¶à¸öApache httpdÇå¾²Îó²î Çå¾²Íþвͨ¸æ
2017-06-21
¿ËÈÕ£¬Apache¹Ù·½Ðû²¼ÁËhttpdµÄа汾ÐÞ¸´Á˶à¸öÇå¾²Îó²î£¬Éæ¼°CVE-2017-3167£¬CVE-2017-3169£¬CVE-2017-7659£¬CVE-2017-7668£¬CVE-2017-7679£¬¿ÉÒÔÔì³ÉÉí·ÝÑéÖ¤±»ÈƹýÒÔ¼°¾Ü¾ø·þÎñ¹¥»÷µÈ¡£´ó²¿·ÖApache httpd 2.2.xÒÔ¼°2.4.x°æ±¾¾ùÊÜÓ°Ïì¡£Ïà¹ØÎó²îÐÅÏ¢ÈçÏ£º
|
CVE񅧏 |
Îó²îÐÎò |
|
CVE-2017-3167 |
µÚÈý·½Ä£¿éÔÚÑéÖ¤½×¶ÎÒÔÍâŲÓÃap_get_basic_auth_pw()ʱÓпÉÄܵ¼ÖÂÑéÖ¤ÒªÇó±»Èƹý |
|
CVE-2017-3169 |
µ±µÚÈý·½Ä£¿éÔÚŲÓÃap_hook_process_connection()·¢ËÍHTTPÇëÇó¸øHTTPS¶Ë¿Úʱ£¬mod_ssl¿ÉÄÜ»á¼ä½ÓÒýÓÿÕÖ¸Õë |
|
CVE-2017-7659 |
ÔÚ´¦Öóͷ£¶ñÒâ½á¹¹µÄHTTP/2ÇëÇóʱ£¬mod_http2¿ÉÄÜ»á¼ä½ÓÒýÓÿÕÖ¸Õ룬ʹ·þÎñÆ÷Àú³ÌÍß½â |
|
CVE-2017-7668 |
HTTPÑÏ¿áÆÊÎö¸Ä¶¯Öб£´æÒ»¸öÁîÅÆÁбíÆÊÎöµÄBUG£¬ap_find_token()¿ÉÒÔËÑË÷ÊäÈë×Ö·û´®Ö®ÍâµÄÄÚÈÝ¡£Í¨¹ý½á¹¹Ò»¸ö¶ñÒâµÄÇëÇóÍ·£¬¹¥»÷Õß¿ÉÒÔÔì³É¶Î¹ýʧ»òÕßÇ¿ÐÐÈÃap_find_token()·µ»ØÒ»¸ö¹ýʧµÄÖµ |
|
CVE-2017-7679 |
µ±¹¥»÷Õß·¢ËÍÒ»¸ö¶ñÒâµÄContent-TypeÏìӦͷʱ£¬mod_mime»áÔ½½ç¶ÁÈ¡»º³åÇøÄÚÈÝ¡£ |
²Î¿¼Á´½Ó£º
https://httpd.apache.org/security/vulnerabilities_24.html
https://httpd.apache.org/security/vulnerabilities_22.html
ÊÜÓ°ÏìµÄ°æ±¾
Apache httpd 2.2.x < 2.2.33-dev
Apache httpd 2.4.x < 2.4.26
¸÷Îó²îÓ°ÏìµÄ°æ±¾ÏêϸÐÅÏ¢¿É²Î¿¼ÎÄÄ©¸½Â¼¡£
²»ÊÜÓ°ÏìµÄ°æ±¾
Apache httpd 2.4.26
¹æ±Ü¼Æ»®
Apache¹Ù·½ÒѾÕë¶Ô2.2.xÒÔ¼°2.4.xÐû²¼ÁËÏìÓ¦µÄ2.2.33-devÒÔ¼°2.4.26а汾ÐÞ¸´ÁËÉÏÊö¸÷Îó²î£¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±ÏÂÔØ¸üÐÂÖÁ×îаæÔÀ´·À»¤Îó²î¡£Çë²Î¿¼ÈçÏÂÅþÁ¬£º
2.2.x°æ±¾£ºhttps://httpd.apache.org/security/vulnerabilities_22.html
2.4.x°æ±¾£ºhttps://httpd.apache.org/security/vulnerabilities_24.html
¸½Â¼
¸÷Îó²îÓ°Ïì°æ±¾µÄÏêϸÐÅÏ¢ÈçÏ£º
CVE-2017-3167
2.4.25 2.4.23 2.4.20 2.4.18 2.4.17 2.4.16 2.4.12 2.4.10 2.4.9 2.4.7 2.4.6 2.4.4 2.4.3 2.4.2 2.4.1 2.2.32 2.2.31 2.2.29 2.2.27 2.2.26 2.2.25 2.2.24 2.2.23 2.2.22 2.2.21 2.2.20 2.2.19 2.2.18 2.2.17 2.2.16 2.2.15 2.2.14 2.2.13 2.2.12 2.2.11 2.2.10 2.2.9 2.2.8 2.2.6 2.2.5 2.2.4 2.2.3 2.2.2 2.2.0
CVE-2017-3169
2.4.25 2.4.23 2.4.20 2.4.18 2.4.17 2.4.16 2.4.12 2.4.10 2.4.9 2.4.7 2.4.6 2.4.4 2.4.3 2.4.2 2.4.1 2.2.32 2.2.31 2.2.29 2.2.27 2.2.26 2.2.25 2.2.24 2.2.23 2.2.22 2.2.21 2.2.20 2.2.19 2.2.18 2.2.17 2.2.16 2.2.15 2.2.14 2.2.13 2.2.12 2.2.11 2.2.10 2.2.9 2.2.8 2.2.6 2.2.5 2.2.4 2.2.3 2.2.2 2.2.0
CVE-2017-7659
2.4.25
CVE-2017-7668
2.4.25 2.2.32
CVE-2017-7679
2.4.25 2.4.23 2.4.20 2.4.18 2.4.17 2.4.16 2.4.12 2.4.10 2.4.9 2.4.7 2.4.6 2.4.4 2.4.3 2.4.2 2.4.1 2.2.32 2.2.31 2.2.29 2.2.27 2.2.26 2.2.25 2.2.24 2.2.23 2.2.22 2.2.21 2.2.20 2.2.19 2.2.18 2.2.17 2.2.16 2.2.15 2.2.14 2.2.13 2.2.12 2.2.11 2.2.10 2.2.9 2.2.8 2.2.6 2.2.5 2.2.4 2.2.3 2.2.2 2.2.0
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ







