¡¾Íþвͨ¸æ¡¿Nginx DNSÆÊÎö³ÌÐòÎó²î£¨CVE-2021-23017£©Í¨¸æ
2021-05-26
Ò». Îó²î¸ÅÊö
5ÔÂ26ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½NginxÐû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁËnginxÆÊÎöÆ÷ÖеÄÒ»¸öDNSÆÊÎö³ÌÐòÎó²î£¨CVE-2021-23017£©£¬ÓÉÓÚngx_resolver_copy()´¦Öóͷ£DNSÏìӦʱ±£´æ¹ýʧ £¬µ±nginxÉèÖÃÎļþÖÐʹÓÃÁË“ resolver”Ö¸Áîʱ£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Î±ÔìÀ´×ÔDNS·þÎñÆ÷µÄUDPÊý¾Ý°ü£¬½á¹¹ÌØÖƵÄDNSÏìÓ¦µ¼ÖÂ1×Ö½ÚÄÚ´æÁýÕÖ£¬´Ó¶øÔì³É¾Ü¾ø·þÎñ»òí§Òâ´úÂëÖ´ÐС£ÏÖÔÚÒÑÓÐϸ½ÚÐÅÏ¢Åû¶£¬ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
²Î¿¼Á´½Ó£º
http://mailman.nginx.org/pipermail/nginx-announce/2021/000300.html
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
l NGINX 0.6.18 - 1.20.0
²»ÊÜÓ°Ïì°æ±¾
l NGINX Open Source 1.20.1 (stable)
l NGINX Open Source 1.21.0 (mainline)
l NGINX Plus R23 P1
l NGINX Plus R24 P1
Èý. Îó²î·À»¤
3.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÔÚ×îа汾ÖÐÐÞ¸´Á˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º
http://nginx.org/en/download.html
3.2 ÆäËû·À»¤²½·¥
ÈôÏà¹ØÓû§ÔÝʱÎÞ·¨Éý¼¶nginxÖÁа汾£¬Ò²¿É×°Öò¹¶¡¾ÙÐÐÐÞ¸´£º
http://nginx.org/download/patch.2021.resolver.txt
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







