Apache Tomcat°²È«·ì϶ÖÒ¸æ
°ä²¼¹¦·ò 2018-07-25·ì϶±àºÅºÍ¼¶±ð
CVE-2018-8034 ³§ÉÌ×ÔÆÀ£ºµÍ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-8037 ³§ÉÌ×ÔÆÀ£º³ÁÒª CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE-2018-1336 ³§ÉÌ×ÔÆÀ£º³ÁÒª CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
·ì϶¸ÅÊö
Apache Tomcat°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö°²È«·ì϶£¬Ô̺¬¿Éµ¼ÖÂÐÅϢй¶µÄ·ì϶£¨CVE-2018-8037£©¡¢¿Éµ¼Ö»ؾø·þÎñµÄ·ì϶£¨CVE-2018-1336£©ÒÔ¼°°²È«Èƹý·ì϶£¨CVE-2018-8034£©¡£Ä¿Ç°Ã»Óз¢ÏÖÈκÎÀûÓÃÕâЩ·ì϶µÄÊÂÎñ¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£
CVE-2018-8034
ÔÒòÔÚÓÚWebSocket¿Í»§¶ËʹÓÃTLSʱ¶ÌȱÖ÷»úÃûÑéÖ¤£¬²¢ÇÒÊÇĬÈÏÆôÓõġ£
Ó°Ïì°æ±¾£º
Apache Tomcat 9.0.0.M1 to 9.0.9
Apache Tomcat 8.5.0 to 8.5.31
Apache Tomcat 8.0.0.RC1 to 8.0.52
Apache Tomcat 7.0.35 to 7.0.88
½¨¸´½¨Ò飺
Éý¼¶ÖÁApache Tomcat 9.0.10 or later
Éý¼¶ÖÁApache Tomcat 8.5.32 or later
Éý¼¶ÖÁApache Tomcat 8.0.53 or later
Éý¼¶ÖÁApache Tomcat 7.0.90 or later
CVE-2018-8037
ÔÒòÔÚÓÚ¸ú×ÙÏνӹعØÊ±µÄÃýÎóµ¼ÖÂÔÚÐÂÏνÓÖгÁÓÃÓû§»á»°¡£
Ó°Ïì°æ±¾£º
Apache Tomcat 9.0.0.M9 to 9.0.9
Apache Tomcat 8.5.5 to 8.5.31
½¨¸´½¨Ò飺
Éý¼¶ÖÁApache Tomcat 9.0.10 or later
Éý¼¶ÖÁApache Tomcat 8.5.32 or later
CVE-2018-1336
ÔÒòÔÚÓÚÔÚÓµÓв¹³ä×Ö·ûµÄUTF-8½âÂëÆ÷Öв»ÕýÈ·µØ´¦ÖÃÒç³ö¿ÉÄܵ¼Ö½âÂëÆ÷ÖеÄÎÞÏÞÑ»·µ¼Ö»ؾø·þÎñ¡£
Ó°Ïì°æ±¾£º
Apache Tomcat 9.0.0.M9 to 9.0.7
Apache Tomcat 8.5.0 to 8.5.30
Apache Tomcat 8.0.0.RC1 to 8.0.51
Apache Tomcat 7.0.28 to 7.0.86
½¨¸´½¨Ò飺
Éý¼¶ÖÁApache Tomcat 9.0.7 or later
Éý¼¶ÖÁApache Tomcat 8.5.32 or later
Éý¼¶ÖÁApache Tomcat 8.0.52 or later
Éý¼¶ÖÁApache Tomcat 7.0.90 or later
½¨¸´½¨Òé
ASF¹Ù·½²¼¸üв¹¶¡£ºhttp://tomcat.apache.org/security-9.html£¬½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£
²Î¿¼Á´½Ó
http://tomcat.apache.org/security-9.html
https://thehackernews.com/2018/07/apache-tomcat-server.html


¾©¹«Íø°²±¸11010802024551ºÅ