Glibc gethostbyname()¶Ñ»º³åÇøÒç³öÎó²î (Alert2015-01)
2015-01-28
ÐÎò£º
CVE ID£ºCVE-2015-0235ÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
====================
Glibc 2.2 - 2.17
δÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
======================
Glibc 2.18
×ÛÊö£º
======
Glibc 2.18֮ǰµÄ°æ±¾ÖеÄ__nss_hostname_digits_dots()º¯Êý±£´æÒ»¸ö¶Ñ»º³åÇøÎó²î£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂë¡£
ÓÉÓÚGlibcÊÇ»ù´¡µÄCÔËÐп⣬´ó×ÚÓ¦Óö¼¿ÉÄÜÊÜ´ËÎÊÌâÓ°Ï죬½¨Ò龡¿ìÉý¼¶¡£
ÆÊÎö£º
======
glibcÊÇGNUÐû²¼µÄlibc¿â£¬¼´cÔËÐп⣬ÏÕЩÆäËüÈκÎÔËÐпⶼ»áÒÀÀµÓÚglibc¡£
glibc 2.18֮ǰ°æ±¾ÖУ¬__nss_hostname_digits_dots()º¯Êý±£´æ¶Ñ»º³åÇøÒç³öÎó²î£¬gethostbyname()¼°gethostbyname2()ÕâÁ½¸öglibcº¯ÊýŲÓÃʱ»áÓõ½¸Ãº¯Êý¡£ÈôÊÇÔ¶³Ì¹¥»÷Õß¿ÉÒÔŲÓÃÕâЩº¯ÊýÖеÄí§ÒâÒ»¸ö£¬¼´¿ÉʹÓôËÎó²îÒÔÄ¿½ñÓû§È¨ÏÞÖ´ÐÐí§Òâ´úÂë¡£
ËäÈ»2013Äê5ÔÂ21ÈÕGNU¹Ù·½ÒѾÐÞ¸´ÁË´ËÎó²î(½éÓÚglibc-2.17¼°glibc-2.18Ö®¼äµÄ°æ±¾)£¬µ«Æäʱ²¢Î´µ±³ÉÎó²î´¦Öóͷ££¬Òò´ËÐí¶àLinux¿¯Ðа沢δ¾ÙÐÐÉý¼¶¡£ÏÖÔÚDebian 7 (wheezy), Red Hat Enterprise Linux 6 & 7, CentOS 6 & 7, Ubuntu 12.04µÈ´ó´ó¶¼µÄLinux¿¯Ðа涼ÊÜ´ËÎÊÌâÓ°Ïì¡£
´ËÎó²î´¥·¢ÑÏÖØÒÀÀµÓ¦ÓóÌÐòŲÓÃgethostbyname()µÄ·½·¨£¬ÐèÒªÖª×ã¶à¸öÌõ¼þ²Å»ª´¥·¢Îó²î¡£ÏÖÔÚ¿´¾ø´ó´ó¶¼µÄÍâµØSUID³ÌÐòºÍ·þÎñ³ÌÐòÎÞ·¨±»Ê¹Óá£
ÏÖÔÚÒÑÖªÊÜÓ°ÏìµÄÓ¦ÓóÌÐòΪexim4Óʼþ·þÎñ³ÌÐò£¬ÈôÊÇÉèÖÃÁ˶ÔHELOºÍEHELOÏÂÁî¾ÙÐÐÌØÊâÇå¾²¼ì²é£¨·ÇĬÈÏÉèÖã©£¬Ôò¿ÉÒÔÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£
²»É¨³ýÆäËûÓ¦ÓÃÊÜ´ËÎÊÌâÓ°Ïì¡£
½â¾öÒªÁ죺
ûÓкõÄÔÝʱ½â¾öÒªÁ죬½¨Ò龡¿ìÉý¼¶»òƾ֤³§É̲¹¶¡¡£³§ÉÌ״̬£º
==========
GNUºÍ¸÷´óLinux¿¯Ðа泧É̾ùÒÑÐÞ¸´´ËÎó²î£¬Ç뾡¿ì¾ÙÐÐÉý¼¶£º
RedHat: https://rhn.redhat.com/errata/RHSA-2015-0090.html
Ubuntu: https://launchpad.net/ubuntu/+source/eglibc
Debian: https://security-tracker.debian.org/tracker/CVE-2015-0235
GNU C Library: http://www.gnu.org/software/libc/
¸½¼ÓÐÅÏ¢£º
==========
1. https://www.qualys.com/research/security-advisories/GHOST-CVE-2015-0235.txt
2. http://www.nsfocus.net/index.php?act=alert&do=view&aid=153
3. https://rhn.redhat.com/errata/RHSA-2015-0090.html
4. https://security-tracker.debian.org/tracker/CVE-2015-0235

AG¹«Ë¾ÔÆ





