¡¾Â©¶´Í¨¸æ¡¿Rsync »º³åÇøÒç³ö©¶´(CVE-2024-12084)
Ðû²¼Ê±¼ä 2025-01-17Ò»¡¢Â©¶´¸ÅÊö
©¶´Ãû³Æ | Rsync »º³åÇøÒç³ö©¶´ | ||
CVE ID | CVE-2024-12084 | ||
©¶´ÀàÐÍ | »º³åÇøÒç³ö | ·¢ÏÖʱ¼ä | 2025-01-17 |
©¶´ÆÀ·Ö | 9.8 | ©¶´Æ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | µÍ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
rsyncÊÇÒ»ÖÖ³£ÓõÄÎļþͬ²½ºÍ´«Ê乤¾ß£¬Ö§³Ö¸ßЧµÄÔöÁ¿±¸·Ý¡£Í¨¹ý±ÈÁ¦Ô´ºÍÄ¿±êÎļþµÄ²îÒ죬rsyncÖ»´«Êä¸ü¸Ä¹ýµÄ²¿ÃÅ£¬´Ó¶ø½ÚÊ¡´ø¿íºÍʱ¼ä¡£ËüÖ§³Öµ±µØºÍÔ¶³ÌÎļþ´«Ê䣬³£ÓÃÓÚ±¸·Ý¡¢Í¬²½ºÍ²¿ÊðÈÎÎñ¡£
2025Äê1ÔÂ17ÈÕ£¬¶«Éƽ̨¼¯ÍÅVSRC¼à²âµ½RsyncÐû²¼Äþ¾²Í¨¸æ£¬È·ÈÏÆä·þÎñ¶Ë½ø³ÌRsyncd´æÔÚ»º³åÇøÒç³ö©¶´£¨CVE-2024-12084£©¡£Â©¶´¼¶±ðΪÑÏÖØ£¬CVSSÆÀ·ÖΪ9.8·Ö£¬¸Ã©¶´Ô´ÓÚrsyncÊØ»¤½ø³ÌÖÐδÕýÈ·´¦Öù¥»÷Õß¿ØÖƵÄУÑéºÍ³¤¶È£¨s2length£©¡£µ±MAX_DIGEST_LENÁè¼ÝÀι̵ÄSUM_LENGTH£¨16×Ö½Ú£©Ê±£¬¹¥»÷Õß¿ÉÒÔÔÚsum2»º³åÇøÖÐдÈëÔ½½çÊý¾Ý£¬´Ó¶ø´¥·¢¶ÑÄÚ´æÒç³öÎÊÌâ¡£
³ýÁË»º³åÇøÒç³ö©¶´£¨CVE-2024-12084£©Í⣬Rsync»¹´æÔÚÒÔÏ©¶´£º
ÐÅϢ鶩¶´£¨CVE-2024-12085£©£ºrsyncÊØ»¤½ø³Ì´æÔÚÐÅϢ鶩¶´£¬¹¥»÷Õß¿Éͨ¹ý²Ù¿ØУÑéºÍ³¤¶È£¨s2length£©£¬Òý·¢Óëδ³õʼ»¯ÄÚ´æµÄ±ÈÁ¦£¬Öð×Ö½Úй¶ջÊý¾Ý¡£Â©¶´¼¶±ðΪ¸ßΣ£¬CVSSÆÀ·ÖΪ7.5·Ö¡£
Îļþ鶩¶´£¨CVE-2024-12086£©£ºrsync´æÔÚÎļþ鶩¶´£¬¹¥»÷Õ߿ɽṹУÑéºÍ£¬Öð×Ö½Úö¾Ù¿Í»§¶ËÈÎÒâÎļþÄÚÈÝ¡£Â©¶´¼¶±ðΪÖÐΣ£¬CVSSÆÀ·ÖΪ6.1·Ö¡£
·¾¶±éÀú©¶´£¨CVE-2024-12087£©£ºrsync´æÔÚ·¾¶±éÀú©¶´£¬¶ñÒâ·þÎñÆ÷¿ÉÀûÓ÷ûºÅÁ´½ÓÈƹý£¬½«ÎļþдÈë¿Í»§¶ËµÄ·ÇÄ¿±êĿ¼¡£Â©¶´¼¶±ðΪÖÐΣ£¬CVSSÆÀ·ÖΪ6.5·Ö¡£
·¾¶±éÀú©¶´£¨CVE-2024-12088£©£ºrsyncÔÚʹÓÃ`--safe-links`Ñ¡ÏîʱδÕýÈ·ÑéÖ¤·ûºÅÁ´½ÓÄ¿±ê£¬µ¼Ö·¾¶±éÀú©¶´£¬¿ÉÄܽ«ÎļþдÈë·ÇÔ¤ÆÚĿ¼¡£Â©¶´¼¶±ðΪÖÐΣ£¬CVSSÆÀ·ÖΪ6.5·Ö¡£
·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þ©¶´£¨CVE-2024-12747£©£ºrsync´æÔÚ·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þ©¶´£¬¹¥»÷Õß¿ÉÀûÓÃʱ»úÈƹýĬÈÏÐÐΪ£¬Ð¹Â¶Ãô¸ÐÐÅÏ¢²¢¿ÉÄܵ¼ÖÂȨÏÞÌáÉý¡£Â©¶´¼¶±ðΪÖÐΣ£¬CVSSÆÀ·ÖΪ5.6·Ö¡£
ÆäÖУ¬»º³åÇøÒç³ö©¶´£¨CVE-2024-12084£©ÓëÐÅϢ鶩¶´£¨CVE-2024-12085£©¿ÉÁªºÏÀûÓ㬹¥»÷Õß¿ÉÄÜʵÏÖÔ¶³Ì´úÂëÖ´ÐС£
¶þ¡¢Ó°Ï췶Χ
CVE-2024-12747£¨·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þ©¶´£©£ºRsync < 3.4.0
Èý¡¢Äþ¾²´ëÊ©
3.1 Éý¼¶°æ±¾
Ä¿Ç°¸Ã©¶´ÒѾÐÞ¸´£¬Ç뾡¿ìÏÂÔز¢Éý¼¶ÖÁ×îа汾