Apache HTTP Server¶à¸öÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-08-110x00 Îó²î¸ÅÊö
²úÆ· |
CVE ID |
Àà ÐÍ |
Îó²îÆ·¼¶ |
Ô¶³ÌʹÓà |
Ó°Ïì¹æÄ£ |
Apache HTTP Server |
CVE-2020-9490 |
DOS |
¸ßΣ |
ÊÇ |
Apache HTTP Server 2.4.20-2.4.43 |
CVE-2020-11984 |
BO |
ÖÐΣ |
ÊÇ |
Apache HTTP Server 2.4.32-2.4.43 |
|
CVE-2020-11993 |
DOS |
ÖÐΣ |
ÊÇ |
Apache HTTP Server 2.4.20-2.4.43 |
0x01 Îó²îÏêÇé
2020Äê8ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬£¬Apache¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËApache HTTP ServerÖеÄÁ½¸ö¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2020-9490/CVE-2020-11993£©ºÍÒ»¸ö»º³åÇøÒç³öÎó²î£¨CVE-2020-11984£©£¬£¬£¬£¬£¬£¬£¬ÏêϸÐÅÏ¢ÈçÏ£º
Apache HTTP Server HTTP/2¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2020-9490£©
¸ÃÎó²îÔ´ÓÚÔÚHTTP/2ÇëÇóÖÐͨ¹ý½á¹¹¡¯Cache-Digest¡¯Öµ¿ÉÔì³ÉЧÀÍÍ߽⣬£¬£¬£¬£¬£¬£¬µ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿ÉÔÝʱÐ޸ġ°H2Push off¡±À´»º½â¹¥»÷¡£¡£¡£¡£¡£¡£¡£
Apache HTTP Server HTTP/2»º³åÇøÒç³öÎó²î£¨CVE-2020-11984£©
mod_proxy_uwsgiÊÇApacheµÄÒ»¸öЧÀÍÄ£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÌṩ¶ÔuwsgiÐÒéµÄÖ§³Ö¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚmod_proxy_uwsgiÖб£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÐÅϢй¶»òÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£
Apache HTTP Server HTTP/2¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2020-11993£©
¸ÃÎó²îÔ´ÓÚApache°æ±¾2.4.20ÖÁ2.4.43ΪHTTP2Ä£¿£¿£¿£¿£¿éºÍijЩÁ÷Á¿±ßÑØÄ£Ê½ÆôÓøú×Ù/µ÷ÊÔʱ£¬£¬£¬£¬£¬£¬£¬ÔÚ¹ýʧµÄÅþÁ¬ÉÏÖ´ÐÐÁËÈÕÖ¾¼Í¼Óï¾ä£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö²¢·¢Ê¹ÓÃÄÚ´æ³Ø£¬£¬£¬£¬£¬£¬£¬½µµÍ³ÌÐòÓë²Ù×÷ϵͳµÄÐÔÄÜ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿ÉÔÝʱÔÚ¡°info¡±ÉÏÉèÖÃmod_http2µÄLogLevelÀ´»º½â¹¥»÷¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
¹Ù·½ÒÑÐû²¼×îа汾£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£º
https://httpd.apache.org/download.cgi
0x03 Ïà¹ØÐÂÎÅ
https://www.tenable.com/plugins/nessus/139436
0x04 ²Î¿¼Á´½Ó
https://httpd.apache.org/security/vulnerabilities_24.html
0x05 ʱ¼äÏß
2020-08-07 ApacheÐû²¼Ç徲ͨ¸æ
2020-08-11 VSRCÐû²¼Îó²îͨ¸æ