OpenBSD¶à¸öÇå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2019-12-06

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-19521£¬£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-19520£¬£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-19522£¬£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-19519£¬£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


OpenBSD 6.5

OpenBSD 6.6


Îó²î¸ÅÊö


OpenBSDÊǼÓÄôóOpenBSDÏîÄ¿×éµÄÒ»Ì×¿çÆ½Ì¨µÄ¡¢»ùÓÚBSDµÄÀàUNIX²Ù×÷ϵͳ£¬£¬£¬£¬ £¬£¬£¬±£´æÈçÏÂËĸö¸ßΣÇå¾²Îó²î£º

CVE-2019-19521£ºÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õ߿ɽèÖú-schallengeÓû§ÃûʹÓøÃÎó²îÈÆ¹ýÉí·ÝÑéÖ¤¡£¡£¡£ ¡£¡£¡£


CVE-2019-19520£ºxlockÖеÄÍâµØÌáȨÎó²î£¬£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÔ´ÓÚxenocara/lib/mesa/src/loader/loader.cÎļþûÓÐ׼ȷ´¦Öóͷ£dlopen¡£¡£¡£ ¡£¡£¡£ÍâµØ¹¥»÷Õß¿Éͨ¹ýÌá½»LIBGL_DRIVERS_PATHÇéÐαäÁ¿Ê¹ÓøÃÎó²î»ñÈ¡¡°auth¡±×éµÄȨÏÞ¡£¡£¡£ ¡£¡£¡£


CVE-2019-19522£º¾­ÓÉS/KeyºÍYubiKeyµÄÍâµØÌáȨÎó²î£¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚ¶Ôͨ¹ý·ÇĬÈÏÉèÖá°S/Key¡±ºÍ¡°YubiKey¡±µÄÊÚȨ»úÖÆ²Ù×÷²»×¼È·£¬£¬£¬£¬ £¬£¬£¬Òò´Ë¾ßÓС°auth¡±×éȨÏÞµÄÍâµØ¹¥»÷ÕßÄܹ»»ñÈ¡ root Óû§µÄÍêÕûȨÏÞ¡£¡£¡£ ¡£¡£¡£


CVE-2019-19519£ºsu ÖеÄÍâµØÌáÈ¡Îó²î£¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚ su µÄÆäÖÐÒ»¸öÖ÷Òªº¯ÊýÖб£´æÒ»¸öÂß¼­¹ýʧ£¬£¬£¬£¬ £¬£¬£¬µ¼ÖÂÍâµØ¹¥»÷ÕßÄܹ»Í¨¹ýʹÓà su µÄ¨CL Ñ¡ÏîʵÏÖí§ÒâÓû§µÄµÇ¼Àࣨͨ³£²»°üÀ¨ root£©¡£¡£¡£ ¡£¡£¡£ÍâµØ¹¥»÷ÕßÄܹ»Ê¹Óà su µÄ¨CL Ñ¡Ï¡°Ò»Ö±Ñ­»·£¬£¬£¬£¬ £¬£¬£¬Ö±µ½ÊäÈë׼ȷµÄÓû§ÃûÃÜÂë×éºÏΪֹ¡±£©ÒÔ×Ô¼ºµÄÉí·ÝµÇ¼µ«Ê¹ÓõÄÊÇÆäËüÓû§µÄµÇ¼ÀࣨÈôÊǹ¥»÷Õß²»ÔÚ¡°wheel¡±×éÖÐÔòÊÇrootµÄµÇ¼Àࣩ£¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚ¸ÃÀà±äÁ¿Ö»ÉèÖÃÒ»´Î²¢ÇÒ²»»áÖØÖᣡ£¡£ ¡£¡£¡£


Îó²îÑéÖ¤


POC£ºhttps://www.qualys.com/2019/12/04/cve-2019-19521/authentication-vulnerabilities-openbsd.txt?_ga=2.58244398.587934852.1575530822-682141427.1570559125¡£¡£¡£ ¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬ £¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://www.openbsd.org/errata66.html¡£¡£¡£ ¡£¡£¡£


²Î¿¼Á´½Ó


https://thehackernews.com/2019/12/openbsd-authentication-vulnerability.html