VxWorks¶à¸öÔ¶³Ì´úÂëÖ´Ðзì϶

°ä²¼¹¦·ò 2019-07-31

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


1¡¢²¼¾°ÃèÊö


°²È«×êÑÐÈËÔ±ÔÚVxWorksÖз¢ÏÖÁË11¸ö0day·ì϶ £¬VxWorksÊÇǶÈëʽÉ豸ÖÐʹÓÃ×î¿í·ºµÄʵʱ²Ù×÷ϵͳ£¨RTOS£©Ö®Ò» £¬¿í·ºÀûÓÃÓÚº½¿Õº½Ìì £¬¹ú·À £¬¹¤Òµ £¬Ò½ÁÆ £¬Æû³µµÈÁìÓò £¬È«ÇòÖÁÉÙ20ÒŲ́É豸ʹÓÃʹÓÃVxWorks¡£ÕâЩ·ì϶±»Í³³ÆÎªURGENT/11 £¬ÓÉÓÚËüÃǹ²ÓÐ11¸ö £¬ÆäÖÐ6¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

VxWorksÓô¦¼«¶È¿í·º £¬ÀýÈçÍøÂçÉãÏñÍ· £¬ÍøÂ绥»»»ú £¬Â·ÓÉÆ÷ £¬·À»ðǽ £¬VOIPµç»° £¬´òÓ¡»úºÍÊÓÆµ»áÒé²úÆ· £¬ÒÔ¼°½»Í¨Ñ¶ºÅµÆ¡£³ý´ËÖ®±í £¬VxWorks»¹±»³ÁҪϵͳʹÓà £¬ÀýÈçSCADA £¬»ð³µ £¬µçÌݺ͹¤Òµ½ÚÔìÆ÷ £¬²¡È˼໤ÒÇ £¬ºË´Å¹²Õñ³ÉÏñÒÇÆ÷ £¬ÎÀÐǵ÷Ôì½âµ÷Æ÷ £¬ÉõÖÁÊÇ»ðÐÇ̽²âÆ÷¡£

2¡¢·ì϶ÏêÇé


URGENT/11·ì϶ӰÏì×Ô6.5°æÒÔÉϵÄËùÓÐVxWorks°æ±¾¡£ÏÔÈ»ÔÚ´Óǰ13ÄêÖа䲼µÄËùÓÐVxWorks°æ±¾¶¼ÈÝÒ×Êܵ½¹¥»÷¡£

ÆäÖÐ6¸ö·ì϶¿É´¥·¢Ô¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷ £¬¶øÊ£Ïµķì϶¿ÉÄܻᵼÖ»ؾø·þÎñ £¬ÐÅϢй¶»òÂß¼­·ì϶¡£

Ô¶³ÌÖ´ÐдúÂëȱµã£º


½âÎöIPv4Ñ¡Ïîʱ²Ö¿âÒç³ö£¨CVE-2019-12256£©


ÓÉÓÚÃýÎó´¦ÖÃTCPµÄÖ¸Õë×ֶζøµ¼ÖµÄËĸöÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-12255 £¬CVE-2019-12260 £¬CVE-2019-12261 £¬CVE-2019-12263£©


ipdhcpcÖеÄDHCP Offer / ACK½âÎöÖеĶÑÒç³ö£¨CVE-2019-12257£©

DoS £¬ÐÅϢй©ºÍÂß¼­È±µã£º


ͨ¹ýÌåʽÃýÎóµÄTCPÑ¡Ïî½øÐÐTCPÏνÓDoS£¨CVE-2019-12258£©


´¦ÖÃδ¾­ÒªÇóµÄ·´ÏòARP»Ø¸´£¨Âß¼­È±µã£©£¨CVE-2019-12262£©


ipdhcpc DHCP¿Í»§¶Ë·ÖÅäIPv4µÄÂß¼­È±µã£¨CVE-2019-12264£©


ÔÚIGMP½âÎöÖÐͨ¹ýNULL½â³ýÒýÓõÄDoS£¨CVE-2019-12259£©


IGMPÐÅϢй©ͨ¹ýIGMPv3ÌØ¶¨³ÉÔ±»ã±¨£¨CVE-2019-12265£©

3¡¢½¨¸´½¨Òé


VxWorksÒÑÌṩ²¹¶¡¸üР£¬¿ÉÔÚVxWorks°²È«ÖÐÐİ䲼µÄWind River Security AlertÖÐÕÒµ½£º


https://www.windriver.com/security/
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/

4¡¢²Î¿¼Á´½Ó


https://www.windriver.com/security/
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
https://www.sonicwall.com/support/product-notification/?sol_id=190717234810906
https://security.business.xerox.com/en-us/