¡¾Â©¶´Í¨¸æ¡¿Apache Tomcat ¾Ü¾ø·þÎñ©¶´£¨CVE-2021-41079£©

Ðû²¼Ê±¼ä 2021-09-16

0x00 ©¶´¸ÅÊö

CVE     ID

CVE-2021-41079

ʱ      ¼ä

2021-09-15

Àà      ÐÍ

DoS

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ


PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

·ñ

 

0x01 ©¶´ÏêÇé

image.png

TomcatÊÇÓÉApacheÈí¼þ»ù½ð»áÏÂÊôµÄJakartaÏîÄ¿¿ª·¢µÄÒ»¸öServletÈÝÆ÷£¬ÊµÏÖÁ˶ÔServletºÍJavaServer Page£¨"text-indent:28px;line-height:150%">2021Äê9ÔÂ15ÈÕ£¬ApacheÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËTomcatÖеÄÒ»¸ö¾Ü¾ø·þÎñ©¶´£¨CVE-2021-41079£© ¡£µ±Tomcat±»ÅäÖÃΪʹÓÃNIO+OpenSSL»òNIO2+OpenSSL½øÐÐTLSʱ£¬¿ÉÒÔʹÓöñÒâÊý¾Ý°ü´¥·¢ÎÞÏÞÑ­»·£¬´Ó¶øµ¼Ö¾ܾø·þÎñ ¡£

 

Ó°Ï췶Χ

Apache Tomcat 10.0.0-M1 µ½ 10.0.2

Apache Tomcat 9.0.0-M1 µ½ 9.0.43

Apache Tomcat 8.5.0 µ½ 8.5.63

 

0x02 ´¦Öý¨Òé

Ŀǰ¸Ã©¶´ÒѾ­ÐÞ¸´£¬½¨ÒéÊÜÓ°ÏìµÄÓû§¼°Ê±Éý¼¶¸üе½ÒÔϰ汾£º

Apache Tomcat 10.0.4 »ò¸ü¸ß°æ±¾

Apache Tomcat 9.0.44 »ò¸ü¸ß°æ±¾

Apache Tomcat 8.5.64 »ò¸ü¸ß°æ±¾

×¢£º¸Ã©¶´ÒÑÔÚApache Tomcat 10.0.3 °æ±¾£¨Ðû²¼Î´Í¨¹ý£©ÖÐÐÞ¸´ ¡£

ÏÂÔØÁ´½Ó£º

https://tomcat.apache.org/

 

0x03 ²Î¿¼Á´½Ó

http://mail-archives.apache.org/mod_mbox/www-announce/202109.mbox/%3Ce1079445-c7b5-c4b0-3155-85c4cfc839ea@apache.org%3E

https://tomcat.apache.org/download-10.cgi

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-09-16

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

CVSS£ºwww.first.org

NVD£ºnvd.nist.gov

 

0x06 ¹ØÓÚ¶«É­Æ½Ì¨

¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png