¡¾Â©¶´Í¨¸æ¡¿Apache James¾Ü¾ø·þÎñ©¶´(CVE-2024-37358)
Ðû²¼Ê±¼ä 2025-02-07Ò»¡¢Â©¶´¸ÅÊö
©¶´Ãû³Æ | Apache James¾Ü¾ø·þÎñ©¶´ | ||
CVE ID | CVE-2024-37358 | ||
©¶´ÀàÐÍ | ¾Ü¾ø·þÎñ | ·¢ÏÖʱ¼ä | 2025-02-07 |
©¶´ÆÀ·Ö | 8.6 | ©¶´Æ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
Apache James£¨Java Apache Mail Enterprise Server£©ÊÇÒ»¸ö¿ªÔ´µÄÓʼþ·þÎñÆ÷£¬Ö§³ÖSMTP¡¢IMAP ºÍ POP3 ÐÒé¡£Ëü»ùÓÚJava¿ª·¢£¬¿ÉÀ©Õ¹²¢Ö§³ÖÄ£¿é»¯¼Ü¹¹£¬ÊÊÓÃÓÚÆóÒµ¼¶Óʼþ´¦Öá£James ¾ß±¸Óʼþ´æ´¢¡¢Óû§¹ÜÀí¡¢Óʼþ¹ýÂ˵ȹ¦Ð§£¬²¢¿É¼¯³ÉLDAP¡¢Êý¾Ý¿âµÈÍⲿϵͳ£¬ÊÊÓÃÓÚ¹¹½¨×Ô½ç˵Óʼþ½â¾ö·½°¸¡£
2025Äê2ÔÂ7ÈÕ£¬¶«Éƽ̨¼¯ÍÅVSRC¼à²âµ½Apache¹Ù·½Ðû²¼ÁËCVE-2024-37358©¶´Í¨¸æ¡£¸Ã©¶´Ó°ÏìApache James£¬¹¥»÷Õß¿ÉÀÄÓÃIMAP×ÖÃæÁ¿£¨IMAP literals£©´¥·¢ÎÞÏÞÖƵÄÄÚ´æ·ÖÅäºÍ³¤Ê±¼ä¼ÆË㣬´Ó¶øµ¼Ö¾ܾø·þÎñ£¨DoS£©¡£¸Ã©¶´¿É±»ÈÏÖ¤Óû§ºÍδÈÏÖ¤Óû§ÀûÓ㬿ÉÄܵ¼Ö·þÎñÆ÷×ÊÔ´ºÄ¾¡£¬Ó°ÏìÕý³£ÒµÎñÔËÐС£