Apache Traffic Server¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-06-30

0x00 Îó²î¸ÅÊö

²úÆ·Ãû³Æ

CVE ID

ÐÎò

Îó²îÆ·¼¶

Ô¶³ÌʹÓÃ

Apache Traffic Server

CVE-2021-27577

»º´æÖж¾

ÖÐΣ

ÊÇ

CVE-2021-32565

HTTPÇëÇó×ß˽

ÖÐΣ

CVE-2021-32566

Dos

¸ßΣ

CVE-2021-32567

ƵÈÔ¶ÁÈ¡

ÖÐΣ

CVE-2021-35474

¿ÍÕ»»º³åÇøÒç³ö

¸ßΣ

 

0x01 Îó²îÏêÇé

image.png

Apache Traffic Server? £¨ATS£©Èí¼þÊÇÒ»ÖÖ¿ìËÙ¡¢¿ÉÀ©Õ¹µÄHTTP/1.1 ºÍ HTTP/2 ¼æÈݵĿªÔ´Web»º´æÊðÀíЧÀÍÆ÷£¬£¬£¬ÏÖΪApache Èí¼þ»ù½ð»áµÄ¶¥¼¶ÏîÄ¿¡£ ¡£¡£

¿ËÈÕ£¬£¬£¬Apache Traffic Server±»Åû¶±£´æ¶à¸öÇå¾²Îó²î£¬£¬£¬Õ⽫µ¼ÖÂATSÈÝÒ×Êܵ½ÖÖÖÖ HTTP/1.x ºÍ HTTP/2 ¹¥»÷¡£ ¡£¡£

±¾´ÎÅû¶µÄÎó²î°üÀ¨£º

CVE-2021-27577£ºApache Traffic ServerµÄurlƬ¶Ï´¦Öóͷ£¹ýʧµ¼Ö»º´æÖж¾£¨ÖÐΣ£©

CVE-2021-32565£ºÍ¨¹ý½ç˵Content-Length×Ö¶ÎʵÏÖHTTPÇëÇó×ß˽£¨ÖÐΣ£©

CVE-2021-32566£ºHTTP/2 Ö¡µÄÌØ¶¨ÐòÁпÉÄܵ¼Ö ATS Í߽⣨¸ßΣ£©

CVE-2021-32567£º¶à´Î¶ÁÈ¡ HTTP/2 Ö¡£ ¡£¡£¨ÖÐΣ£©

CVE-2021-35474£ºcachekey²å¼þÖеĶ¯Ì¬¿ÍÕ»»º³åÇøÒç³ö£¨¸ßΣ£©

 

Ó°Ïì¹æÄ£

ATS 7.0.0 - 7.1.12

ATS 8.0.0 - 8.1.1

ATS 9.0.0 - 9.0.1

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚÕâЩÎó²îÒѾ­ÐÞ¸´£¬£¬£¬½¨ÒéÉý¼¶ÖÁÒÔϰ汾£º

7.x Óû§£ºÉý¼¶µ½ 8.1.2 »ò 9.0.2 »ò¸ü¸ß°æ±¾

8.x Óû§£ºÉý¼¶µ½ 8.1.2 »ò¸ü¸ß°æ±¾

9.x Óû§£ºÉý¼¶µ½ 9.0.2 »ò¸ü¸ß°æ±¾

ÏÂÔØÁ´½Ó£º

https://trafficserver.apache.org/downloads

 

0x03 ²Î¿¼Á´½Ó

https://lists.apache.org/thread.html/ra1a41ff92a70d25bf576d7da2590575e8ff430393a3f4a0c34de4277%40%3Cannounce.trafficserver.apache.org%3E

https://trafficserver.apache.org/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32565

 

0x04 ʱ¼äÏß

2021-06-24  Îó²îÅû¶

2021-06-30  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png