СÖ÷£¬£¬£¬£¬¡°Ìì¾µ¡±Ç°À´ÎÊÕïÀ²~
Ðû²¼Ê±¼ä 2018-04-09
°Ù»¨Æë·Å¡¢ÍòÁø´¹ÌÐ
±¾¸ÃÊǸö̤ÇàÉÍ´º¡¢ÐÀÐÀÏòÈٵĺü¾½Ú
È»¶øÇå¾²È¦È´Î´ÔøÏûÍ£
ÔÚÂÄÀúÁË¡°ÈÛ¶Ï¡±ºÍ¡°ÓÄÁ顱µÄÏ´Àñºó
ÿ¸öÍøÂçÇå¾²È˶¼Ê±¿ÌСÐÄ×Å
ËæÊ±·ÀÓùÐÂÒ»ÂÖ¶ñÒâ¹¥»÷
Õâ²»
ÍòÀû¹ú¼Ê¹ÙÍøÂ©É¨ÍŶӾͿªÆôÁË¡°Ìì¾µÎÊÕïģʽ¡±
¡ý¡ý¡ý
ÎÊÕïÒ»ºÅ£ºmemcache·Å´ó¹¥»÷
memcachedµÄЧÀÍÒì³£·¢°ü£¬£¬£¬£¬µ¼ÖÂϵͳ×ÊÔ´Ö÷Òª£¬£¬£¬£¬Õâô´óµÄÊý¾ÝÁ¿»á²»»á¶Ô±ðµÄÍøÂç×°±¸Ôì³ÉÓ°Ï죿£¿£¿£¿£¿
Òì³£·¢°ü£¬£¬£¬£¬×ÊÔ´Ö÷Òª£¬£¬£¬£¬·¢°üÄ¿µÄµØµãÃ÷È·£»£»£»£»£»£»£»¸Ã»¼Õß±£´æ±àºÅΪCVE-2018-1000115µÄMemcache Ïà¹ØÎó²î£¬£¬£¬£¬Í¨¹ý¸ÃÎó²î£¬£¬£¬£¬Òѱ»ÓÃÓÚ·Å´ó¾Ü¾øÐ§À͹¥»÷È⼦£¬£¬£¬£¬½¨ÒéʵʱÅŲ顣¡£¡£¡£¡£¡£
memcached·Å´ó¹¥»÷£¬£¬£¬£¬ºÚ¿Íͨ¹ýÌØ¶¨µÄµÄIPµØµãÏòÍøÕ¾µÄ»º´æÐ§ÀÍÆ÷UDP¶Ë¿Ú11211£¬£¬£¬£¬·¢³ö¼ÙÇëÇ󣬣¬£¬£¬×îÖÕÒý·¢´ó¹æÄ£µÄ²¢·¢»ØÓ¦¡£¡£¡£¡£¡£¡£¾ÝÍøÂçÇå¾²¹«Ë¾ÆÊÎö£¬£¬£¬£¬Ö»ÐèÒªÉÙÁ¿µÄÅþÁ¬ÇëÇó¾Í¿ÉÒÔÇë·¢³ÉǧÉÏÍò´ÎµÄÍøÕ¾»ØÓ¦´ÎÊý£¬£¬£¬£¬15±ÈÌØµÄÅþÁ¬ÇëÇó»áÒý·¢134KBµÄ»ØÓ¦£¬£¬£¬£¬ÕâÖÖ¹¥»÷Ч¹û·Å´óÁË10000±¶£¡ÏÖʵ²âÊÔÖУ¬£¬£¬£¬ÉõÖÁ»¹ÄÜÒý·¢750KBµÄ»ØÓ¦£¬£¬£¬£¬¹¥»÷Ч¹û·Å´óÁË51200±¶£¡
1.¼ì²âÊÇ·ñ±£´æ±È±àºÅΪCVE-2018-1000115µÄÎó²î£»£»£»£»£»£»£»
2.¼ì²âMemcacheÆäËüµÄÏà¹ØÎó²î£¬£¬£¬£¬°ü¹ÜMemcacheЧÀÍÕý³£ÔËÐС£¡£¡£¡£¡£¡£
£¨½¨ÒéʹÓÃÌ쾵ųÈõɨÃèÓëÖÎÀíϵͳ£¬£¬£¬£¬Éý¼¶ÖÁ60700151Éý¼¶°ü£©
×î¼òÆÓµÄÔ¤·À²½·¥ÊÇϵͳ·À»ðǽ£¬£¬£¬£¬½ûÓûòÏÞÖÆ11211µÄUDP¶Ë¿ÚºÅ¡£¡£¡£¡£¡£¡£ÓÉÓÚMemcached»º´æÐ§ÀÍÆ÷ĬÈÏ¿ªÆô¼àÌýINADDR_ANYºÍUDP¹¦Ð§£¬£¬£¬£¬ÏµÍ³ÖÎÀíÔ±¿ÉÒÔÔÚÉèÖÃÖйرÕUDP¡£¡£¡£¡£¡£¡£
ÎÊÕï¶þºÅ£ºEximí§ÒâÏÂÁîÖ´ÐÐ
EximÔÚ´¦Öóͷ£ÎļþµÄʱ¼ä£¬£¬£¬£¬ÔÚϵͳÖе¯³öÁËÅÌËãÆ÷£¬£¬£¬£¬ÕâÊÇÔõô»ØÊ£¿£¿£¿£¿£¿
ƾ֤ÏÖÓÐʱ¼äµã£¬£¬£¬£¬¸Ã»¼ÕßÓ¦¸Ã±£´æ±àºÅΪCVE-2018-6789µÄÎó²î£¬£¬£¬£¬Õâ¸öÎó²î¿ÉÒÔÈÃEximÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬½¨ÒéʵʱÅŲ顣¡£¡£¡£¡£¡£
¸ÃÎó²îÔ´ÓÚbase64½âÂ뺯ÊýÖеÄÒ»¸ö»º³åÇøÒç³öÎÊÌâ¡£¡£¡£¡£¡£¡£Í¨ÀýÏÂbase64±àÂëµÄ×Ö·û´®µÄ³¤¶ÈΪ4µÄ±¶Êý£¬£¬£¬£¬¿ÉÊÇÓпÉÄÜÔÚ´«Êä»òÕß¶ñÒâ½á¹¹µÄÇéÐÎϵ¼Ö³¤¶È²»Îª4µÄ±¶Êý£¬£¬£¬£¬ÖÂʹ³¤¶ÈÅÌËã¹ýʧ¡£¡£¡£¡£¡£¡£Í¨¹ý¸ÃÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÈÆ¹ý·À»¤»úÖÆÔÚÊÜÓ°ÏìµÄÓ¦ÓóÌÐòÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£Èô¹¥»÷ʵÑéʧ°ÜÈԿɵ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£¡£
1. ¼ì²âÊÇ·ñ±£´æ±àºÅCVE-2018-6789Îó²î£»£»£»£»£»£»£»
2. ¼ì²âEximÆäËüµÄÏà¹ØÎó²î£¬£¬£¬£¬°ü¹ÜEximЧÀÍÕý³£ÔËÐС£¡£¡£¡£¡£¡£
£¨½¨ÒéʹÓÃÌ쾵ųÈõɨÃèÓëÖÎÀíϵͳ£¬£¬£¬£¬Éý¼¶ÖÁ60700151Éý¼¶°ü£©
ÎÊÕïÈýºÅ£ºCisco¾Ü¾øÐ§À͹¥»÷
CiscoµÄ4786¶Ë¿Ú×ÜÄÜÎüÊÕµ½Òì³£Êý¾Ý£¬£¬£¬£¬ÓÐʱ¼äCisco»á¾Ü¾øÐ§ÀÍ£¬£¬£¬£¬ÓÐʱ¼ä»áÔÚÈÕÖ¾Öп´µ½Ö´ÐзÇͨÀýÏÂÁ£¿£¿£¿£¿
4786¶Ë¿ÚÊÇ˼¿Æ IOS ºÍ IOS-XE ϵͳ Smart Install ClientµÄЧÀͶ˿ڣ¬£¬£¬£¬¸Ã»¼ÕßÓ¦¸Ã»¼ÓбàºÅΪCVE-2018-0171µÄCiscoÏà¹ØÎó²î¡£¡£¡£¡£¡£¡£
˼¿Æ IOS ºÍ IOS-XE ϵͳ Smart Install Client ´úÂëÖб£´æÒ»´¦»º³åÇøÕ»Òç³öÎó²î£¨CVE-2018-0171£©¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÔ¶³ÌÏò TCP 4786 ¶Ë¿Ú·¢ËÍÒ»¸ö¶ñÒâÊý¾Ý°ü£¬£¬£¬£¬Ê¹ÓøÃÎó²î£¬£¬£¬£¬´¥·¢Ä¿µÄ×°±¸µÄÕ»Òç³öÎó²îÔì³É×°±¸¾Ü¾øÐ§ÀÍ£¨DoS£©»òÔÚÔì³ÉÔ¶³ÌÏÂÁîÖ´ÐУ¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔ¶³Ì¿ØÖÆÊܵ½Îó²îÓ°ÏìµÄÍøÂç×°±¸¡£¡£¡£¡£¡£¡£
1. ¼ì²âÊÇ·ñ±£´æ±àºÅCVE-018-0171µÄÎó²î£»£»£»£»£»£»£» 2. ¼ì²âCiscoÆäËüµÄÏà¹ØÎó²î£¬£¬£¬£¬°ü¹ÜCiscoЧÀÍÕý³£ÔËÐС£¡£¡£¡£¡£¡£
£¨½¨ÒéʹÓÃÌ쾵ųÈõɨÃèÓëÖÎÀíϵͳ£¬£¬£¬£¬Éý¼¶ÖÁ60700151Éý¼¶°ü£©
ÎÊÕïËĺţºWeblogic·´ÐòÁл¯í§ÒâÏÂÁîÖ´ÐÐ
Weblogic×î½ü×Ü»áÖ´ÐзÇÊÚȨÏÂÁ£¬£¬£¬ÊÇ·ñÓв½·¥È·¶¨È·ÈÏÊÇ·ñ±£´æ·´ÐòÁл¯Îó²î£¿£¿£¿£¿£¿
ƾ֤ÐÎò£¬£¬£¬£¬ÓпÉÄܱ£´æjava·´ÐòÁл¯Îó²î£¬£¬£¬£¬½¨Òé¶Ôjava·´ÐòÁл¯Ïà¹ØÎó²î¾ÙÐÐÑéÖ¤£»£»£»£»£»£»£»
Java·´ÐòÁл¯ÊÇÖ¸°Ñ×Ö½ÚÐòÁлָ´ÎªJava¹¤¾ßµÄÀú³Ì£¬£¬£¬£¬ObjectInputStreamÀàµÄreadObject()ÒªÁìÓÃÓÚ·´ÐòÁл¯¡£¡£¡£¡£¡£¡£Ì»Â¶»ò¼ä½Ó̻¶·´ÐòÁл¯API£¬£¬£¬£¬µ¼ÖÂÓû§¿ÉÒÔ²Ù×÷´«ÈëÊý¾Ý£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÈ«ÐĽṹ·´ÐòÁл¯¹¤¾ß²¢Ö´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£
1.ÑéÖ¤java·´ÐòÁл¯Ïà¹ØÎó²î,±àºÅΪCVE-2016-0638¡¢CVE-2016-3510¡¢CVE-2017-10271¡¢CVE-2017-3248¡¢CVE-2015-4852¡¢CVE-2015-4852£»£»£»£»£»£»£»
2.¼ì²âweblogicÆäËüµÄÏà¹ØÎó²î£¬£¬£¬£¬°ü¹ÜweblogicЧÀÍÕý³£ÔËÐС£¡£¡£¡£¡£¡£
£¨½¨ÒéʹÓÃÌ쾵ųÈõɨÃèÓëÖÎÀíϵͳ£¬£¬£¬£¬Éý¼¶ÖÁ60700151Éý¼¶°ü£¬£¬£¬£¬Ê¹ÓÃÎó²îÑéÖ¤¹¦Ð§£©
¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍøÂ©É¨²úÆ·ÖÐÐÄ
ÍòÀû¹ú¼Ê¹ÙÍøÂ©É¨²úÆ·ÖÐÐľ۽¹ÓÚÍøÂç×ʲúųÈõÐÔÇå¾²ÆÀ¹À¡¢¼ì²âºÍÐÞ¸´£»£»£»£»£»£»£»Ñз¢ÁËÕë¶ÔÇ徲Σº¦¸÷¸ö½×¶ÎµÄÇå¾²²úÆ·¼°Ð§ÀÍ£»£»£»£»£»£»£»²úÆ·°üÀ¨£ºÌ쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ¡¢Ìì¾µwebÓ¦Óüì²âϵͳ¡¢Ì쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ-¹¤¿Ø×¨Óð桢¹¤¿ØÎÞËðÆÀ¹Àϵͳ¡¢Îó²îÐÞ¸´ÖÎÀíϵͳ¡¢Ìì¾µÎó²îÖÎÀíÆ½Ì¨¡¢¹¤¿ØÎó²îÍÚ¾òϵͳ¡£¡£¡£¡£¡£¡£
ÍòÀû¹ú¼Ê¹ÙÍøÅ³ÈõÐÔÆÀ¹ÀºÍÖÎÀí²úÆ·×å


¾©¹«Íø°²±¸11010802024551ºÅ