OpenSSHÐÅϢй¶Îó²î£¨CVE-2018-15473¡¢CVE-2018-15919£© ÍþвԤ¾¯Í¨¸æ
2018-10-15
×ÛÊö
ǰ¶Îʱ¼ä£¬OpenSSH±»ÆØ³ö±£´æÁ½¸öÐÅϢй¶Îó²î£¨CVE-2018-15473ºÍCVE-2018-15919£©¡£ÆäÖÐCVE-2018-15919Ó°Ïì×Ô2011Äê9ÔÂ6ÈÕÐû²¼µÄ5.9°æ±¾µ½½ñÄê8ÔÂ24ÈÕÐû²¼µÄ×îа汾7.8¡£CVE-2018-15473ÔòÓ°Ïì×Ô1999ÄêÒÔÀ´ÖÁ½ñÄê7.7°æ±¾ÖÐËùÓа汾£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓÃÎó²îÍÆ²âÔÚOpenSSH·þÎñÆ÷ÉÏ×¢²áµÄÓû§Ãû¡£
ƾ֤·¢Ã÷CVE-2018-15919µÄÑо¿Ö°Ô±µÄ˵·¨£¬OpenSSHµÄ¿ªÔ´¿ª·¢Ö°Ô±ÌåÏÖ²¢Î´½«´ËÐÅϢй¶ÊÓΪÑÏÖØÍþв£¬ÓÉÓÚÓû§Ãû±»ÒÔΪÊÇÓû§Éí·ÝµÄ·ÇÉñÃØ²¿·Ö£¬Òò´ËÔÚ¶Ìʱ¼äÄÚ²¢Î´ÓÐÐÞ¸´ÍýÏë¡£
²Î¿¼Á´½Ó£º
https://securityaffairs.co/wordpress/75748/hacking/cve-2018-15919-username-enumeration-openssh.html
Îó²îÐÎò
CVE-2018-15473
¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄϵͳ·¢ËÍÉí·ÝÑéÖ¤ÇëÇóÊý¾Ý°üÀ´Ê¹ÓôËÎó²î£¬ÀֳɵÄʹÓÿÉÄÜÔÊÐí¹¥»÷Õß»á¼ûÃô¸ÐÐÅÏ¢£¬ÀýÈçϵͳÉϵÄÓÐÓÃÓû§Ãû¡£Îó²îÔµ¹ÊÔÓÉÊÇ
OpenSSH·þÎñÆ÷ÔÚ¶Ô°üÀ¨ÁËÇëÇóµÄÊý¾Ý°üÍêÈ«ÆÊÎö֮ǰ£¬²»»áÑÓ³Ù´¦Öóͷ£Ò»¸öÑéÖ¤ÎÞЧµÄÓû§¡£¸ÃÎó²îºÍauth2-gss.cauth2-hostbased.cauth2-pubkey.cÓйء£
CVSS3 Base Score£º5.3
CVSS3 Base Metrics£º
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C
ÊÜÓ°ÏìµÄ°æ±¾
l OpenSSH <= 7.7
²»ÊÜÓ°ÏìµÄ°æ±¾
l openssh-7.8p1-1.fc28 openssh-7.6p1-6.fc27
½â¾ö¼Æ»®
½¨ÒéÓû§Éý¼¶µ½²»ÊÜÓ°Ïì°æ±¾¡£ÇÒOpenBSDÏîÄ¿ÒÑÔÚÒÔÏÂÁ´½ÓÐû²¼ÁËÔ´´úÂëÐÞ¸´£º
https://github.com/openbsd/src/commit/779974d35b4859c07bc3cb8a12c74b43b0a7d1e0
²Î¿¼Á´½Ó£º
https://tools.cisco.com/security/center/viewAlert.x?alertId=58762
CVE-2018-15919
¸ÃÎó²î±£´æÓÚOpenSSHµÄauth-gss2.cÔ´´úÂëÎļþÖУ¬ÊÇÓÉÓÚÔÚÊÜÓ°ÏìµÄϵͳÉÏʹÓÃGuide Star Server II£¨GSS2£©×é¼þʱ¶ÔÇëÇóÊý¾Ý°üÑéÖ¤²»³ä·ÖÔì³É¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄϵͳ·¢ËÍÉí·ÝÑéÖ¤ÇëÇóÊý¾Ý°üÀ´Ê¹ÓôËÎó²î¡£ÀÖ³ÉʹÓÃÎó²î¿ÉÄÜÔÊÐí¹¥»÷Õß»á¼ûÃô¸ÐÐÅÏ¢£¬ÀýÈôÓÐÓõÄÓû§Ãû¡£
CVSS3 Base Score£º5.3
CVSS3 Base Metrics£ºCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:U/RC:R
ÊÜÓ°ÏìµÄ°æ±¾
l OpenSSH <= 7.8
l OpenSSH >= 5.9
½â¾ö¼Æ»®
OpenBSDÏîÄ¿ÉÐδÐû²¼Èí¼þ¸üС£
²Î¿¼Á´½Ó£º
https://tools.cisco.com/security/center/viewAlert.x?alertId=58800
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚÂÌÃ˿Ƽ¼
±±¾©ÉñÖÝAG¹«Ë¾ÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖÝAG¹«Ë¾ÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊÐÉúÒ⣬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ





