NGINX njs »º³åÇøÃýÎó·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-05

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12208 £¬Î£ÏÕ¼¶±ð£ºÑϳÁ £¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


NGINXÖÐʹÓõÄnjs 0.3.1¼°Ö®Ç°°æ±¾


·ì϶¸ÅÊö


NGINXÊÇÃÀ¹úNGINX¹«Ë¾µÄÒ»¿îÇáÁ¿¼¶Web·þÎñÆ÷/·´Ïò´úÀí·þÎñÆ÷¼°µç×ÓÓʼþ£¨IMAP/POP3£©´úÀí·þÎñÆ÷ ¡£njsÊÇÆäÖеÄÒ»¸öÖ§³ÖÀ©´óNGINXÖ°Äܵľ籾˵»°×é¼þ ¡£


NGINXÖÐʹÓõÄnjs 0.3.1¼°Ö®Ç°°æ±¾µÄnjs/njs_function.cÎļþµÄ¡®njs_function_native_call¡¯º¯Êý´æÔÚ»ùÓڶѵĻº³åÇøÒç¶Âí½Å ¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ £¬Î´ÕýÈ·ÑéÖ¤Êý¾ÝÌìǵ £¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æµØÎ»ÉÏÖ´ÐÐÁËÃýÎóµÄ¶Áд²Ù×÷ ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶µ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ ¡£ 


·ì϶ÑéÖ¤


POC£ºhttps://github.com/nginx/njs/issues/163 ¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©½â¾ö´Ë°²È«ÎÊÌâ £¬½¨ÒéʹÓôËÈí¼þµÄÓû§ËæÊ±¹Ø×¢³§ÉÌÖ÷Ò³»ò²Î¿¼ÍøÖ·ÒÔ»ñÈ¡½â¾ö·¨×Ó£ºhttps://nginx.org/  ¡£


²Î¿¼Á´½Ó


http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201905-806