¡¾Íþвͨ¸æ¡¿¿ª·ÅÖÎÀí»ù´¡ÉèÊ©£¨OMI£©¶à¸ö¸ßΣÎó²îͨ¸æ
2021-09-17
Ò». Îó²î¸ÅÊö
9ÔÂ15ÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½Î¢ÈíÐû²¼9ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË86¸öÇå¾²ÎÊÌ⣬ÆäÖаüÀ¨Open Management InfrastructureÖеö¸ßΣÎó²î£¬Ä³Ð© Azure ²úÆ·£¨ÀýÈç Configuration Management£©£¬µ±¿ª·ÅÁËÕìÌý OMI µÄ HTTP/S ¶Ë¿Ú£¨Ä¬ÒÔΪ5986£©Ê±£¬ÊÜÏÂÁÐÎó²îÓ°Ïì¡£
OMIÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-38647£©£ºÎ´¾Éí·ÝÈÏÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýHTTPSÐÒé·¢ËÍÌØÖÆµÄÊý¾Ý°üµ½Ä¿µÄϵͳµÄOMI¶Ë¿Ú£¬¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐС£
OMIȨÏÞÌáÉýÎó²î£¨CVE-2021-38648/CVE-2021-38645/CVE-2021-38649£©£º¾ÓÉÉí·ÝÑéÖ¤µÄͨË×Óû§¿ÉʹÓôËÀàÎó²îÌáÉýÖÁϵͳrootȨÏÞ¡£
¿ª·ÅÖÎÀí»ù´¡ÉèÊ© (OMI) ÊÇÒ»¸ö¿ªÔ´ÏîÄ¿£¬Ö¼ÔÚ½øÒ»²½¿ª·¢ DMTF CIM/WBEM ±ê×¼µÄÉú²úÖÊÁ¿ÊµÑé¡£Ö§³Ö´ó´ó¶¼µÄUNIXºÍLinuxϵͳ¿¯Ðа棬ÊÊÓÃÓÚǶÈëʽϵͳºÍÆäËû»ù´¡ÉèÊ©×é¼þ¡£
²Î¿¼Á´½Ó£º
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38648
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38645
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38649
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
Azure Open Management Infrastructure < omi-1.6.8-1
²»ÊÜÓ°Ïì°æ±¾
Azure Open Management Infrastructure = omi-1.6.8-1
Èý. Îó²î¼ì²â
3.1 È˹¤¼ì²â
Óû§¿Éͨ¹ýÒÔÏÂÏÂÁîÉó²éAzure Linux ½Úµã¼àÌýOMI¶Ë¿ÚµÄÇéÐΣ¬¼ì²âϵͳÊÇ·ñÊÜÒÔÉÏÎó²îÓ°Ï죺
|
netstat -an | grep <port-number> |
×¢£º¹ØÓÚ²î±ðµÄ·þÎñ£¬¶Ë¿ÚºÅ¿ÉÄܲî±ð¡£
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÓÚ8ÔÂ12ÈÕÔÚ×îа汾ÖÐÐÞ¸´ÁËÒÔÉÏÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º https://github.com/microsoft/omi-kits/tree/master/release
Ò»¡¢Æ¾Ö¤ÄúʹÓÃµÄ Linux ²Ù×÷ϵͳ£¬½« MSRepo ×°Öõ½ÏµÍ³ÖУ¬²Î¿¼Á´½Ó£ºhttps://docs.microsoft.com/en-us/windows-server/administration/Linux-Package-Repository-for-Microsoft-Software
¶þ¡¢Ê¹ÓÃÄúƽ̨µÄ´ò°ü¹¤¾ßÀ´Éý¼¶ OMI£¬Èçsudo apt-get install omi»òsudo yum install omi
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







