Intel Wi-FiÇý¶¯Â©¶´·ÖÎö
Ðû²¼Ê±¼ä 2021-04-27Intel Wi-FiоƬ¹ã·ºÓ¦ÓÃÓÚ¸öÈËÌõ¼Ç±¾µçÄÔ²úÎÈçThinkPad¡¢DellÌõ¼Ç±¾µÈ¡£2020Ä꣬ZDI×éÖ¯Åû¶ÁËIntelÎÞÏßÍø¿¨WindowsÇý¶¯·¨Ê½ÖдæÔÚCVE-2020-0557 ºÍ CVE-2020-0558©¶´¡£ÆäÖУ¬CVE-2020-0557µÄCVSS v3.0ÆÀ·ÖΪ 8.1 ·Ö£¬CVE-2020-0558µÄCVSS v3.0ÆÀ·ÖΪ 8.2 ·Ö¡£Í¨¹ýÕâÁ½¸ö©¶´£¬¹¥»÷Õß¿ÉÒÔÔÚÊܺ¦ÕßµçÄÔÖÐÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£
©¶´±àºÅ | Ó°ÏìµÄÎÞÏßÍø¿¨ | Ó°ÏìÇý¶¯ |
CVE-2020-0557 | AC 7265 Rev D¡¢AC 3168¡¢AC 8265ºÍAC8260 | Intel PROSet/Wireless WiFi Software 21.70֮ǰ°æ±¾ |
CVE-2020-0558 | AC8265 | Intel PROSet/Wireless WiFi Software 21.70֮ǰ°æ±¾ |
CVE-2020-0558©¶´·ÖÎö
1¡¢Â©¶´ÔÀí
µ±APÈȵ㴦ÖÃAssocReqʱ£¬»áµ÷ÓÃprvhPanClientSaveAssocRespº¯ÊýÉú´æAssocReqÖ¡ÖÐSSIDµÄÖµ£¬ÔÚ´¦ÖÃSSIDµÄ¹ý³ÌÖУ¬»áµ÷ÓÃparse_ieº¯Êý´ÓÊý¾ÝÖ¡ÖÐÈ¡³össidµÄTLV½á¹¹£¬²¢µ÷ÓÃmemcpy_sº¯Êý½«ssidµÄÄÚÈݸ´ÖƵ½Ä¿±ê»º³åÇø¡£ÔÚµ÷ÓÃmemcpy_sº¯ÊýµÄʱºò£¬´íÎóµØʹÓÃssidµÄlength×÷ΪÊý¾Ý¸´ÖƳ¤¶È£¬µ±ssidµÄ³¤¶È´óÓÚÄ¿±ê»º³åÇøµÄ³¤¶Èʱ£¬»áµ¼Ö»º³åÇøÒç³ö¡£º¯Êýµ÷ÓÃͼÈçÏÂËùʾ£º
2¡¢ÎÊÌâ´úÂë
µ÷ÓÃparse_ieº¯Êý´ÓÊý¾ÝÖ¡ÖÐÈ¡³össidµÄTLV½á¹¹£¬²¢µ÷ÓÃmemcpy_sº¯Êý½«ssidµÄÄÚÈݸ´ÖƵ½Ä¿±ê»º³åÇø¡£ÔÚµ÷ÓÃmemcpy_sº¯ÊýµÄʱºò£¬´íÎóµØʹÓÃssidµÄlength×÷ΪÊý¾Ý¸´ÖƳ¤¶È£¬µ±ssidµÄ³¤¶È´óÓÚÄ¿±ê»º³åÇøµÄ³¤¶Èʱ£¬»áµ¼Ö»º³åÇøÒç³ö¡£ÔÚÏÂͼÖУ¬¹¥»÷Õß¿ÉÒÔ¿ØÖÆ*(v8+1)µÄÖµ£¬¿ÉÒÔ¿½±´³¬³¤µÄÊý¾Ý¸´ÖƵ½Ä¿±êµØÖ·ÖУ¬´Ó¶øµ¼Ö»º³åÇøÒç³ö¡£ÈçÏÂͼËùʾ£º
3¡¢Â©¶´ÐÞ¸´
а汾µÄ´úÂëÖÐʹÓÃosalMemoryCopyº¯ÊýÌæ´úÁËÔÀ´µÄmemcpy_sº¯Êý£¬ÁíÍâ°ÑSSID¿½±´µÄ×î´ó³¤¶ÈÇ¿ÖÆÉèΪ32×Ö½Ú£¬ÕâÑù¾ÍÖÆÖ¹ÁË»º´æÇøÒç³öµÄÎÊÌâ¡£ÈçÏÂͼËùʾ£º
CVE-2020-0557©¶´·ÖÎö
1¡¢Â©¶´ÔÀí
µ±APÈȵ㴦ÖÃAssocReqʱ£¬»áµ÷ÓÃprvhPanClientSaveAssocRespº¯Êý´¦ÖÃAssocReqÖ¡ÖеÄÊý¾Ý£¬ÆäÖÐÔÚº¯ÊýÖлáµ÷ÓÃprvGoVifClientAssocStoreSupportedChannelsº¯ÊýÀ´´¦Öü°Éú´æÇëÇó¶ËͨµÀÐÅÏ¢£¬ÕâÆäÖÐprvGoVifClientAssocStoreSupportedChannelsº¯Êý»áÑ»·µ÷ÓÃutilRegulatoryClassToChannelListÀ´´¦ÖÃRegulatoryClass£¨¹ÜÖÆÒªÇó£©ÐÅÏ¢¡£ÓÉÓÚÔÚÑ»·´¦ÖÃûÓп¼ÂÇÄ¿±êµÄÆ«ÒÆÊÇ·ñÔ½½ç£¬µ±APÈȵã½ÓÊÕµ½AssocReqÊý¾ÝÖ¡ÖÐRegulatoryClassÐÅÏ¢µ¥ÔªÓжà¸öÐŵÀÊý¾Ýʱ»áµ¼ÖÂÔ½½çд¡£º¯Êýµ÷ÓÃͼÈçÏÂͼËùʾ£º
2¡¢ÎÊÌâ´úÂë
prvGoVifClientAssocStoreSupportedChannelsº¯Êý£¬ÈçÏÂͼËùʾ£º
3¡¢Â©¶´ÐÞ¸´
ÔÚа汾 Ôö½øÁ˶Ե±Ç°indexµÄÅжϣ¬Èç¹ûindex´óÓÚ255ÔòÍ˳öÑ»·¡£ÈçÏÂͼËùʾ£º
4¡¢Â©¶´ÑéÖ¤
²Î¿¼Á´½Ó£º
¡¾1¡¿https://www.thezdi.com/blog/2020/5/4/analyzing-a-trio-of-remote-code-execution-bugs-in-intel-wireless-adapters
¶«Éƽ̨»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØֹĿǰ£¬ADLabÒÑͨ¹ýCVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´½ü1100¸ö£¬Í¨¹ý CNVD/CNNVDÀÛ¼ÆÐû²¼Äþ¾²Â©¶´1000Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç²Ù×÷ϵͳÓëÓ¦ÓÃϵͳÄþ¾²Ñо¿¡¢ÖÇÄÜÖÕ¶ËÄþ¾²Ñо¿¡¢ÎïÁªÍøÖÇÄÜÉ豸Äþ¾²Ñо¿¡¢WebÄþ¾²Ñо¿¡¢¹¤¿ØϵͳÄþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£