2023Äê10ÔÂ30ÈÕ£¬×ðÁú¿Ê±ÐÇÂÞÍøÂç¿Õ¼äÇ徲ʵÑéÊÒ¼à²âµ½Apache HTTP ServerÖÐÐÞ¸´ÁËÒ»¸öÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2023-31122£©¡£
Îó²î¸ÅÊö
Apache HTTP ServerÊÇApacheÈí¼þ»ù½ð»áµÄÒ»¸ö¿ª·ÅÔ´´úÂëµÄÍøҳЧÀÍÆ÷£¬ÓÉÓÚÆä¾ßÓпçƽ̨ÐÔºÍÇå¾²ÐÔ£¬±»ÆÕ±éʹÓã¬ËüÊÇ×îÊ¢ÐеÄWebЧÀÍÆ÷¶ËÈí¼þÖ®Ò»¡£
Σº¦ÌáÐÑ
Îó²îÆ·¼¶
¸ßΣ
Ó°Ïì¹æÄ£
Apache HTTP Server <= 2.4.57
ÐÞ¸´½¨Òé
1.Éý¼¶°æ±¾£º
ÏÖÔÚ¸ÃÎó²îÒѾÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½Apache HTTP Server 2.4.58¡£
2.ÏÂÔØÁ´½Ó£º
https://httpd.apache.org/download.cgi
ÔÝʱ²½·¥
ÔÝÎÞ¡£
3. ͨÓý¨Ò飺
°´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔÌϵͳÎó²î£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔ̹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔÔò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏ޶ȡ£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£
4. ²Î¿¼Á´½Ó
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2023-31122
https://svn.apache.org/viewvc?view=revision&revision=1912993
https://www.openwall.com/lists/oss-security/2023/10/19/4
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬½ËÕ×ðÁú¿Ê±ÐÇÂÞÍøÂç¿Õ¼äÇ徲ʵÑéÊÒ²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÒòÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕ棬½ËÕ×ðÁú¿Ê±ÐÇÂÞÍøÂç¿Õ¼äÇ徲ʵÑéÊÒÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
½ËÕ×ðÁú¿Ê±/Profile?
¹«Ë¾ÒÔ¡°´´Á¢¸üÇå¾²µÄÊý×ÖδÀ´"ΪʹÃü£¬»ùÓÚ×ÔÖ÷Á¢ÒìÊÖÒÕ×ö¾«×öÉîȫϵÊý¾ÝÇå¾²²úÆ·£¬¼ÓËÙ²úÆ·±ê×¼»¯¡¢¹ú²ú»¯¡¢ÔÆ»¯¡¢Ô×Ó»¯ºÍÄÜÁ¦¿ª·Å¹²Ïí£¬Îª¿Í»§ÌṩÇå¾²¡¢ºÏ¹æ¡¢È«ÉúÃüÖÜÆÚ¡¢È«ÓªÒµ³¡¾°µÄÊý¾ÝÇå¾²ÕûÌå½â¾ö¼Æ»®ºÍЧÀÍ£¬ÎªÆóÒµÊý×Ö»¯×ªÐÍÌṩÊý×ÖÇå¾²°ü¹Ü¡£