Apache mod_jk»á¼û¿ØÖÆÈƹýÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-11-09Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-11759£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ 7.3£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Apache Group Tomcat JK£¨mod_jk£©Connector 1.2.0-1.2.44
Îó²î¸ÅÊö
¿ËÈÕ£¬£¬£¬£¬£¬£¬Apache Tomcat¹Ù·½Ðû²¼ÁËmod_jk±£´æ»á¼û¿ØÖÆÈƹýÎó²î£¨CVE-2018-11759£©µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÏÖÔÚPoCÒѾ¹ûÕæ£¬£¬£¬£¬£¬£¬ÇëÏà¹ØÓû§ÒýÆð×¢ÖØ£¬£¬£¬£¬£¬£¬ÊµÊ±½ÓÄÉÌá·À²½·¥¡£¡£¡£
Apache Tomcat JK£¨mod_jk£©ConnectorÊÇÒ»¿îΪApache»òIISÌṩÅþÁ¬ºǫ́TomcatµÄÄ£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬ËüÖ§³Ö¼¯ÈººÍ¸ºÔØÆ½ºâµÈ¡£¡£¡£ ´ËÎó²î£¨CVE-2018-11759£©ÓëCVE-2018-1323ÀàËÆ£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚApache Tomcat WebЧÀÍÆ÷(httpd)ÓÃÓڹ淶ÇëÇó·¾¶µÄ´úÂ룬£¬£¬£¬£¬£¬ÔÚÆ¥ÅäApache Tomcat JK(mod_jk)ÅþÁ¬Æ÷ÖеÄURI-WorkerÓ³Éä֮ǰ£¬£¬£¬£¬£¬£¬Ã»ÓÐ׼ȷ´¦Öóͷ£Ä³Ð©±ßÑØÇéÐΣ¨Èç¹ýÂË¡°£»£»£»£»£»¡±£©¶øµ¼Ö¡£¡£¡£¹¥»÷ÕßʹÓôËÎó²î¿Éͨ¹ý½á¹¹¶ñÒâÇëÇ󣬣¬£¬£¬£¬£¬ÊµÏÖ»á¼û¿ØÖÆÈƹý¡£¡£¡£
Îó²îÑéÖ¤
https://github.com/immunIT/CVE-2018-11759
Óû§Ò²¿Éͨ¹ýPoC×ÔÐÐÅŲéÄ¿½ñËùʹÓõÄÄ£¿£¿£¿£¿éÊÇ·ñÊÜ´ËÎó²îÓ°Ï죬£¬£¬£¬£¬£¬ÈçÏÂͼÔÚhttpd.confÉèÖÃÎļþÖоÙÐÐÈçÏÂÉèÖ㬣¬£¬£¬£¬£¬¼´¶Ô127.0.0.1µØµãµÄ»á¼û¾ÙÐÐÁËÏÞÖÆ¡£¡£¡£
µ±Ê¹ÓÃÍâµØµØµãlocalhost»á¼ûʱ£¬£¬£¬£¬£¬£¬»áÌáÐѱ»Õ¥È¡»á¼û£º
ÔڵصãºóÌí¼ÓÌØÊâ·ûºÅ¡°;¡±£¬£¬£¬£¬£¬£¬¼´Èƹý´Ë»á¼ûÏÞÖÆ¡£¡£¡£Èô·ºÆðÏÂͼËùʾÇéÐΣ¬£¬£¬£¬£¬£¬Ôò˵Ã÷Ä¿½ñËùʹÓõÄmod_jkÊÜ´ËÎó²îÓ°Ïì¡£¡£¡£
ÊÖ¹¤×Ô²é
Óû§¿Éͨ¹ý×ÔÐÐÅŲéÄ¿½ñËùʹÓð汾ÊÇ·ñÔÚÊÜÓ°Ïì¹æÄ£ÄÚ£¬£¬£¬£¬£¬£¬À´ÅжÏÊÇ·ñÊܱ£´æÍþв¡£¡£¡£Ïêϸ°ì·¨ÈçÏ£º
ʹÓÃstringsÖ±½ÓÉó²émod_jk.so¡£¡£¡£ÏÂÁîÈçÏ£ºstrings mod_jk.so | grep mod_jk
ÐÞ¸´½¨Òé
Apache¹Ù·½ÒѾÐû²¼ÁËа汾ÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬£¬£¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±¸üе½1.2.46»ò¸üеİ汾£¬£¬£¬£¬£¬£¬ÐγɶԴËÎó²îºã¾ÃÓÐÓõķÀ»¤¡£¡£¡£
https://archive.apache.org/dist/tomcat/tomcat-connectors/jk/tomcat-connectors-1.2.46-src.zip
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ