Exim Mail Server 5Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2021-05-070x00 Îó²î¸ÅÊö
EximÊÇÓɽ£ÇÅ´óѧ¿ª·¢µÄÐÂÎÅ´«ÊäÊðÀí£¨MTA£©£¬£¬£¬£¬£¬£¬£¬Ö÷Òª±»¹¹½¨ÔÚÀàUnix²Ù×÷ϵͳÉÏ·¢ËͺÍÎüÊÕµç×ÓÓʼþ¡£¡£¡£ºÃ±È£¬£¬£¬£¬£¬£¬£¬ËüÒÑԤװÔÚLinux¿¯Ðа棨ÈçDebian£©ÉÏ¡£¡£¡£Exim¿ÉÒÔ´¦Öóͷ£´ó×Ú»¥ÁªÍøÁ÷Á¿£¬£¬£¬£¬£¬£¬£¬ÆäʹÓúÜÊÇÆÕ±é¡£¡£¡£
2021Äê05ÔÂ04ÈÕ£¬£¬£¬£¬£¬£¬£¬Qualys¹ûÕæÅû¶ÁËEximÓʼþЧÀÍÆ÷ÖеÄ21¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý×éºÏʹÓÃÕâЩÎó²î¾ÙÐÐδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©£¬£¬£¬£¬£¬£¬£¬»ñµÃrootÓû§È¨ÏÞºÍÈä³æÊ½ºáÏòÒÆ¶¯¡£¡£¡£
0x01 Îó²îÏêÇé

MTAÊǹ¥»÷Õ߸ÐÐËȤµÄÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃÇͨ³£¿£¿£¿£¿ÉÒÔͨ¹ýInternet»á¼û£¬£¬£¬£¬£¬£¬£¬Ò»µ©±»Ê¹Ó㬣¬£¬£¬£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔÐÞ¸ÄÓʼþЧÀÍÆ÷Éϵĵç×ÓÓʼþÉèÖ㬣¬£¬£¬£¬£¬£¬²¢ÔÚÄ¿µÄÓʼþЧÀÍÆ÷ÉϽ¨ÉèÐÂÕÊ»§¡£¡£¡£È¥Ä꣬£¬£¬£¬£¬£¬£¬EximÖеÄÎó²îÔø³ÉΪAPTµÄÄ¿µÄ¡£¡£¡£Æ¾Ö¤ShodanµÄËÑË÷£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚԼĪÓÐ400Íǫ̀EximЧÀÍÆ÷Ö±½Ó̻¶ÔÚ»¥ÁªÍøÉÏ¡£¡£¡£
ÔÚ±¾´Î¹ûÕæµÄ21¸öÎó²îÖУ¬£¬£¬£¬£¬£¬£¬ÆäÖÐ10¸ö¿ÉÒÔ±»Ô¶³ÌʹÓᣡ£¡£ËäÈ»Qualys²¢Î´Ðû²¼ÈκÎÍêÕûµÄÎó²îPoc£¬£¬£¬£¬£¬£¬£¬µ«ÆäÖдó´ó¶¼¶¼¿ÉÒÔÔÚĬÈÏÉèÖûò³£¼ûÉèÖÃÖб»Ê¹Ó㬣¬£¬£¬£¬£¬£¬ÕâЩÎó²î»áÓ°ÏìEximÓÚ2004ÄêÖ®ºó¿ª·¢µÄËùÓа汾£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý×éºÏʹÓÃÕâЩÎó²î»ñµÃ³õʼ»á¼ûȨÏÞ¡¢Ôì³ÉÈä³æÊ¹Óá¢È¨ÏÞÌáÉý¡¢×°ÖóÌÐò¡¢ÐÞ¸ÄÊý¾Ý²¢½¨ÉèÐÂÕË»§¡£¡£¡£
21 Nails EximÖУ¬£¬£¬£¬£¬£¬£¬10¸ö¿ÉÔ¶³ÌʹÓõÄÎó²îΪ£º
CVE-2020-28017£ºreceive_add_recipient£¨£©ÖеÄÕûÊýÒç³ö
CVE-2020-28020£ºreceive_msg£¨£©ÖеÄÕûÊýÒç³ö
CVE-2020-28023£ºÔÚsmtp_setup_msg£¨£©ÖжÁȡԽ½ç
CVE-2020-28021£ºÔÚspoolÍ·ÎļþÖÐ×¢ÈëÐÂÐÐ
CVE-2020-28022£ºextract_option£¨£©ÖжÑÔ½½ç¶ÁÈ¡ºÍдÈë
CVE-2020-28026£ºspool_read_header£¨£©ÖеÄÐнضϺÍ×¢Èë
CVE-2020-28019£ºBDAT¹ýʧºóÎÞ·¨ÖØÖú¯ÊýÖ¸Õë
CVE-2020-28024£ºsmtp_ungetc£¨£©ÖеĶѻº³åÇøÏÂÒç
CVE-2020-28018£ºÔÚtls-openssl.cÖÐUse-after-free
CVE-2020-28025£ºÔÚpdkim_finish_bodyhash£¨£©ÖжÑÔ½½ç¶ÁÈ¡
21 Nails EximÖУ¬£¬£¬£¬£¬£¬£¬11¸öÍâµØÊ¹ÓõÄÎó²îΪ£º
CVE-2020-28007£ºEximÈÕ־Ŀ¼ÖеÄÁ´½Ó¹¥»÷
CVE-2020-28008£ºEximµÄspoolĿ¼ÖеÄÖÖÖÖ¹¥»÷
CVE-2020-28014£ºí§ÒâÎļþ½¨ÉèºÍ¿ÚÁî¹¥»÷
CVE-2021-27216£ºÉ¾³ýí§ÒâÎļþ
CVE-2020-28011£ºqueue_run£¨£©ÖеĶѻº³åÇøÒç³ö
CVE-2020-28010£ºmain()ÖеĶÑÔ½½çд²Ù×÷
CVE-2020-28013£ºparse_fix_phrase£¨£©ÖеĶѻº³åÇøÒç³ö
CVE-2020-28016£ºparse_fix_phrase()ÖеĶÑÔ½½çдÈë
CVE-2020-28015£ºÔÚspoolÍ·ÎļþÖÐ×¢ÈëÐÂÐÐ
CVE-2020-28012£ºÌØÈ¨¹ÜµÀȱÉÙÖ´ÐÐʱ¹Ø±ÕµÄ±ê¼Ç
CVE-2020-28009£ºget_stdinput£¨£©ÖеÄÕûÊýÒç³ö
ÔÚÕâЩÎó²îÖУ¬£¬£¬£¬£¬£¬£¬CVE-2020-28018ÊÇ×îÑÏÖØµÄÎó²îÖ®Ò»£¬£¬£¬£¬£¬£¬£¬ÈôÊÇEximЧÀÍÆ÷ÊÇÓÃOpenSSL¹¹½¨µÄ£»£»£»£»£»£»ÈôÊÇSTARTTLSºÍPIPELINING£¨Ä¬ÈÏ£©±»ÆôÓ㻣»£»£»£»£»ÈôÊÇX_PIPE_CONNECT±»½ûÓã¨Exim 4.94֮ǰµÄĬÈÏÉèÖã©£¬£¬£¬£¬£¬£¬£¬Ëü¾Í¿ÉÒÔ±»Ê¹Óᣡ£¡£ÁíÒ»¸öÖµµÃ×¢ÖØµÄÎó²îÊÇCVE-2020-28020£¬£¬£¬£¬£¬£¬£¬ËüÊÇÒ»¸öÕûÊýÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃËüÒÔ ¡°exim ¡±Óû§Éí·ÝÖ´ÐÐí§ÒâÏÂÁî²¢¿ú̽Êý¾Ý£¬£¬£¬£¬£¬£¬£¬Ëü±£´æÓÚreceive_msg£¨£©º¯ÊýÖУ¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¹¦Ð§Ç¿Ê¢£¬£¬£¬£¬£¬£¬£¬µ«Ò²ÊÇ21¸öÎó²îÖÐ×îÄÑʹÓõġ£¡£¡£¶øµ±CVE-2020-28021ÓëÆäËüÎó²î×éºÏʹÓÃʱ£¬£¬£¬£¬£¬£¬£¬¾ÓÉÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÔÚspoolÍ·ÎļþÖÐ×¢ÈëÐÂÐУ¬£¬£¬£¬£¬£¬£¬²¢ÒÔrootÉí·ÝÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£
Ó°Ïì¹æÄ£
2004ÄêÖ®ºó¿ª·¢µÄËùÓа汾
0x02 ´¦Öóͷ£½¨Òé
QualysµÄÑо¿Ö°Ô±ºÍExim¹Ù·½¾ùÐû²¼ÁËÏà¹Ø²¹¶¡¡£¡£¡£ÖÁÓÚÖÖÖÖLinux¿¯Ðа棬£¬£¬£¬£¬£¬£¬×îÆÕ±éʹÓõģ¨CentOS¡¢RHELºÍSuSE£©£¬£¬£¬£¬£¬£¬£¬ÒÑ¾ÍÆ³öÁËÐÞ¸´³ÌÐò¡£¡£¡£DebianÔÚ ¡°oldstable¡±£¨´úºÅStretch£©¡¢¡°stable¡±£¨Buster£©»ò ¡°Still-in-development¡±£¨Sid£©°æ±¾Öв»±£´æÕâЩÎó²î£¬£¬£¬£¬£¬£¬£¬¶ø¡°unstable¡±£¨Bullseye£©°æ±¾Ôò±£´æÎó²î£¬£¬£¬£¬£¬£¬£¬ÇÒÏÖÔÚÉÐδÐÞ¸´¡£¡£¡£
Ïà¹ØÎó²îµÄÐÞ¸´ÒªÁì»ò²¹¶¡½¨Òé²Î¿¼QualysÐû²¼µÄÇå¾²×Éѯ£º
https://www.qualys.com/2021/05/04/21nails/21nails.txt
0x03 ²Î¿¼Á´½Ó
https://www.qualys.com/2021/05/04/21nails/21nails.txt
https://threatpost.com/exim-security-linux-mail-server-takeovers/165894/
http://www.exim.org/
0x04 ʱ¼äÏß
2021-05-04 Qualys¹ûÕæÅû¶Îó²î
2021-05-07 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ