¡¾Ç徲ͨ¸æ¡¿Exim Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-28020£©Í¨¸æ
2021-07-27
Ò». Îó²î¸ÅÊö
5Ô·ÝQualys¹ûÕæÅû¶ÁËEximÓʼþ·þÎñÆ÷ÖеÄ21¸öÇå¾²Îó²î£¬ÕâЩÎó²îÓ°ÏìEximÔÚ2004ÄêÖ®ºó¿ª·¢µÄËùÓа汾£¬ÇÒ´ó´ó¶¼¿ÉÒÔÔÚĬÈÏÉèÖÃÖб»Ê¹Óã¬AG¹«Ë¾¿Æ¼¼¿ËÈÕ¼à²âµ½Óв¿·ÖÎó²îϸ½ÚÓëPoC±»¹ûÕæ£¬ÆäÖÐ×îÑÏÖØµÄΪEximÕûÊýÒç³öÎó²î£¨CVE-2020-28020£©£¬¸ÃÎó²îÔ´ÓÚreceive_msgº¯Êý£¬¹¥»÷Õß¿ÉÒÔͨ¹ý”\n”ÈÆ¹ýExim¶ÔÓʼþÍ·¾ÞϸµÄÏÞÖÆ£¬´Ó¶øÔì³ÉÕûÊýÒç³ö£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓôËÎó²îÔì³É¾Ü¾ø·þÎñ»òÔ¶³Ì´úÂëÖ´ÐС£ÏÖÔÚÎó²îÏêÇéÓë¿´·¨ÑéÖ¤³ÌÐòÒѹûÕæ£¬ÇëÏà¹ØÓû§ÊµÊ±½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
EximÊÇÒ»¿îÓʼþ´«ÊäÊðÀíÈí¼þ£¨MTA£©£¬¿ÉʵÏÖÓʼþµÄ·ÓÉ¡¢×ª·¢ºÍͶµÝ¡£Ö÷Òª±»¹¹½¨ÔÚÀàUnix²Ù×÷ϵͳÉÏ·¢ËͺÍÎüÊÕµç×ÓÓʼþ£¬°üÀ¨Solaris¡¢AIX¡¢LinuxµÈ£»Exim¿ÉÒÔ´¦Öóͷ£´ó×Ú»¥ÁªÍøÁ÷Á¿£¬ÓÉÓÚÆä¾ßÓÐÉèÖÃÎÞаµÄÌØµã£¬Í¨³£»áÓëÆäËûÓ¦ÓÃÈí¼þ´îÅäʹÓá£
²Î¿¼Á´½Ó£º
https://www.exim.org/static/doc/security/CVE-2020-qualys/CVE-2020-28020-HSIZE.txt
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
Exim < 4.94.2
²»ÊÜÓ°Ïì°æ±¾
Exim = 4.94.2
Èý. Îó²î·À»¤
3.1 ¹Ù·½Éý¼¶
ÏÖÔÚExim¹Ù·½ÒÑÔÚ4.94.2°æ±¾ÖÐÐÞ¸´ÁËÒÔÉÏÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º
https://ftp.exim.org/pub/exim/exim4/
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







