VxWorks¶à¸öÔ¶³Ì´úÂëÖ´Ðзì϶

°ä²¼¹¦·ò 2019-07-31

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


1¡¢²¼¾°ÃèÊö


°²È«×êÑÐÈËÔ±ÔÚVxWorksÖз¢ÏÖÁË11¸ö0day·ì϶£¬VxWorksÊÇǶÈëʽÉ豸ÖÐʹÓÃ×î¿í·ºµÄʵʱ²Ù×÷ϵͳ£¨RTOS£©Ö®Ò»£¬¿í·ºÀûÓÃÓÚº½¿Õº½Ì죬¹ú·À£¬¹¤Òµ£¬Ò½ÁÆ£¬Æû³µµÈÁìÓò£¬È«ÇòÖÁÉÙ20ÒŲ́É豸ʹÓÃʹÓÃVxWorks¡£ÕâЩ·ì϶±»Í³³ÆÎªURGENT/11£¬ÓÉÓÚËüÃǹ²ÓÐ11¸ö£¬ÆäÖÐ6¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

VxWorksÓô¦¼«¶È¿í·º£¬ÀýÈçÍøÂçÉãÏñÍ·£¬ÍøÂ绥»»»ú£¬Â·ÓÉÆ÷£¬·À»ðǽ£¬VOIPµç»°£¬´òÓ¡»úºÍÊÓÆµ»áÒé²úÆ·£¬ÒÔ¼°½»Í¨Ñ¶ºÅµÆ¡£³ý´ËÖ®±í£¬VxWorks»¹±»³ÁҪϵͳʹÓã¬ÀýÈçSCADA£¬»ð³µ£¬µçÌݺ͹¤Òµ½ÚÔìÆ÷£¬²¡È˼໤ÒÇ£¬ºË´Å¹²Õñ³ÉÏñÒÇÆ÷£¬ÎÀÐǵ÷Ôì½âµ÷Æ÷£¬ÉõÖÁÊÇ»ðÐÇ̽²âÆ÷¡£

2¡¢·ì϶ÏêÇé


URGENT/11·ì϶ӰÏì×Ô6.5°æÒÔÉϵÄËùÓÐVxWorks°æ±¾¡£ÏÔÈ»ÔÚ´Óǰ13ÄêÖа䲼µÄËùÓÐVxWorks°æ±¾¶¼ÈÝÒ×Êܵ½¹¥»÷¡£

ÆäÖÐ6¸ö·ì϶¿É´¥·¢Ô¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷£¬¶øÊ£Ïµķì϶¿ÉÄܻᵼÖ»ؾø·þÎñ£¬ÐÅϢй¶»òÂß¼­·ì϶¡£

Ô¶³ÌÖ´ÐдúÂëȱµã£º


½âÎöIPv4Ñ¡Ïîʱ²Ö¿âÒç³ö£¨CVE-2019-12256£©


ÓÉÓÚÃýÎó´¦ÖÃTCPµÄÖ¸Õë×ֶζøµ¼ÖµÄËĸöÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-12255£¬CVE-2019-12260£¬CVE-2019-12261£¬CVE-2019-12263£©


ipdhcpcÖеÄDHCP Offer / ACK½âÎöÖеĶÑÒç³ö£¨CVE-2019-12257£©

DoS£¬ÐÅϢй©ºÍÂß¼­È±µã£º


ͨ¹ýÌåʽÃýÎóµÄTCPÑ¡Ïî½øÐÐTCPÏνÓDoS£¨CVE-2019-12258£©


´¦ÖÃδ¾­ÒªÇóµÄ·´ÏòARP»Ø¸´£¨Âß¼­È±µã£©£¨CVE-2019-12262£©


ipdhcpc DHCP¿Í»§¶Ë·ÖÅäIPv4µÄÂß¼­È±µã£¨CVE-2019-12264£©


ÔÚIGMP½âÎöÖÐͨ¹ýNULL½â³ýÒýÓõÄDoS£¨CVE-2019-12259£©


IGMPÐÅϢй©ͨ¹ýIGMPv3ÌØ¶¨³ÉÔ±»ã±¨£¨CVE-2019-12265£©

3¡¢½¨¸´½¨Òé


VxWorksÒÑÌṩ²¹¶¡¸üУ¬¿ÉÔÚVxWorks°²È«ÖÐÐİ䲼µÄWind River Security AlertÖÐÕÒµ½£º


https://www.windriver.com/security/
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/

4¡¢²Î¿¼Á´½Ó


https://www.windriver.com/security/
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
https://www.sonicwall.com/support/product-notification/?sol_id=190717234810906
https://security.business.xerox.com/en-us/