AG¹«Ë¾

AG¹«Ë¾

AG¹«Ë¾¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

Glibc gethostbyname()¶Ñ»º³åÇøÒç³öÎó²î (Alert2015-01)

2015-01-28

Ðû²¼ÕߣºAG¹«Ë¾¿Æ¼¼

ÐÎò£º

CVE ID£ºCVE-2015-0235
ÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
====================
Glibc 2.2 - 2.17
δÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
======================
Glibc 2.18
×ÛÊö£º
======
Glibc 2.18֮ǰµÄ°æ±¾ÖеÄ__nss_hostname_digits_dots()º¯Êý±£´æÒ»¸ö¶Ñ»º³åÇøÎó²î£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂë¡£
ÓÉÓÚGlibcÊÇ»ù´¡µÄCÔËÐп⣬´ó×ÚÓ¦Óö¼¿ÉÄÜÊÜ´ËÎÊÌâÓ°Ï죬½¨Ò龡¿ìÉý¼¶¡£
ÆÊÎö£º
======
glibcÊÇGNUÐû²¼µÄlibc¿â£¬¼´cÔËÐп⣬ÏÕЩÆäËüÈκÎÔËÐпⶼ»áÒÀÀµÓÚglibc¡£
glibc 2.18֮ǰ°æ±¾ÖУ¬__nss_hostname_digits_dots()º¯Êý±£´æ¶Ñ»º³åÇøÒç³öÎó²î£¬gethostbyname()¼°gethostbyname2()ÕâÁ½¸öglibcº¯ÊýŲÓÃʱ»áÓõ½¸Ãº¯Êý¡£ÈôÊÇÔ¶³Ì¹¥»÷Õß¿ÉÒÔŲÓÃÕâЩº¯ÊýÖеÄí§ÒâÒ»¸ö£¬¼´¿ÉʹÓôËÎó²îÒÔÄ¿½ñÓû§È¨ÏÞÖ´ÐÐí§Òâ´úÂë¡£
ËäÈ»2013Äê5ÔÂ21ÈÕGNU¹Ù·½ÒѾ­ÐÞ¸´ÁË´ËÎó²î(½éÓÚglibc-2.17¼°glibc-2.18Ö®¼äµÄ°æ±¾)£¬µ«Æäʱ²¢Î´µ±³ÉÎó²î´¦Öóͷ££¬Òò´ËÐí¶àLinux¿¯Ðа沢δ¾ÙÐÐÉý¼¶¡£ÏÖÔÚDebian 7 (wheezy), Red Hat Enterprise Linux 6 & 7, CentOS 6 & 7, Ubuntu 12.04µÈ´ó´ó¶¼µÄLinux¿¯Ðа涼ÊÜ´ËÎÊÌâÓ°Ïì¡£
´ËÎó²î´¥·¢ÑÏÖØÒÀÀµÓ¦ÓóÌÐòŲÓÃgethostbyname()µÄ·½·¨£¬ÐèÒªÖª×ã¶à¸öÌõ¼þ²Å»ª´¥·¢Îó²î¡£ÏÖÔÚ¿´¾ø´ó´ó¶¼µÄÍâµØSUID³ÌÐòºÍ·þÎñ³ÌÐòÎÞ·¨±»Ê¹Óá£
ÏÖÔÚÒÑÖªÊÜÓ°ÏìµÄÓ¦ÓóÌÐòΪexim4Óʼþ·þÎñ³ÌÐò£¬ÈôÊÇÉèÖÃÁ˶ÔHELOºÍEHELOÏÂÁî¾ÙÐÐÌØÊâÇå¾²¼ì²é£¨·ÇĬÈÏÉèÖã©£¬Ôò¿ÉÒÔÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£
²»É¨³ýÆäËûÓ¦ÓÃÊÜ´ËÎÊÌâÓ°Ïì¡£

½â¾öÒªÁ죺

ûÓкõÄÔÝʱ½â¾öÒªÁ죬½¨Ò龡¿ìÉý¼¶»òƾ֤³§É̲¹¶¡¡£
³§ÉÌ״̬£º
==========
GNUºÍ¸÷´óLinux¿¯Ðа泧É̾ùÒÑÐÞ¸´´ËÎó²î£¬Ç뾡¿ì¾ÙÐÐÉý¼¶£º
RedHat: https://rhn.redhat.com/errata/RHSA-2015-0090.html
Ubuntu: https://launchpad.net/ubuntu/+source/eglibc
Debian: https://security-tracker.debian.org/tracker/CVE-2015-0235
GNU C Library: http://www.gnu.org/software/libc/
¸½¼ÓÐÅÏ¢£º
==========
1. https://www.qualys.com/research/security-advisories/GHOST-CVE-2015-0235.txt
2. http://www.nsfocus.net/index.php?act=alert&do=view&aid=153
3. https://rhn.redhat.com/errata/RHSA-2015-0090.html
4. https://security-tracker.debian.org/tracker/CVE-2015-0235


?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈëAG¹«Ë¾¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
  • Ìá½»µ½ÓÊÏä
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
AG¹«Ë¾¿Æ¼¼ÉçÇø
AG¹«Ë¾¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼