Apache Tomcat Ô¶³Ì´úÂëÖ´ÐÐÎó²î CVE-2017-12617
2017-10-09
×ÛÊö
¿ËÈÕ£¬Apache¹Ù·½Ðû²¼ÁËTomcatµÄа汾£¬ÐÞ¸´ÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2017-12617£©¡£¸ÃÎó²îÔ´ÓÚÔÚHTTP PUTÒªÁìʱ£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÌØÖÆÇëÇó½«JSPÎļþÉÏ´«µ½·þÎñÆ÷¡£ È»ºó¿ÉÒÔÇëÇó´ËJSP£¬È÷þÎñÆ÷Ö´ÐиÃJSPÖаüÀ¨µÄí§Òâ´úÂë¡£
Ïà¹ØµØµã£º
https://lists.apache.org/thread.html/3fd341a604c4e9eab39e7eaabbbac39c30101a022acc11dd09d7ebcb@%3Cannounce.tomcat.apache.org%3E
http://tomcat.apache.org/security-7.html
http://tomcat.apache.org/security-8.html
http://tomcat.apache.org/security-9.html
ÊÜÓ°ÏìµÄ°æ±¾
¡¤ Apache Tomcat 9.0.0.M1 ¨C 9.0.0
¡¤ Apache Tomcat 8.5.0 ¨C 8.5.22
¡¤ Apache Tomcat 8.0.0.RC1 - 8.0.46
¡¤ Apache Tomcat 7.0.0 ¨C 7.0.81
²»ÊÜÓ°ÏìµÄ°æ±¾
¡¤ Apache Tomcat 9.0.1
¡¤ Apache Tomcat 8.5.23
¡¤ Apache Tomcat 8.0.47
¡¤ Apache Tomcat 7.0.82
½â¾ö¼Æ»®
¹Ù·½ÒѾÐû²¼ÁËа汾ÐÞ¸´Á˸ÃÎó²î£¬ÊÜÓ°ÏìµÄÓû§Ç뾡¿ìÉý¼¶ÖÁ×îаæÔÀ´·À»¤¸ÃÎó²î¡£
²Î¿¼Á´½Ó£º
Apache Tomcat 9.0.1:
https://tomcat.apache.org/download-90.cgi
Apache Tomcat 8.5.23/8.0.47:
https://tomcat.apache.org/download-80.cgi
Apache Tomcat 7.0.82:
https://tomcat.apache.org/download-70.cgi
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ







