¡¾Â©¶´Í¨¸æ¡¿Apache MINA¾Ü¾ø·þÎñ©¶´ (CVE-2021-41973)
Ðû²¼Ê±¼ä 2021-11-020x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-41973 | ʱ ¼ä | 2021-11-01 |
Àà ÐÍ | Dos | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | Ó°Ï췶Χ | ||
¹¥»÷ÅÓ´ó¶È | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | ÔÚÒ°ÀûÓÃ |
0x01 ©¶´ÏêÇé
Apache MINA ÊÇÒ»¸öÍøÂçÓ¦Óÿò¼Ü£¬¿ÉÒÔ×ÊÖúÓû§ÇáËÉ¿ª·¢¸ßÐÔÄÜ¡¢¸ßÀ©Õ¹ÐÔµÄÍøÂçÓ¦Óá£Ëüͨ¹ý Java NIO ÔÚ TCP/IP ºÍ UDP/IP µÈÖÖÖÖ´«ÊäÉÏÌṩ³éÏóµÄʼþÇý¶¯Òì²½ API¡£
2021Äê11ÔÂ1ÈÕ£¬ApacheÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËApache MINAÖеÄÒ»¸ö¾Ü¾ø·þÎñ©¶´£¨CVE-2021-41973£©¡£
ÔÚApache MINAÖУ¬¶ñÒâÖÆ×÷µÄ¸ñʽ´íÎóµÄHTTPÇëÇó¿ÉÄܵ¼ÖÂHTTP Header½âÂëÆ÷ÎÞÏÞÑ»·¡£½âÂëÆ÷¼Ù¶¨HTTPÍ·´Ó»º³åÇøµÄ¿ªÍ·¿ªÊ¼£¬Èç¹ûÓбÈÔ¤ÆÚ¸ü¶àµÄÊý¾Ý¾Í»áÑ»·¡£
Ó°Ï췶Χ
Apache MINA < 2.1.5
Apache MINA < 2.0.22
0x02 ´¦Öý¨Òé
Ŀǰ´Ë©¶´ÒѾÐÞ¸´£¬½¨Ò齫Apache MINA ¸üе½2.0.22¡¢ 2.1.5»ò¸ü¸ß°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://mina.apache.org/downloads-mina_2_0.html
0x03 ²Î¿¼Á´½Ó
http://mail-archives.apache.org/mod_mbox/www-announce/202111.mbox/%3CCAG8=FRgUymSxuEoHDaQSAc7G4i+_uMivwenKN3U=hfrRESo0Sw@mail.gmail.com%3E
https://lists.apache.org/thread/r0b907da9340d5ff4e6c1a4798ef4e79700a668657f27cca8a39e9250@%3cdev.mina.apache.org%3e
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41973
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-11-02 | Ê×´ÎÐû²¼ |
0x05 ¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨¼ò½é
¶«Éƽ̨¹«Ë¾½¨Á¢ÓÚ1996Ä꣬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎïºÍÄþ¾²¹ÜÀíÆ½Ì¨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ£»²¢ÔÚ»ª±±¡¢»ª¶«¡¢Î÷ÄϺͻªÄϽṹËÄ´óÑз¢ÖÐÐÄ£¬·Ö±ðΪ±±¾©Ñз¢×ܲ¿¡¢ÉϺ£Ñз¢ÖÐÐÄ¡¢³É¶¼Ñз¢ÖÐÐĺ͹ãÖÝÑз¢ÖÐÐÄ¡£
¶àÄêÀ´£¬¶«Éƽ̨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
¹ØÓÚ¶«Éƽ̨
¶«Éƽ̨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£
¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º