Apache HTTPЧÀÍ×é¼þÌáȨÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-04-03

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-0211 £¬£¬£¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.2 £¬£¬£¬£¬£¬£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Apache HTTP Server 2.4.38, 2.4.37, 2.4.35, 2.4.34, 2.4.33, 2.4.30, 2.4.29, 2.4.28, 2.4.27, 2.4.26, 2.4.25, 2.4.23, 2.4.20, 2.4.18, 2.4.17


Îó²î¸ÅÊö


Apache¹Ù·½Ðû²¼2.4.39°æ±¾µÄ¸üР£¬£¬£¬£¬£¬£¬ £¬£¬ÆäÖÐÐÞ¸´ÁËÒ»¸ö±àºÅΪCVE-2019-0211µÄÌáȨÎó²î £¬£¬£¬£¬£¬£¬ £¬£¬¾ÝÆÊÎö £¬£¬£¬£¬£¬£¬ £¬£¬¸ÃÎó²îÓ°ÏìÑÏÖØ £¬£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õßͨ¹ýÉÏ´«CGI¾ç±¾¿ÉÖ±½ÓÔì³ÉÄ¿µÄϵͳµÄÌáȨ¹¥»÷ £¬£¬£¬£¬£¬£¬ £¬£¬Ó°Ïì*nixƽ̨ϵÄApache 2.4.17µ½2.4.38°æ±¾ £¬£¬£¬£¬£¬£¬ £¬£¬½¨Ò龡¿ì¾ÙÐÐÆÀ¹ÀÐÞ¸´¡£ ¡£¡£¡£


*nixƽ̨ £¬£¬£¬£¬£¬£¬ £¬£¬ÔÚApache HTTP×é¼þ2.4.17µ½2.4.38°æ±¾ÖÐ £¬£¬£¬£¬£¬£¬ £¬£¬²»¹ÜÊÇʹÓÃMPM eventÄ£×Ó¡¢Workder¡¢ÕÕ¾Épreforkģʽ £¬£¬£¬£¬£¬£¬ £¬£¬ÔËÐÐÓÚµÍȨÏÞµÄ×ÓÀú³Ì»òÏ̶߳¼¿ÉÒÔͨ¹ýʹÓüƷְ壨manipulating the scoreboard£©µÄ·½·¨À´ÒÔ¸¸Àú³ÌµÄȨÏÞ£¨Í¨³£ÊÇrootȨÏÞ£©Ö´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£


¹¥»÷³¡¾°ÖÐ £¬£¬£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÐèҪͨ¹ýÉÏ´«¿ÉÖ´Ðо籾µÄ¹¥»÷·½·¨À´¾ÙÐй¥»÷¡£ ¡£¡£¡£ÈôÊÇÄ¿µÄϵͳÊǽÓÄÉÖ÷»ú¹²ÏíµÄ³¡¾° £¬£¬£¬£¬£¬£¬ £¬£¬¸ÃÎó²î¿ÉÄÜ¿ÉÖ±½Ó±»Ê¹Óᣠ¡£¡£¡£


ÐÞ¸´½¨Òé


1. *nixƽ̨¾¡¿ìͨ¹ý¸÷×ԵĸüÐÂÇþµÀ¾ÙÐиüУ¨ÏÖÔÚ¸÷¼ÒLinuxÕýÔÚ½ôÆÈÆÀ¹À¸üÐÂÖУ©

2. ×ÔÐбàÒëµÄHTTPÇëͨ¹ýÔ´Âë¸üÐµķ½·¨¾¡¿ìÐÞ¸´


²Î¿¼Á´½Ó


https://access.redhat.com/security/cve/cve-2019-0211
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2019-0211