VxWorks¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Ðû²¼Ê±¼ä 2019-07-31

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


1¡¢Åä¾°ÐÎò


Çå¾²Ñо¿Ö°Ô±ÔÚVxWorksÖз¢Ã÷ÁË11¸ö0dayÎó²î£¬£¬VxWorksÊÇǶÈëʽװ±¸ÖÐʹÓÃ×îÆÕ±éµÄʵʱ²Ù×÷ϵͳ£¨RTOS£©Ö®Ò»£¬£¬ÆÕ±éÓ¦ÓÃÓÚº½¿Õº½Ì죬£¬¹ú·À£¬£¬¹¤Òµ£¬£¬Ò½ÁÆ£¬£¬Æû³µµÈÁìÓò£¬£¬È«ÇòÖÁÉÙ20ÒŲ́װ±¸Ê¹ÓÃʹÓÃVxWorks¡£¡£¡£ÕâЩÎó²î±»Í³³ÆÎªURGENT/11£¬£¬ÓÉÓÚËüÃǹ²ÓÐ11¸ö£¬£¬ÆäÖÐ6¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£

VxWorksÓÃ;ºÜÊÇÆÕ±é£¬£¬ÀýÈçÍøÂçÉãÏñÍ·£¬£¬ÍøÂç½»Á÷»ú£¬£¬Â·ÓÉÆ÷£¬£¬·À»ðǽ£¬£¬VOIPµç»°£¬£¬´òÓ¡»úºÍÊÓÆµ¾Û»á²úÆ·£¬£¬ÒÔ¼°½»Í¨Ñ¶ºÅµÆ¡£¡£¡£³ý´ËÖ®Í⣬£¬VxWorks»¹±»Ö÷ҪϵͳʹÓ㬣¬ÀýÈçSCADA£¬£¬»ð³µ£¬£¬µçÌݺ͹¤Òµ¿ØÖÆÆ÷£¬£¬²¡È˼໤ÒÇ£¬£¬ºË´Å¹²Õñ³ÉÏñÒÇÆ÷£¬£¬ÎÀÐǵ÷ÖÆ½âµ÷Æ÷£¬£¬ÉõÖÁÊÇ»ðÐÇ̽²âÆ÷¡£¡£¡£

2¡¢Îó²îÏêÇé


URGENT/11Îó²îÓ°Ïì×Ô6.5°æÒÔÉϵÄËùÓÐVxWorks°æ±¾¡£¡£¡£ÏÔÈ»ÔÚÒÑÍù13ÄêÖÐÐû²¼µÄËùÓÐVxWorks°æ±¾¶¼ÈÝÒ×Êܵ½¹¥»÷¡£¡£¡£

ÆäÖÐ6¸öÎó²î¿É´¥·¢Ô¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷£¬£¬¶øÊ£ÏµÄÎó²î¿ÉÄܻᵼÖ¾ܾøÐ§ÀÍ£¬£¬ÐÅϢй¶»òÂß¼­Îó²î¡£¡£¡£

Ô¶³ÌÖ´ÐдúÂëȱÏÝ£º


ÆÊÎöIPv4Ñ¡Ïîʱ¿ÍÕ»Òç³ö£¨CVE-2019-12256£©


ÓÉÓÚ¹ýʧ´¦Öóͷ£TCPµÄÖ¸Õë×ֶζøµ¼ÖµÄËĸöÄÚ´æËð»µÎó²î£¨CVE-2019-12255£¬£¬CVE-2019-12260£¬£¬CVE-2019-12261£¬£¬CVE-2019-12263£©


ipdhcpcÖеÄDHCP Offer / ACKÆÊÎöÖеĶÑÒç³ö£¨CVE-2019-12257£©

DoS£¬£¬ÐÅÏ¢×ß©ºÍÂß¼­È±ÏÝ£º


ͨ¹ýÃûÌùýʧµÄTCPÑ¡Ïî¾ÙÐÐTCPÅþÁ¬DoS£¨CVE-2019-12258£©


´¦Öóͷ£Î´¾­ÇëÇóµÄ·´ÏòARP»Ø¸´£¨Âß¼­È±ÏÝ£©£¨CVE-2019-12262£©


ipdhcpc DHCP¿Í»§¶Ë·ÖÅÉIPv4µÄÂß¼­È±ÏÝ£¨CVE-2019-12264£©


ÔÚIGMPÆÊÎöÖÐͨ¹ýNULLɨ³ýÒýÓõÄDoS£¨CVE-2019-12259£©


IGMPÐÅÏ¢×ß©ͨ¹ýIGMPv3ÌØ¶¨³ÉÔ±±¨¸æ£¨CVE-2019-12265£©

3¡¢ÐÞ¸´½¨Òé


VxWorksÒÑÌṩ²¹¶¡¸üУ¬£¬¿ÉÔÚVxWorksÇå¾²ÖÐÐÄÐû²¼µÄWind River Security AlertÖÐÕÒµ½£º


https://www.windriver.com/security/
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/

4¡¢²Î¿¼Á´½Ó


https://www.windriver.com/security/
https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
https://www.sonicwall.com/support/product-notification/?sol_id=190717234810906
https://security.business.xerox.com/en-us/