CVE-2020-11996 | Apache Tomcat HTTP/2»Ø¾ø·þÎñ·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-06-290x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-11996 |
ʱ ¼ä |
2020-06-29 |
|
ÀàÐÍ |
DOS |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
Apache Tomcat 10.0.0-M1ÖÁ10.0.0-M5 Apache Tomcat 9.0.0.M1ÖÁ9.0.35 Apache Tomcat 8.5.0ÖÁ8.5.55 |
0x01 ·ì϶ÏêÇé
Apache TomcatÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿îÇáÁ¿¼¶WebÀûÓ÷þÎñÆ÷¡£¸Ã·¨Ê½ÊµÏÖÁ˶ÔServletºÍJavaServer Page£¨JSP£©µÄÖ§³Ö£¬ÊÇ¿ª·¢ºÍµ÷ÊÔJSP ·¨Ê½µÄÊ×Ñ¡¡£ApacheÖ»Ö§³Ö¾²Ì¬ÍøÒ³£¬µ«Ïñphp,cgi,jspµÈ¶¯Ì¬ÍøÒ³¾Í±ØÒªTomcatÀ´´¦Öá£
2020Äê6ÔÂ25ÈÕ£¬Apache¹Ù·½°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËÒ»¸öApache TomcatÖеÄHTTP/2»Ø¾ø·þÎñ·ì϶£¨CVE-2020-11996£©¡£¸Ã·ì϶ԴÓÚ¶ñÒâµÄHTTP/2ÒªÇóÐòÁпÉÄܻᵼÖ³¤´ï¼¸ÃëÖÓµÄCPU¸ßʹÓÃÂÊ£¬¹¥»÷Õßͨ¹ý·¢ËÍ´óÁ¿µÄ´ËÀàÒªÇóÀ´ÀûÓô˷ì϶£¬µ¼Ö·þÎñÆ÷»Ø¾øÏìÓ¦£¬´Ó¶øÊµÏÖDoS¹¥»÷¡£
0x02 ´ëÖý¨Òé
¸Ã·ì϶ӰÏìApache Tomcat 10.0.0-M1ÖÁ10.0.0-M5°æ±¾¡¢9.0.0.M1ÖÁ9.0.35°æ±¾ºÍ8.5.0ÖÁ8.5.55°æ±¾£¬¹Ù·½ÒѰ䲼×îа汾£¬ÇëÓйØÓû§ÊµÊ±Éý¼¶£¬ÏêÇéÈçÏ£º
1. Apache Tomcat 10.0.0-M1ÖÁ10.0.0-M5 °æ±¾µÄÓû§ÇëÉý¼¶µ½10.0.0-M6»ò¸ü¸ß°æ±¾£¬ÏÂÔØµØÖ·£ºhttps://tomcat.apache.org/download-10.cgi
2. Apache Tomcat 9.0.0.M1ÖÁ9.0.35 °æ±¾µÄÓû§ÇëÉý¼¶µ½9.0.36»ò¸ü¸ß°æ±¾£¬ÏÂÔØµØÖ·£ºhttps://tomcat.apache.org/download-90.cgi
3. Apache Tomcat 8.5.0ÖÁ8.5.55 °æ±¾µÄÓû§ÇëÉý¼¶µ½8.5.56»ò¸ü¸ß°æ±¾£¬ÏÂÔØµØÖ·£ºhttps://tomcat.apache.org/download-80.cgi
0x03 ÓйØÐÂÎÅ
https://www.tenable.com/cve/CVE-2020-11996
0x04 ²Î¿¼Á´½Ó
https://lists.apache.org/thread.html/r5541ef6b6b68b49f76fc4c45695940116da2bcbe0312ef204a00a2e0%40%3Cannounce.tomcat.apache.org%3E
http://mail-archives.us.apache.org/mod_mbox/www-announce/202006.mbox/%3Cfd56bc1d-1219-605b-99c7-946bf7bd8ad4%40apache.org%3E
0x05 ¹¦·òÏß
2020-06-25 Apache°ä²¼°²È«²¼¸æ
2020-06-29 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ