PHP CGI²ÎÊý×¢È멶´£¨CVE-2024-4577£© ·ÖÎö

Ðû²¼Ê±¼ä 2024-06-08

Ò»¡¢Â©¶´ÃèÊö


2024Äê6ÔÂ6ÈÕ£¬PHP¹Ù·½Ðû²¼Á˶à¸öа汾£¬ÆäÖж¼°üÂÞ¶Ô±àºÅΪCVE-2024-4577µÄÄþ¾²Â©¶´µÄÐÞ¸´¸üР¡£¸Ã©¶´ÊÇPHP CGIµÄ²ÎÊý×¢È멶´£¬ÊǶÔCVE-2012-1823©¶´µÄÐÞ¸´Èƹý ¡£


¸Ã©¶´·¢ÉúµÄÔ­ÒòÊÇ£ºÔÚPHP CGIģʽÏ£¬Î´ÕýÈ·´¦ÖÃWindowsϵͳÖеġ°Best-Fit Mapping¡±ÌØÐÔ£¬µ¼Ö¼òÌåÖÐÎÄ¡¢·±ÌåÖÐÎÄ¡¢ÈÕÎÄ»òÆäËûÊÜÓ°ÏìÓïÑÔ»·¾³½«Ä³Ð©×Ö·û´íÎóµÄʶ±ð³ÉÁË'-' ¡£¹¥»÷Õß¿Éͨ¹ýÒýÈë¶ñÒâ²ÎÊýʵÏÖÈÎÒâ´úÂëÖ´ÐÐ ¡£


¶þ¡¢Â©¶´¸´ÏÖ


ÈçÏÂͼËùʾ£º


ͼƬ1.png


Èý¡¢Â©¶´·ÖÎö


CVE-2012-1823²¹¶¡µÄÐÞ¸´´ëÊ©ÊÇ£¬PHP´¦ÖÃͨ±¨½øÀ´µÄ×Ö·û´®Ê±£¬ÔÚÌø¹ýÇ°Ãæ¿Õ°×·ûºó£¬ÅжϵÚһλÊÇ·ñÊÇ'-'£»Èç¹ûÊÇ'-'£¬¾Í²î³ØºóÃæµÄ×Ö·û½øÐвÎÊý½âÎö£¬ºÃ±È-d,-s,-cµÈ²ÎÊý ¡£


PHP¹Ù·½µÄcommitÈçÏÂͼËùʾ£º


ͼƬ2.png


¿ÉÒÔ¿´µ½£¬µ±ÔËÐÐϵͳ»·¾³ÎªWindowsʱ£¬PHPµ÷ÓÃWideCharToMultiByteº¯ÊýÀ´¼ÓÇ¿¶Ô¿í×Ö·ûµÄÅжÏ ¡£Èç¹ûת»»ºóµÄ×Ö·ûΪ'-'£¬Ôò½«skip_getoptÖÃΪ1£¬Ê¹µÃºóÐø¾Í²»»á¶Ô´«ÈëµÄ×Ö·û´®½øÐвÎÊý½âÎö ¡£

ÄÇô£¬Ê²Ã´ÑùµÄ¿í×Ö·ûÄܹ»×ª»»ºóÄð³É'-'£¬´Ó¶øÈƹý֮ǰµÄÐÞ¸´ÄØ£¿


ÒÔÊÜÓ°ÏìµÄ¼òÌåÖÐÎÄ¡¢·±ÌåÖÐÎÄ¡¢ÈÕÎľÙÀý£¬ËûÃǶÔÓ¦µÄWindows ´úÂëÒ³·Ö±ðÊÇ936¡¢950¡¢932 ¡£ÆäÖж¼Óн«0x00adÓ³ÉäΪ0x002dµÄ²Ù×÷£¬ÈçÏÂͼËùʾ£º


ͼƬ3.png


ͼƬ4.png


ͼƬ5.png


Òò´Ëͨ¹ýÒýÈë0x00ad¼´¿ÉÌæ´ú0x002d£¬ÊµÏÖ²ÎÊý×¢ÈëÀ´Ö´ÐÐÈÎÒâ´úÂë ¡£


ËÄ¡¢×ܽá


CVE-2024-4577©¶´ÀûÓüòµ¥£¬Î£º¦ÑÏÖØ ¡£ÌرðÔÚijЩ¶ÔApache¡¢PHP½øÐм¯³É²¿ÊðºÍ¹ÜÀíµÄÁ÷ÐÐÈí¼þÖУ¬Èç¹ûδÕýÈ·ÅäÖÃphp cgi£¬¼´¿ÉÔì³ÉÑÏÖØΣº¦ ¡£



²Î¿¼Á´½Ó£º


PHP¹Ù·½commit

https://github.com/php/php-src/commit/4dd9a36c165974c84c4217aa41849b70a9fc19c9

DEVCOREµÄ©¶´Í¨±¨

https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability/