¡¾Â©¶´Í¨¸æ¡¿Rsync »º³åÇøÒç³ö©¶´(CVE-2024-12084)

Ðû²¼Ê±¼ä 2025-01-17

Ò»¡¢Â©¶´¸ÅÊö


©¶´Ãû³Æ

Rsync »º³åÇøÒç³ö©¶´

CVE   ID

CVE-2024-12084

©¶´ÀàÐÍ

»º³åÇøÒç³ö

·¢ÏÖʱ¼ä

2025-01-17

©¶´ÆÀ·Ö

9.8

©¶´Æ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÈ»

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


rsyncÊÇÒ»ÖÖ³£ÓõÄÎļþͬ²½ºÍ´«Ê乤¾ß£¬Ö§³Ö¸ßЧµÄÔöÁ¿±¸·Ý¡£Í¨¹ý±ÈÁ¦Ô´ºÍÄ¿±êÎļþµÄ²îÒ죬rsyncÖ»´«Êä¸ü¸Ä¹ýµÄ²¿ÃÅ£¬´Ó¶ø½ÚÊ¡´ø¿íºÍʱ¼ä¡£ËüÖ§³Öµ±µØºÍÔ¶³ÌÎļþ´«Ê䣬³£ÓÃÓÚ±¸·Ý¡¢Í¬²½ºÍ²¿ÊðÈÎÎñ¡£


2025Äê1ÔÂ17ÈÕ£¬¶«É­Æ½Ì¨¼¯ÍÅVSRC¼à²âµ½RsyncÐû²¼Äþ¾²Í¨¸æ£¬È·ÈÏÆä·þÎñ¶Ë½ø³ÌRsyncd´æÔÚ»º³åÇøÒç³ö©¶´£¨CVE-2024-12084£©¡£Â©¶´¼¶±ðΪÑÏÖØ£¬CVSSÆÀ·ÖΪ9.8·Ö£¬¸Ã©¶´Ô´ÓÚrsyncÊØ»¤½ø³ÌÖÐδÕýÈ·´¦Öù¥»÷Õß¿ØÖƵÄУÑéºÍ³¤¶È£¨s2length£©¡£µ±MAX_DIGEST_LENÁè¼ÝÀι̵ÄSUM_LENGTH£¨16×Ö½Ú£©Ê±£¬¹¥»÷Õß¿ÉÒÔÔÚsum2»º³åÇøÖÐдÈëÔ½½çÊý¾Ý£¬´Ó¶ø´¥·¢¶ÑÄÚ´æÒç³öÎÊÌâ¡£


³ýÁË»º³åÇøÒç³ö©¶´£¨CVE-2024-12084£©Í⣬Rsync»¹´æÔÚÒÔÏ©¶´£º


ÐÅϢ鶩¶´£¨CVE-2024-12085£©£ºrsyncÊØ»¤½ø³Ì´æÔÚÐÅϢ鶩¶´£¬¹¥»÷Õß¿Éͨ¹ý²Ù¿ØУÑéºÍ³¤¶È£¨s2length£©£¬Òý·¢Óëδ³õʼ»¯ÄÚ´æµÄ±ÈÁ¦£¬Öð×Ö½Úй¶ջÊý¾Ý¡£Â©¶´¼¶±ðΪ¸ßΣ£¬CVSSÆÀ·ÖΪ7.5·Ö¡£


Îļþ鶩¶´£¨CVE-2024-12086£©£ºrsync´æÔÚÎļþ鶩¶´£¬¹¥»÷Õ߿ɽṹУÑéºÍ£¬Öð×Ö½Úö¾Ù¿Í»§¶ËÈÎÒâÎļþÄÚÈÝ¡£Â©¶´¼¶±ðΪÖÐΣ£¬CVSSÆÀ·ÖΪ6.1·Ö¡£


·¾¶±éÀú©¶´£¨CVE-2024-12087£©£ºrsync´æÔÚ·¾¶±éÀú©¶´£¬¶ñÒâ·þÎñÆ÷¿ÉÀûÓ÷ûºÅÁ´½ÓÈƹý£¬½«ÎļþдÈë¿Í»§¶ËµÄ·ÇÄ¿±êĿ¼¡£Â©¶´¼¶±ðΪÖÐΣ£¬CVSSÆÀ·ÖΪ6.5·Ö¡£


·¾¶±éÀú©¶´£¨CVE-2024-12088£©£ºrsyncÔÚʹÓÃ`--safe-links`Ñ¡ÏîʱδÕýÈ·ÑéÖ¤·ûºÅÁ´½ÓÄ¿±ê£¬µ¼Ö·¾¶±éÀú©¶´£¬¿ÉÄܽ«ÎļþдÈë·ÇÔ¤ÆÚĿ¼¡£Â©¶´¼¶±ðΪÖÐΣ£¬CVSSÆÀ·ÖΪ6.5·Ö¡£


·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þ©¶´£¨CVE-2024-12747£©£ºrsync´æÔÚ·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þ©¶´£¬¹¥»÷Õß¿ÉÀûÓÃʱ»úÈƹýĬÈÏÐÐΪ£¬Ð¹Â¶Ãô¸ÐÐÅÏ¢²¢¿ÉÄܵ¼ÖÂȨÏÞÌáÉý¡£Â©¶´¼¶±ðΪÖÐΣ£¬CVSSÆÀ·ÖΪ5.6·Ö¡£


ÆäÖУ¬»º³åÇøÒç³ö©¶´£¨CVE-2024-12084£©ÓëÐÅϢ鶩¶´£¨CVE-2024-12085£©¿ÉÁªºÏÀûÓ㬹¥»÷Õß¿ÉÄÜʵÏÖÔ¶³Ì´úÂëÖ´ÐС£


¶þ¡¢Ó°Ï췶Χ


CVE-2024-12084£¨»º³åÇøÒç³ö©¶´£©£º3.2.7=
CVE-2024-12085£¨ÐÅϢ鶩¶´£©£ºRsync < 3.4.0
CVE-2024-12086£¨Îļþ鶩¶´£©£ºRsync < 3.4.0
CVE-2024-12087£¨Â·¾¶±éÀú©¶´£©£ºRsync < 3.4.0
CVE-2024-12088£¨Â·¾¶±éÀú©¶´£©£ºRsync < 3.4.0

CVE-2024-12747£¨·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þ©¶´£©£ºRsync < 3.4.0


Èý¡¢Äþ¾²´ëÊ©


3.1 Éý¼¶°æ±¾


Ä¿Ç°¸Ã©¶´ÒѾ­ÐÞ¸´£¬Ç뾡¿ìÏÂÔز¢Éý¼¶ÖÁ×îа汾


ÏÂÔØÁ´½Ó£º
https://rsync.samba.org/download.html


3.2 ÁÙʱ´ëÊ©


CVE-2024-12084 (»º³åÇøÒç³ö©¶´)£¬½ûÓÃSHA*Ö§³Ö£¬Ê¹ÓÃÒÔϱàÒëÑ¡ÏCFLAGS=-DDISABLE_SHA512_DIGEST ºÍ CFLAGS=-DDISABLE_SHA256_DIGEST¡£
CVE-2024-12085 (ÐÅϢ鶩¶´)£¬±àÒëʱʹÓà -ftrivial-auto-var-init=zero£¬½«Õ»ÄÚÈݳõʼ»¯ÎªÁ㣬ÒÔ·ÀÖ¹ÐÅϢй¶¡£
CVE-2024-12086 (Îļþ鶩¶´)£¬ÏÞÖƶԿͻ§¶ËÎļþÄÚÈݵķÃÎÊ£¬È·±£·þÎñÆ÷½öÄܹ»·ÃÎÊÊÚȨµÄÎļþ¡£
CVE-2024-12087 (·¾¶±éÀú©¶´)£¬½ûÓÃ--inc-recursiveÑ¡Ïî»òÇ¿»¯·ûºÅÁ´½ÓÑéÖ¤£¬È·±£ÎļþдÈë½öÏÞÓÚÄ¿±êĿ¼ÄÚ¡£
CVE-2024-12088 (·¾¶±éÀú©¶´)£¬¼ÓÇ¿¶Ô--safe-linksÑ¡ÏîÏ·ûºÅÁ´½ÓÄ¿±êµÄÑéÖ¤£¬ÖÆֹ·¾¶±éÀú©¶´µÄ·¢Éú¡£
CVE-2024-12747 (·ûºÅÁ´½Ó¾ºÌ¬Ìõ¼þ©¶´)£¬Í¨¹ýÔöÇ¿·ûºÅÁ´½Ó´¦ÖÃÖеľºÌ¬Ìõ¼þ±£»¤£¬ÖÆÖ¹¹¥»÷ÕßÈƹýĬÈÏÐÐΪ²¢Ð¹Â¶Ãô¸ÐÐÅÏ¢¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬¼õÉÙϵͳ©¶´£¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ£¬Ð޸ķÀ»ðǽ¼Æı£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬¼õÉÙ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Äþ¾²²úÎÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏ޶ȡ£
ÆôÓÃÇ¿ÃÜÂë¼Æı²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£


3.4 ²Î¿¼Á´½Ó


https://www.openwall.com/lists/oss-security/2025/01/14/3
https://kb.cert.org/vuls/id/952657
https://nvd.nist.gov/vuln/detail/cve-2024-12084
https://nvd.nist.gov/vuln/detail/CVE-2024-12085
https://nvd.nist.gov/vuln/detail/CVE-2024-12086
https://nvd.nist.gov/vuln/detail/CVE-2024-12087
https://nvd.nist.gov/vuln/detail/CVE-2024-12088
https://nvd.nist.gov/vuln/detail/CVE-2024-12747
https://download.samba.org/pub/rsync/NEWS