Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | OpenSSL CMSÄ£¿£¿éÕ»»º³åÇøÒç³öÎó²î |
CVE ID | CVE-2025-15467 |
Îó²îÀàÐÍ | Õ»»º³åÇøÒç³ö | ·¢Ã÷ʱ¼ä | 2026-1-30 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
OpenSSLÊÇÒ»¸öÆÕ±éʹÓõĿªÔ´¼ÓÃܿ⣬£¬£¬£¬£¬£¬ÌṩʵÏÖÇ徲ͨѶÐÒéµÄ¹¤¾ßºÍ¿â£¬£¬£¬£¬£¬£¬Ö§³Ö¶àÖÖ¼ÓÃÜËã·¨£¬£¬£¬£¬£¬£¬°üÀ¨¶Ô³Æ¼ÓÃÜ¡¢·Ç¶Ô³Æ¼ÓÃÜ¡¢¹þÏ£Ëã·¨ºÍÊý×ÖÖ¤Êé´¦Öóͷ£µÈ¡£¡£¡£¡£¡£ËüÊÇÐí¶à»¥ÁªÍøÐÒ飨ÈçSSL/TLS£©ºÍÓ¦ÓóÌÐòµÄ»ù´¡×é¼þ£¬£¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚWebЧÀÍÆ÷¡¢µç×ÓÓʼþ¡¢ÐéÄâ˽ÈËÍøÂ磨VPN£©µÈÁìÓò¡£¡£¡£¡£¡£OpenSSLÒÔÆä¸ßЧ¡¢ÎÞаºÍǿʢµÄ¹¦Ð§³ÉΪ¿ªÔ´¼ÓÃܽâ¾ö¼Æ»®µÄÐÐÒµ±ê×¼£¬£¬£¬£¬£¬£¬²¢Ìṩ¿ª·¢ÕßÓѺõÄAPI½Ó¿ÚÓÃÓÚ¼ÓÃܲÙ×÷ºÍÇ徲ͨѶ¡£¡£¡£¡£¡£
2026Äê1ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬ÈËÉú¾ÍÊDz©¼¯ÍÅVSRC¼à²âµ½OpenSSLÖеÄÒ»¸ö¸ßΣջ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬±£´æÓÚÆÊÎöCMS£¨¼ÓÃÜÐÂÎÅÓï·¨£©AuthEnvelopedData½á¹¹Ê±¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚOpenSSLÔÚ´¦Öóͷ£Ê¹ÓÃAEAD¼ÓÃÜËã·¨£¨ÈçAES-GCM£©µÄÐÂÎÅʱ£¬£¬£¬£¬£¬£¬Î´¶ÔASN.1²ÎÊýÖеijõʼ»¯ÏòÁ¿£¨IV£©³¤¶È¾ÙÐÐУÑ飬£¬£¬£¬£¬£¬Ö±½Ó½«Æä¸´ÖƵ½Àο¿¾ÞϸµÄÕ»»º³åÇøÖУ¬£¬£¬£¬£¬£¬µ¼ÖÂÕ»Òç³ö¡£¡£¡£¡£¡£ÓÉÓÚ¸ÃÀú³Ì±¬·¢ÔÚÉí·ÝÑéÖ¤ºÍÍêÕûÐÔУÑé֮ǰ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½á¹¹ÌØÖÆµÄ¶ñÒâCMSÐÂÎÅ£¬£¬£¬£¬£¬£¬Ê¹Ó󬳤IVÖµ´¥·¢Òç³ö¡£¡£¡£¡£¡£´ËÎó²î¿ÉÄܵ¼ÖÂЧÀÍÍ߽⣬£¬£¬£¬£¬£¬´Ó¶øÒý·¢¾Ü¾øÐ§ÀÍ£¨DoS£©¹¥»÷£¬£¬£¬£¬£¬£¬ÉõÖÁÔÚijЩÇéÐÎÏ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÕ»Òç³öʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/openssl/openssl/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2025-15467/https://openssl-library.org/news/secadv/20260127.txt/