PPPDÔ¶³Ì´úÂëÖ´Ðзì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-06

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-8597£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


pppd 2.4.2ÖÁ2.4.8 °æ±¾


·ì϶¸ÅÊö


US-CERT °ä²¼°²È«²¼¸æ³Æ£¬£¬£¬£¬£¬£¬PPP ÊØ»¤¹ý³Ì (pppd) Èí¼þÖдæÔÚÒ»¸öÒÑÓÐ17ÄêÖ®¾ÃµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬Ó°ÏìÏÕЩËùÓлùÓÚ Linux µÄ²Ù×÷ϵͳÒÔ¼°ÍøÂçÉ豸¹Ì¼þ ¡£¡£¡£¡£¡£¡£


ÊÜÓ°ÏìµÄ pppd Èí¼þÊǵã¶ÔµãºÍ̸£¨PPP£¬£¬£¬£¬£¬£¬Ö§³Ö½ÚµãÖ®¼äµÄͨѶºÍÊý¾Ý´«Ê䣩µÄʵÏÖ£¬£¬£¬£¬£¬£¬ÖØÒªÓÃÓÚÉèÁ¢»¥ÁªÍøÁ´½ÓÈ粦ºÅµ÷Ôì½âµ÷Æ÷¡¢DSL¿í´øÏνӺÍÐ鹹רÓÃÍøÂçµÄÏÎ½Ó ¡£¡£¡£¡£¡£¡£


¸Ã·ì϶ÓÉpppd Èí¼þµÄ¿ÉÀ©´óÈÏÖ¤ºÍ̸ (EAP) Êý¾Ý°ü½âÎöÆ÷ÖдæÔÚµÄÒ»¸öÂß¼­ÃýÎóÒý·¢£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂδÈÏÖ¤¹¥»÷ÕßÔÚÊÜÓ°ÏìϵͳÉÏÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë²¢ÆëÈ«½ÚÔìϵͳ ¡£¡£¡£¡£¡£¡£¶ø¹¥»÷ÕßҪʵÏÖÕâÒ»Ö÷ÕÅ£¬£¬£¬£¬£¬£¬±ØÒª×öµÄ²»ÍâÊÇÏòÒ×Êܹ¥»÷µÄ ppp ¿Í»§¶Ë»ò·þÎñÆ÷·¢ËÍÌåʽÃýÎóµÄ EAP Êý¾Ý°ü ¡£¡£¡£¡£¡£¡£


Áí±í£¬£¬£¬£¬£¬£¬ÓÉÓÚ pppd ͨ³£ÒÔ¸ßȨÏÞÔËÐÐÇÒÓëÄÚºËÇý¶¯·¨Ê½Ò»Â·ÔË×÷£¬£¬£¬£¬£¬£¬Òò¶ø¸Ã·ì϶¿ÉÄÜʹ¹¥»÷ÕßÒÔϵͳ»ò root ȨÏÞÖ´ÐжñÒâ´úÂë ¡£¡£¡£¡£¡£¡£


°²È«²¼¸æÖ¸³ö£¬£¬£¬£¬£¬£¬¡°½«ËùÌṩÊý¾Ý¸´Ôìµ½ÄÚ´æÇ°£¬£¬£¬£¬£¬£¬ÑéÖ¤ÊäÈë´óÓ×ʱ³öÏÖÃýÎóµ¼Ö·ì϶²úÉú ¡£¡£¡£¡£¡£¡£ÓÉÓÚ¶ÔÊý¾Ý´óÓ×µÄÑéÖ¤²»ÕýÈ·£¬£¬£¬£¬£¬£¬Òò¶ø¿É½«ËÁÒâÊý¾Ý¸´Ôìµ½ÄÚ´æÖв¢Òý·¢ÄÚ´æ°Ü»µÎÊÌ⣬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÖ´Ðв»ÓÃÒªµÄ´úÂë ¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚ eap ½âÎö´úÂëÂß¼­ÖУ¬£¬£¬£¬£¬£¬¾ßÌå´æÔÚÓÚÍøÂçÊäÈë¾ä±úŲÓÃµÄ eap.c ÖÐµÄ eap_request() ºÍeap_response()º¯ÊýÖÐ ¡£¡£¡£¡£¡£¡£¡±°²È«²¼¸æ»¹Ö¸³ö£¬£¬£¬£¬£¬£¬ÈôÊÇδÆôÓà EAP »òÔ¶³Ì¶ÔµÈ·½Î´Ê¹ÓÃÃÜÂëЭÉÌEAP£¬£¬£¬£¬£¬£¬ÔòÒÔΪ pppd ²»Ò×Êܹ¥»÷µÄ¸ÅÏë²»ÕýÈ·£¬£¬£¬£¬£¬£¬Ô­ÒòÔÚÓÚÈÏÖ¤µÄ¹¥»÷Õß¿ÉÄÜÒÀÈ»¿ÉÄÜ·¢ËÍδ¾­ÒªÇóµÄ EAP Êý¾Ý°ü´¥·¢»º³åÇøÒç¶Âí½Å ¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP ¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


ppp Èí¼þÉÐδÕë¶Ô¸Ã·ì϶°ä²¼Ð嵀 Release °æ±¾£¬£¬£¬£¬£¬£¬ÇëÉý¼¶ ppp ÖÁ 8d7970b8f3db727fe798b65f3377fe6787575426 (git commit id)£ºhttps://github.com/paulusmack/ppp/commit/8d7970b8f3db727fe798b65f3377fe6787575426 ¡£¡£¡£¡£¡£¡£

һЩ¿í·ºÊ¹Óõ쬣¬£¬£¬£¬£¬Ê¢ÐеÄLinux¿¯ÐаæÒѾ­±»Ö¤ÊµÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬½¨¸´Çé¿öÈçÏ£º



Debian£ºhttps://www.debian.org/security/2020/dsa-4632

Ubuntu£ºhttps://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-8597.html

SUSE Linux£ºhttps://www.suse.com/security/cve/CVE-2020-8597/

Fedora£ºhttps://access.redhat.com/security/cve/cve-2020-8597

NetBSD£ºhttps://cvsweb.netbsd.org/bsdweb.cgi/src/external/bsd/ppp/dist/pppd/eap.c?only_with_tag=MAIN

Red Hat Enterprise Linux£ºhttps://access.redhat.com/security/cve/cve-2020-8597

Centos£ºhttps://centos.pkgs.org/7/centos-updates-x86_64/ppp-2.4.5-34.el7_7.x86_64.rpm.html


´Ë±í£¬£¬£¬£¬£¬£¬Ò»Ð©Êܵ½Ó°ÏìµÄÀûÓ÷¨Ê½ºÍÉ豸½¨¸´Çé¿öÈçÏ£º


Cisco CallManager£ºhttps://quickview.cloudapps.cisco.com/quickview/bug/CSCvs95534/

TP-LINK ²úÆ·£ºhttps://www.tp-link.com/en/support/faq/2803/

OpenWRT Embedded OS£ºhttps://openwrt.org/advisory/2020-02-21-1

Synology£¨DiskStation ÖÎÀíÆ÷¡¢VisualStation¡¢Router Manager£©£ºhttps://www.synology.cn/en-global/security/advisory/Synology_SA_20_02


²Î¿¼Á´½Ó


https://thehackernews.com/2020/03/ppp-daemon-vulnerability.html