net/¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.talosintelligence.com/2020/01/e2fsprogs-remote-code-execution-vuln-jan-2020.html