¡¾Ô¤¾¯Í¨¸æ¡¿PostgreSQLí§Òâ´úÂëÖ´ÐÐÎó²îCVE-2019-9193
2019-03-26
Îó²î¸ÅÊö
¿ËÈÕ£¬Çå¾²Ñо¿Ö°Ô±Åû¶ÁËPostgreSQLÌáȨ´úÂëÖ´ÐÐÎó²î£¨CVE-2019-9193£©µÄÎó²îϸ½Ú£¬¾ßÓÐÊý¾Ý¿â·þÎñ¶ËÎļþ¶ÁȨÏ޵Ĺ¥»÷ÕßʹÓôËÎó²î£¬¿ÉÖ´ÐÐí§ÒâϵͳÏÂÁî¡£
PostgreSQLÊÇÒ»¿î¹¦Ð§Ç¿Ê¢µÄÊý¾Ý¿âÈí¼þ£¬¿ÉÔËÐÐÔÚËùÓÐÖ÷Á÷²Ù×÷ϵͳÉÏ£¬°üÀ¨Linux¡¢Windows¡¢Mac OS XµÈ¡£´Ë´ÎÅû¶µÄÎó²î±£´æÓÚµ¼Èëµ¼³öÊý¾ÝµÄÏÂÁî¡°COPY TO/FROM PROGRAM¡±¡±ÖУ¬¡°pg_read_server_files¡±×éÄÚÓû§Ö´ÐÐÉÏÊöÏÂÁîºó£¬¿É»ñÈ¡Êý¾Ý¿â³¬µÈÓû§È¨ÏÞ£¬´Ó¶øÖ´ÐÐí§ÒâϵͳÏÂÁî¡£
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
- PostgreSQL >=9.3
½â¾ö½¨Òé
pg_read_server_files¡¢pg_write_server_files¡¢pg_execute_server_program ½Çɫɿ¼°µ½¶ÁдÊý¾Ý¿â·þÎñ¶ËÎļþ£¬È¨Ï޽ϴ󣬷ÖÅɴ˽ÇɫȨÏÞ¸øÊý¾Ý¿âÓû§Ê±ÐèÉóÉ÷˼Á¿¡£
²úÆ··À»¤
ÏÖÔÚ¹Ù·½ÔÝÎÞÐÞ¸´´ËÎó²îµÄÍýÏ룬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍøÂçÈëÇÖ·À»¤ÏµÍ³£¨NIPS£©½«ÓÚÀýÐиüÐÂÖÐÐû²¼Õë¶Ô´ËÎó²îµÄ·À»¤¹æÔò£¬ÇëÏà¹ØÓû§¹Ø×¢£¬ÊµÊ±ÍêªϰÔò¸üУ¬ÒÔʵÏÖ¶Ô´ËÎó²îµÄ·À»¤¡£Íê³É¸üкó£¬ÔÚϵͳĬÈϹæÔò¿âÖвéÕÒ¹æÔò±àºÅ£º41660£¬¼´¿ÉÅÌÎʵ½¶ÔÓ¦µÄ¹æÔòÏêÇé¡£
²Î¿¼Á´½Ó£º
http://paper.tuisec.win/detail/66d2b3ec28c7239
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³Æ¾ÅÓÎÀÏ¸ç¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖݾÅÓÎÀϸçÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊÐÉúÒ⣬¹ÉƱ¼ò³Æ£º¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

¾ÅÓÎÀϸçÔÆ





