Zip SlipÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-06-06

Îó²î±àºÅ


CVE-2018-8008
CVE-2018-8009
CVE-2018-1261
CVE-2018-1263
CVE-2018-1002200
CVE-2018-1002201
CVE-2018-1002202
CVE-2018-1002203
CVE-2018-1002204
CVE-2018-1002205
CVE-2018-1002206
CVE-2018-1002207


Îó²î¼¶±ð


ÑÏÖØ  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


Zip SlipÎó²î ¡°í§ÒâÎļþÁýÕÖ¡±ºÍ¡°Ä¿Â¼±éÀú¡±ÎÊÌâµÄÁ¬Ïµ £¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö¹¥»÷Õß¿ÉÒÔ½«Îļþ½âѹËõµ½Õý³£½âѹËõ·¾¶Ö®Íâ²¢ÁýÕÖÃô¸ÐÎļþ £¬£¬£¬£¬£¬£¬£¬£¬ÈçÒªº¦OS¿â»òЧÀÍÆ÷ÉèÖÃÎļþ ¡£¡£¡£¡£¡£ËäȻʹÓü¸ÖÖ±à³ÌÓïÑÔ±àдµÄ¿âÒÑÖª»áÊܵ½Ó°Ïì £¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçJavaScript £¬£¬£¬£¬£¬£¬£¬£¬Python £¬£¬£¬£¬£¬£¬£¬£¬Ruby £¬£¬£¬£¬£¬£¬£¬£¬.NET £¬£¬£¬£¬£¬£¬£¬£¬GoºÍGroovy £¬£¬£¬£¬£¬£¬£¬£¬µ«Õâ¸öÎÊÌâÖ÷ÒªÓ°ÏìJavaÉú̬ϵͳ ¡£¡£¡£¡£¡£


Zip SlipÎó²îÊÇÔÚ±àÂëÆ÷¡¢²å¼þºÍ¿âʵÏÖ½âѹ¹éµµÎļþµÄÀú³ÌÖеÄÒ»¸öÎÊÌâ ¡£¡£¡£¡£¡£ Ðí¶à´ò°üÃûÌà £¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨tar £¬£¬£¬£¬£¬£¬£¬£¬jar £¬£¬£¬£¬£¬£¬£¬£¬war £¬£¬£¬£¬£¬£¬£¬£¬cpio £¬£¬£¬£¬£¬£¬£¬£¬apk £¬£¬£¬£¬£¬£¬£¬£¬rarºÍ7z¶¼»áÊܵ½Ó°Ïì £¬£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÕâ¸üÏñÊÇÂß¼­ÎÊÌâ £¬£¬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇÌØ¶¨µÄ±àÂë¹ýʧ ¡£¡£¡£¡£¡£


¶à¸ö´óÐ͹«Ë¾ £¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨Google¡¢Oracle¡¢IBM¡¢Apache¡¢ÑÇÂíÑ·µÈÔÚÄÚµÄÊýǧ¸öÏîÄ¿ÊÜÓ°Ï죨¼û£ºhttps://github.com/snyk/zip-slip-vulnerability£© ¡£¡£¡£¡£¡£ËäÈ» £¬£¬£¬£¬£¬£¬£¬£¬ÕâÖÖÀàÐ͵ÄÎó²îÔçÒѱ£´æ £¬£¬£¬£¬£¬£¬£¬£¬µ«×î½üËüÒѾ­ÔÚ¸ü¶àµÄÏîÄ¿ºÍ¿âÖÐÌåÏÖ³öÀ´ ¡£¡£¡£¡£¡£

 

ÊÜÓ°ÏìµÄ¿âºÍÏîÄ¿£º


ÊÜÓ°ÏìµÄ¿â£º

 

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

 

ÊÜÓ°ÏìµÄÏîÄ¿£º

 

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

 

Îó²îÐÎò


Zip SlipÊÇĿ¼±éÀúµÄÒ»ÖÖÐÎʽ £¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý´Ó´ò°üÎļþÖÐÌáÈ¡ÎļþÀ´Ê¹Óà ¡£¡£¡£¡£¡£ Ŀ¼±éÀúÎó²îµÄÌõ¼þÊǹ¥»÷Õß¿ÉÒÔ»á¼ûÎļþϵͳÖÐÓ¦¸ÃפÁôµÄÄ¿µÄÎļþ¼ÐÖ®ÍâµÄ²¿·ÖÎļþϵͳ ¡£¡£¡£¡£¡£ È»ºó £¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÁýÕÖ¿ÉÖ´ÐÐÎļþ²¢Ô¶³ÌŲÓÃËüÃÇ £¬£¬£¬£¬£¬£¬£¬£¬»òÕßÆÚ´ýϵͳ»òÓû§Å²ÓÃËüÃÇ £¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖÊܺ¦Õß»úеÉϵÄÔ¶³ÌÏÂÁîÖ´ÐÐ ¡£¡£¡£¡£¡£´ËÎó²î»¹¿ÉÄÜͨ¹ýÁýÕÖÉèÖÃÎļþ»òÆäËûÃô¸Ð×ÊÔ´¶øÔì³ÉË𺦠£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜ»áÔÚ¿Í»§¶Ë£¨Óû§£©»úеºÍЧÀÍÆ÷ÉÏÊܵ½¹¥»÷ ¡£¡£¡£¡£¡£


Ò²¾ÍÊÇ˵ £¬£¬£¬£¬£¬£¬£¬£¬Zip SlipÊÇ¡°í§ÒâÎļþÁýÕÖ¡±ºÍ¡°Ä¿Â¼±éÀú¡±ÎÊÌâµÄÁ¬Ïµ £¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö¹¥»÷Õß¿ÉÒÔ½«Îļþ½âѹËõµ½Õý³£½âѹËõ·¾¶Ö®Íâ²¢ÁýÕÖÃô¸ÐÎļþ £¬£¬£¬£¬£¬£¬£¬£¬ÈçÒªº¦OS¿â»òЧÀÍÆ÷ÉèÖÃÎļþ ¡£¡£¡£¡£¡£


Îó²îPOC£ºhttps://github.com/snyk/zip-slip-vulnerability/tree/master/archives


ʹÓôËÎó²îÐèÒªµÄÁ½¸ö²¿·ÖÊDz»Ö´ÐÐÑéÖ¤¼ì²éµÄ¶ñÒâ¹éµµºÍÌáÈ¡´úÂë ¡£¡£¡£¡£¡£ÈÃÎÒÃÇÒÀ´ÎÉó²éÕâÁ½²¿·Ö ¡£¡£¡£¡£¡£Ê×ÏÈ £¬£¬£¬£¬£¬£¬£¬£¬zipÎļþµÄÄÚÈÝÔÚÌáȡʱÐèÒªÓÐÒ»¸ö»ò¶à¸öÍÑÀëÄ¿µÄĿ¼µÄÎļþ ¡£¡£¡£¡£¡£ÔÚÏÂÃæµÄÀý×ÓÖÐ £¬£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇ¿ÉÒÔ¿´µ½Ò»¸özipÎļþµÄÄÚÈÝ ¡£¡£¡£¡£¡£ËüÓÐÁ½¸öÎļþ £¬£¬£¬£¬£¬£¬£¬£¬Ò»¸ögood.shÎļþ½«±»½âѹËõµ½Ä¿µÄĿ¼ÖÐ £¬£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öevil.shÎļþÕýÔÚʵÑé±éÀúĿ¼Ê÷ÒÔ·­¿ª¸ùĿ¼ £¬£¬£¬£¬£¬£¬£¬£¬È»ºó½«ÎļþÌí¼Óµ½tmpĿ¼ÖÐ ¡£¡£¡£¡£¡£µ±ÄúʵÑécd .. ÔÚ¸ùĿ¼ÖÐʱ £¬£¬£¬£¬£¬£¬£¬£¬ÈÔÈ»»á·¢Ã÷×Ô¼ºÎ»ÓÚ¸ùĿ¼ÖÐ £¬£¬£¬£¬£¬£¬£¬£¬Òò´Ë¶ñÒâ·¾¶¿ÉÄܰüÀ¨¶à¸ö¼¶±ðµÄĿ¼ ../ ÔÚʵÑé±éÀúÃô¸ÐÎļþ֮ǰ £¬£¬£¬£¬£¬£¬£¬£¬ÓиüºÃµÄʱ»úµÖ´ï¸ùĿ¼ ¡£¡£¡£¡£¡£

 

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

 

Õâ¸özipÎļþµÄÄÚÈݱØÐèÊÖ¹¤ÖÆ×÷ ¡£¡£¡£¡£¡£Ö»¹Üzip¹æ·¶ÔÊÐí £¬£¬£¬£¬£¬£¬£¬£¬µµ°¸½¨É蹤¾ßͨ³£²»ÔÊÐíÓû§Ê¹ÓÃÕâЩ·¾¶Ìí¼ÓÎļþ ¡£¡£¡£¡£¡£¿ÉÊÇ £¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÌØ¶¨µÄ¹¤¾ß £¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÕâЩ·¾¶½¨ÉèÎļþºÜÈÝÒ× ¡£¡£¡£¡£¡£


ÄúÐèҪʹÓôËÎó²îµÄµÚ¶þ¼þÊÂÊÇʹÓÃÄú×Ô¼ºµÄ´úÂë»ò¿âÀ´ÌáÈ¡¹éµµÎļþ ¡£¡£¡£¡£¡£½âѹËõ´úÂëºöÂÔ´æµµÖÐÎļþ·¾¶µÄÑé֤ʱ±£´æ´ËÎó²î ¡£¡£¡£¡£¡£ÏÂÃæÊÇÒ»¸öÒ×Êܹ¥»÷µÄ´úÂëÆ¬¶ÏµÄʾÀý£¨ÒÔJavaÏÔʾµÄʾÀý£© ¡£¡£¡£¡£¡£

 

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

 

½â¾ö²½·¥


ÒÑÐÞ¸´µÄ¿âºÍÏîÄ¿Á´½Ó¼û£ºhttps://github.com/snyk/zip-slip-vulnerability


²Î¿¼×ÊÁÏ


https://github.com/snyk/zip-slip-vulnerability


http://7xkk1o.com1.z0.glb.clouddn.com/technical-whitepaper.pdf#page=8&zoom=auto,-99,199


https://github.com/snyk/zip-slip-vulnerability/tree/master/archives