¡¾Îó²îͨ¸æ¡¿OpenSSHË«ÖØÊÍ·ÅÎó²î£¨CVE-2023-25136£©
Ðû²¼Ê±¼ä 2023-02-060x00 Îó²î¸ÅÊö
CVE ID | CVE-2023-25136 | ·¢Ã÷ʱ¼ä | 2023-02-06 |
Àà ÐÍ | Double-Free | µÈ ¼¶ | |
Ô¶³ÌʹÓà | ËùÐèȨÏÞ | ||
¹¥»÷ÖØÆ¯ºó | Óû§½»»¥ | ||
PoC/EXP | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé
OpenSSHÊÇSSH£¨Secure SHell£©ÐÒéµÄ¿ªÔ´ÊµÏÖ£¬£¬£¬£¬£¬£¬£¬Ëüͨ¹ý²»Çå¾²µÄÍøÂçÔÚÁ½¸ö²»ÊÜÐÅÈεÄÖ÷»úÖ®¼äÌṩÇå¾²µÄ¼ÓÃÜͨѶ¡£¡£¡£¡£OpenSSH ÆÕ±éÓÃÓÚ»ùÓÚUnix µÄϵͳ£¬£¬£¬£¬£¬£¬£¬Í¨³£ÓÃÓÚÇå¾²Ô¶³ÌµÇ¼ºÍÔ¶³ÌÎļþ´«Ê䣬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÆäËüÍøÂçЧÀÍ¡£¡£¡£¡£
2ÔÂ3ÈÕ£¬£¬£¬£¬£¬£¬£¬ OpenSSH Server°æ±¾9.1Öб»Åû¶±£´æÒ»¸öË«ÖØÊÍ·ÅÎó²î£¨CVE-2023-25136£©£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎó²îµÄϸ½ÚÒѾ¹ûÕæ¡£¡£¡£¡£
OpenSSH server (sshd) 9.1ÔÚoptions.kex_algorithms´¦Öóͷ£Àú³ÌÖйýʧµØÒýÈëÁËÒ»¸öË«ÖØÊÍ·ÅÎó²î£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÔÚδ¾Éí·ÝÑéÖ¤µÄÇéÐÎÏÂÔÚOpenSSH server (sshd)µÄĬÈÏÉèÖÃÖд¥·¢Ë«ÖØÊÍ·Å¡£¡£¡£¡£
Ó°Ïì¹æÄ£
OpenSSH °æ±¾ 9.1
×¢£º¸ÃÎó²îÊÇsshd pre-auth·ÇÌØÈ¨Àú³ÌÖеÄË«ÖØÊÍ·ÅÎó²î£¬£¬£¬£¬£¬£¬£¬ÇÒ¸ÃÎó²î²»Ò×±»Ê¹Óᣡ£¡£¡£
0x02 Çå¾²½¨Òé
ÏÖÔÚ¸ÃÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ OpenSSH 9.2¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.openssh.com/
0x03 ²Î¿¼Á´½Ó
https://www.openssh.com/releasenotes.html#9.2
https://blog.qualys.com/vulnerabilities-threat-research/2023/02/03/cve-2023-25136-pre-auth-double-free-vulnerability-in-openssh-server-9-1
https://www.openwall.com/lists/oss-security/2023/02/02/2
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2023-02-06 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
¼øºÚµ£±£Íø¼ò½é
¼øºÚµ£±£Íø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¼øºÚµ£±£Íø´óÏ㬣¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£
¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º