Apache Tomcat HTTP/2»Ø¾ø·þÎñ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-26

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºcve-2019-0199 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ7.5 £¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Apache Tomcat 9.0.0.M1 ÖÁ 9.0.14

Apache Tomcat 8.5.0 ÖÁ 8.5.37


·ì϶¸ÅÊö


Apache Tomcat¹Ù·½Åû¶ÁË¡ª¸öHTTP/2µÄDoS·ì϶ £¬¸Ã·ì϶ϵHTTP/2ÔڽӹܹýÁ¿SETTINGS FrameÁ÷Êý¾ÝʱÔÊÐí¿Í»§¶ËÔÚ²»¶Á£¯Ð´ÒªÇó£¯ÏìÓ¦Êý¾ÝµÄÇé¿öÏÂÒÀȻά³ÖÁ÷´ò¿ª×´Ì¬ £¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶´Ó¿Í»§¶ËÌáÒé´óÁ¿µÄopen streamÒªÇó´Ó¶ø×èÈû·þÎñÆ÷¶ËµÄÏß³Ì £¬ÒýÆð·þÎñÆ÷¶ËÏß³Ì×ÊÔ´ºÄ¾¡´Ó¶øµ¼Ö·þÎñ²»³ÉÓà ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC¡¢EXP

²é¿´Apache Tomcat¶ÔÓ¦µÄ°æ±¾ºÅÊÇ·ñÔÚÊÜÓ°Ïì°æ¼¼ÇÉÓòÄÚ ¡£


½¨¸´½¨Òé


Ŀǰ·ì϶ϸ½ÚÒѾ­Åû¶ £¬¹Ù·½Ò²ÔÚApache Tomcat 9.0.16¡¢Apache Tomcat8.5.38¼°ÒÔÀ´°æ±¾½¨¸´ÖÐÓèÒÔ½¨¸´ ¡£
http://tomcat.apache.org/security-9.html

http://tomcat.apache.org/security-8.html


²Î¿¼Á´½Ó


https://www.mail-archive.com/dev@tomcat.apache.org/msg132386.html