¡¾Îó²îͨ¸æ¡¿OpenSSHË«ÖØÊÍ·ÅÎó²î£¨CVE-2023-25136£©
Ðû²¼Ê±¼ä 2023-02-060x00 Îó²î¸ÅÊö
CVE ID | CVE-2023-25136 | ·¢Ã÷ʱ¼ä | 2023-02-06 |
Àà ÐÍ | Double-Free | µÈ ¼¶ | |
Ô¶³ÌʹÓà | ËùÐèȨÏÞ | ||
¹¥»÷ÖØÆ¯ºó | Óû§½»»¥ | ||
PoC/EXP | ÔÚҰʹÓà |
0x01 Îó²îÏêÇé
OpenSSHÊÇSSH£¨Secure SHell£©ÐÒéµÄ¿ªÔ´ÊµÏÖ£¬£¬£¬£¬£¬Ëüͨ¹ý²»Çå¾²µÄÍøÂçÔÚÁ½¸ö²»ÊÜÐÅÈεÄÖ÷»úÖ®¼äÌṩÇå¾²µÄ¼ÓÃÜͨѶ¡£¡£¡£¡£¡£OpenSSH ÆÕ±éÓÃÓÚ»ùÓÚUnix µÄϵͳ£¬£¬£¬£¬£¬Í¨³£ÓÃÓÚÇå¾²Ô¶³ÌµÇ¼ºÍÔ¶³ÌÎļþ´«Ê䣬£¬£¬£¬£¬ÒÔ¼°ÆäËüÍøÂçЧÀÍ¡£¡£¡£¡£¡£
2ÔÂ3ÈÕ£¬£¬£¬£¬£¬ OpenSSH Server°æ±¾9.1Öб»Åû¶±£´æÒ»¸öË«ÖØÊÍ·ÅÎó²î£¨CVE-2023-25136£©£¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎó²îµÄϸ½ÚÒѾ¹ûÕæ¡£¡£¡£¡£¡£
OpenSSH server (sshd) 9.1ÔÚoptions.kex_algorithms´¦Öóͷ£Àú³ÌÖйýʧµØÒýÈëÁËÒ»¸öË«ÖØÊÍ·ÅÎó²î£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÔÚδ¾Éí·ÝÑéÖ¤µÄÇéÐÎÏÂÔÚOpenSSH server (sshd)µÄĬÈÏÉèÖÃÖд¥·¢Ë«ÖØÊÍ·Å¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
OpenSSH °æ±¾ 9.1
×¢£º¸ÃÎó²îÊÇsshd pre-auth·ÇÌØÈ¨Àú³ÌÖеÄË«ÖØÊÍ·ÅÎó²î£¬£¬£¬£¬£¬ÇÒ¸ÃÎó²î²»Ò×±»Ê¹Óᣡ£¡£¡£¡£
0x02 Çå¾²½¨Òé
ÏÖÔÚ¸ÃÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ OpenSSH 9.2¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.openssh.com/
0x03 ²Î¿¼Á´½Ó
https://www.openssh.com/releasenotes.html#9.2
https://blog.qualys.com/vulnerabilities-threat-research/2023/02/03/cve-2023-25136-pre-auth-double-free-vulnerability-in-openssh-server-9-1
https://www.openwall.com/lists/oss-security/2023/02/02/2
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2023-02-06 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
ÍòÀû¹ú¼Ê¹ÙÍø¼ò½é
ÍòÀû¹ú¼Ê¹ÙÍø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÍòÀû¹ú¼Ê¹ÙÍø´óÏ㬣¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£
¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø
ÍòÀû¹ú¼Ê¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ