CVE编号
CVE-2018-1000140利用情况
EXP 已公开补丁情况
官方补丁披露时间
2018-03-24漏洞描述
rsyslog librelp 1.2.14及更早版本在检查来自对等方的x509证书时包含缓冲区溢出漏洞,该漏洞可能导致远程代码执行。此攻击似乎可利用远程攻击者,该远程攻击者可以通过发送特制的x509证书连接到rsyslog并触发堆栈缓冲区溢出。解决建议
目前厂商暂未发布修复措施解决此安全问题,建议使用此软件的用户随时关注厂商主页或参考网址以获取解决办法:https://www.rsyslog.com/
参考链接 |
|
---|---|
https://access.redhat.com/errata/RHSA-2018:1223 | |
https://access.redhat.com/errata/RHSA-2018:1225 | |
https://access.redhat.com/errata/RHSA-2018:1701 | |
https://access.redhat.com/errata/RHSA-2018:1702 | |
https://access.redhat.com/errata/RHSA-2018:1703 | |
https://access.redhat.com/errata/RHSA-2018:1704 | |
https://access.redhat.com/errata/RHSA-2018:1707 | |
https://github.com/rsyslog/librelp/blob/532aa362f0f7a8d037505b0a27a1df452f9ba... | |
https://lgtm.com/rules/1505913226124/ | |
https://security.gentoo.org/glsa/201804-21 | |
https://usn.ubuntu.com/3612-1/ | |
https://www.debian.org/security/2018/dsa-4151 |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | rsyslog | librelp | * |
Up to (including) 1.2.14 |
|||||
运行在以下环境 | |||||||||
系统 | amazon_2 | librelp | * |
Up to (excluding) 1.2.12-1.amzn2.0.1 |
|||||
运行在以下环境 | |||||||||
系统 | centos_6 | librelp | * |
Up to (excluding) 1.2.7-3.el6_9.1 |
|||||
运行在以下环境 | |||||||||
系统 | centos_7 | librelp | * |
Up to (excluding) 1.2.12-1.el7_5.1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_8 | librelp | * |
Up to (excluding) 1.2.7-2+deb8u1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_9 | librelp | * |
Up to (excluding) 1.2.12-1+deb9u1 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_26 | librelp | * |
Up to (excluding) 1.2.15-1.fc26 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_27 | librelp | * |
Up to (excluding) 1.2.15-1.fc27 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_42.3 | librelp | * |
Up to (excluding) 1.2.12-2.3.1 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_6 | librelp | * |
Up to (excluding) 1.2.7-3.el6_9.1 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_7 | librelp | * |
Up to (excluding) 1.2.12-1.el7_5.1 |
|||||
运行在以下环境 | |||||||||
系统 | suse_12_SP2 | librelp | * |
Up to (excluding) 1.2.7-3.3.1 |
|||||
运行在以下环境 | |||||||||
系统 | suse_12_SP3 | librelp | * |
Up to (excluding) 1.2.12-3.3.1 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_14.04 | librelp | * |
Up to (excluding) 1.2.2-2ubuntu1.1 |
|||||
- 攻击路径 远程
- 攻击复杂度 容易
- 权限要求 无需权限
- 影响范围 有限影响
- EXP成熟度 EXP 已公开
- 补丁情况 官方补丁
- 数据保密性 无影响
- 数据完整性 无影响
- 服务器危害 无影响
- 全网数量 N/A
还没有评论,来说两句吧...