¶à¸öApache httpdÇå¾²Îó²î Çå¾²Íþвͨ¸æ
2017-06-21
¿ËÈÕ£¬Apache¹Ù·½Ðû²¼ÁËhttpdµÄа汾ÐÞ¸´Á˶à¸öÇå¾²Îó²î£¬Éæ¼°CVE-2017-3167£¬CVE-2017-3169£¬CVE-2017-7659£¬CVE-2017-7668£¬CVE-2017-7679£¬¿ÉÒÔÔì³ÉÉí·ÝÑéÖ¤±»ÈƹýÒÔ¼°¾Ü¾ø·þÎñ¹¥»÷µÈ¡£´ó²¿·ÖApache httpd 2.2.xÒÔ¼°2.4.x°æ±¾¾ùÊÜÓ°Ïì¡£Ïà¹ØÎó²îÐÅÏ¢ÈçÏ£º
|
CVE񅧏 |
Îó²îÐÎò |
|
CVE-2017-3167 |
µÚÈý·½Ä£¿éÔÚÑéÖ¤½×¶ÎÒÔÍâŲÓÃap_get_basic_auth_pw()ʱÓпÉÄܵ¼ÖÂÑéÖ¤ÒªÇó±»Èƹý |
|
CVE-2017-3169 |
µ±µÚÈý·½Ä£¿éÔÚŲÓÃap_hook_process_connection()·¢ËÍHTTPÇëÇó¸øHTTPS¶Ë¿Úʱ£¬mod_ssl¿ÉÄÜ»á¼ä½ÓÒýÓÿÕÖ¸Õë |
|
CVE-2017-7659 |
ÔÚ´¦Öóͷ£¶ñÒâ½á¹¹µÄHTTP/2ÇëÇóʱ£¬mod_http2¿ÉÄÜ»á¼ä½ÓÒýÓÿÕÖ¸Õ룬ʹ·þÎñÆ÷Àú³ÌÍß½â |
|
CVE-2017-7668 |
HTTPÑÏ¿áÆÊÎö¸Ä¶¯Öб£´æÒ»¸öÁîÅÆÁбíÆÊÎöµÄBUG£¬ap_find_token()¿ÉÒÔËÑË÷ÊäÈë×Ö·û´®Ö®ÍâµÄÄÚÈÝ¡£Í¨¹ý½á¹¹Ò»¸ö¶ñÒâµÄÇëÇóÍ·£¬¹¥»÷Õß¿ÉÒÔÔì³É¶Î¹ýʧ»òÕßÇ¿ÐÐÈÃap_find_token()·µ»ØÒ»¸ö¹ýʧµÄÖµ |
|
CVE-2017-7679 |
µ±¹¥»÷Õß·¢ËÍÒ»¸ö¶ñÒâµÄContent-TypeÏìӦͷʱ£¬mod_mime»áÔ½½ç¶ÁÈ¡»º³åÇøÄÚÈÝ¡£ |
²Î¿¼Á´½Ó£º
https://httpd.apache.org/security/vulnerabilities_24.html
https://httpd.apache.org/security/vulnerabilities_22.html
ÊÜÓ°ÏìµÄ°æ±¾
Apache httpd 2.2.x < 2.2.33-dev
Apache httpd 2.4.x < 2.4.26
¸÷Îó²îÓ°ÏìµÄ°æ±¾ÏêϸÐÅÏ¢¿É²Î¿¼ÎÄÄ©¸½Â¼¡£
²»ÊÜÓ°ÏìµÄ°æ±¾
Apache httpd 2.4.26
¹æ±Ü¼Æ»®
Apache¹Ù·½ÒѾÕë¶Ô2.2.xÒÔ¼°2.4.xÐû²¼ÁËÏìÓ¦µÄ2.2.33-devÒÔ¼°2.4.26а汾ÐÞ¸´ÁËÉÏÊö¸÷Îó²î£¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±ÏÂÔØ¸üÐÂÖÁ×îаæÔÀ´·À»¤Îó²î¡£Çë²Î¿¼ÈçÏÂÅþÁ¬£º
2.2.x°æ±¾£ºhttps://httpd.apache.org/security/vulnerabilities_22.html
2.4.x°æ±¾£ºhttps://httpd.apache.org/security/vulnerabilities_24.html
¸½Â¼
¸÷Îó²îÓ°Ïì°æ±¾µÄÏêϸÐÅÏ¢ÈçÏ£º
CVE-2017-3167
2.4.25 2.4.23 2.4.20 2.4.18 2.4.17 2.4.16 2.4.12 2.4.10 2.4.9 2.4.7 2.4.6 2.4.4 2.4.3 2.4.2 2.4.1 2.2.32 2.2.31 2.2.29 2.2.27 2.2.26 2.2.25 2.2.24 2.2.23 2.2.22 2.2.21 2.2.20 2.2.19 2.2.18 2.2.17 2.2.16 2.2.15 2.2.14 2.2.13 2.2.12 2.2.11 2.2.10 2.2.9 2.2.8 2.2.6 2.2.5 2.2.4 2.2.3 2.2.2 2.2.0
CVE-2017-3169
2.4.25 2.4.23 2.4.20 2.4.18 2.4.17 2.4.16 2.4.12 2.4.10 2.4.9 2.4.7 2.4.6 2.4.4 2.4.3 2.4.2 2.4.1 2.2.32 2.2.31 2.2.29 2.2.27 2.2.26 2.2.25 2.2.24 2.2.23 2.2.22 2.2.21 2.2.20 2.2.19 2.2.18 2.2.17 2.2.16 2.2.15 2.2.14 2.2.13 2.2.12 2.2.11 2.2.10 2.2.9 2.2.8 2.2.6 2.2.5 2.2.4 2.2.3 2.2.2 2.2.0
CVE-2017-7659
2.4.25
CVE-2017-7668
2.4.25 2.2.32
CVE-2017-7679
2.4.25 2.4.23 2.4.20 2.4.18 2.4.17 2.4.16 2.4.12 2.4.10 2.4.9 2.4.7 2.4.6 2.4.4 2.4.3 2.4.2 2.4.1 2.2.32 2.2.31 2.2.29 2.2.27 2.2.26 2.2.25 2.2.24 2.2.23 2.2.22 2.2.21 2.2.20 2.2.19 2.2.18 2.2.17 2.2.16 2.2.15 2.2.14 2.2.13 2.2.12 2.2.11 2.2.10 2.2.9 2.2.8 2.2.6 2.2.5 2.2.4 2.2.3 2.2.2 2.2.0
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ





