E2fsprogs Ô¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-01-14Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-5188£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
E2fsprogs 1.43.3 - 1.45.4
Îó²î¸ÅÊö
˼¿ÆTalosÑо¿ÍŶÓÅû¶ÎļþϵͳÖÎÀí¹¤¾ßE2fsprogsÖеÄRCEÎó²î¡£¡£¡£E2fsprogsÊÇÒ»×éÓÃÓÚÓëext2¡¢ext3ºÍext4Îļþϵͳ½»»¥µÄÊÊÓóÌÐò£¬£¬£¬£¬¸ÃÈí¼þ±»ÊÓΪLinuxºÍÀàUnix²Ù×÷ϵͳµÄ±Ø±¸Èí¼þ£¬£¬£¬£¬Ä¬ÈÏÔÚ´ó´ó¶¼Linux¿¯ÐаæÖгö³§¸½´ø¡£¡£¡£
¸ÃÎó²î£¨CVE-2019-5188£©±£´æÓÚE2fsprogs e2fsck rehash.cÎļþµÄmutate_name()º¯ÊýÖУ¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÌØÖÆµÄext4Ŀ¼´¥·¢¿ÍÕ»Ô½½çдÈ룬£¬£¬£¬´Ó¶øµ¼Ö´úÂëÖ´ÐС£¡£¡£¹¥»÷ÕßÐè񻮮Ëð·ÖÇøÀ´´¥·¢´ËÎó²î¡£¡£¡£
Îó²îÑéÖ¤
POC£ºhttps://talosintelligence.com/vulnerability_reports/TALOS-2019-0973¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£ºhttp://e2fsprogs.sourceforge.net/¡£¡£¡£
²Î¿¼Á´½Ó
https://blog.talosintelligence.com/2020/01/e2fsprogs-remote-code-execution-vuln-jan-2020.html