RSA Authentication Agent Îó²î £¨CVE-2017-14377£¬CVE-2017-14378£©
2017-12-05
×ÛÊö
¿ËÈÕ£¬RSA Authentication Agent±»·¢Ã÷±£´æ2¸öÒªº¦Îó²î£º
CVE-2017-14377£¬CVE-2017-14378¡£ÀÖ³ÉʹÓÃÕâЩÎó²î¿ÉÄܵ¼ÖÂÑéÖ¤ÈÆ¹ý´Ó¶ø»á¼ûÆäËû×ÊÔ´¡£ÏêϸµÄÎó²îÐÅÏ¢Çë²Î¿¼ÏÂÎÄ¡£
Ïà¹ØÁ´½Ó£º
http://securityaffairs.co/wordpress/66325/hacking/rsa-authentication-sdk-flaws.html
http://seclists.org/fulldisclosure/2017/Nov/46
http://seclists.org/fulldisclosure/2017/Nov/48
CVE-2017-14377
ÓÃÓÚApache Web ServerµÄRSAÉí·ÝÑéÖ¤ÊðÀíµÄWebÉϵÄÇå¾²Îó²î¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£
CVSS v3.0 Base Score: 10
(AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)
Ó°ÏìµÄ²úÆ·¼°°æ±¾
- RSA? Authentication Agent for Web: Apache Web Server version 8.0
- RSA? Authentication Agent for Web: Apache Web Server version 8.0.1 prior to Build 618
²»ÊÜÓ°ÏìµÄ²úÆ·¼°°æ±¾
- RSA Authentication Agent for Web: Apache Web Server version 8.0.1 Build 618
´¦Öóͷ£¼Æ»®
RSA½¨ÒéËùÓÐÓû§¾¡¿ìÉý¼¶µ½Çå¾²°æ±¾¡£
²Î¿¼Á´½Ó
https://community.rsa.com/community/products/securid/authentication-agent-web-apache.
http://seclists.org/fulldisclosure/2017/Nov/46
CVE-2017-14378
RSA Authentication Agent API / SDK for C°æ±¾8.5ºÍ8.6ÖеÄÒ»¸öÇå¾²Îó²î¿ÉÄܵ¼ÖÂÔÚijЩÓÐÏÞµÄʵÏÖÖÐÈÆ¹ýÉí·ÝÑéÖ¤
CVSS v3 Base Score: 10
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Ó°ÏìµÄ²úÆ·¼°°æ±¾£º
- RSA? Authentication Agent API 8.5 for C
- RSA? Authentication Agent SDK 8.6 for C
²»ÊÜÓ°ÏìµÄ²úÆ·¼°°æ±¾
- RSA Authentication Agent for Web: Apache Web Server version 8.0.1 Build 618
´¦Öóͷ£¼Æ»®
RSA½¨ÒéËùÓÐÓû§¾¡¿ìÉý¼¶µ½Çå¾²°æ±¾£¬Í¬Ê±ÇëÈ·±£ÆäAPI / SDKµÄʵÏÖÇкϡ°RSAÉí·ÝÑéÖ¤ÊðÀíAPI for C¿ª·¢Ö°Ô±Ö¸ÄÏ¡±ÖмͼµÄ±àÂë×¼Ôò¡£
²Î¿¼Á´½Ó£º
https://community.rsa.com/docs/DOC-40601#agents
http://seclists.org/fulldisclosure/2017/Nov/48
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ







