2024å¹´7æ1æ¥ãOpenSSHã®éçºãã¼ã ã¯æ·±å»ãªèå¼±æ§ CVE-2024-6387 ã確èªãããã¨ãã¦ã»ãã¥ãªãã£æ å ±ãçºåºããèå¼±æ§ãä¿®æ£ãããã¼ã¸ã§ã³ãå ¬éãã¾ããããã®èå¼±æ§ãçºè¦ããQualysã«ããã°ãæ¢å®è¨å®ã§æ§æãããsshdãå½±é¿ãåããã¨ãããå½±é¿ãåããã¨ã¿ãããã¤ã³ã¿ã¼ãããæ¥ç¶å¯è½ãªãã¹ããå¤æ°ç¨¼åãã¦ããç¶æ³ã«ããã¨å ±åãã¦ãã¾ããããã§ã¯é¢é£ããæ å ±ãã¾ã¨ãã¾ãã æ¦è¦ æ·±å»ãªèå¼±æ§ã確èªãããã®ã¯OpenSSHãµã¼ãã¼ï¼sshdï¼ã³ã³ãã¼ãã³ããèå¼±æ§ãæªç¨ãããå ´åãç¹æ¨©ã§ãªã¢ã¼ãããèªè¨¼ãªãã®ä»»æã³ã¼ãå®è¡ããããæããããã æªç¨ã«ãããå ±åãªã©ã¯å ¬è¡¨æç¹ã§ããã¦ããªãããglibcãã¼ã¹ã®Linuxã«ããã¦æ»æãæåãããã¨ãæ¢ã«å®è¨¼ãããã¦ãããçºè¦è ã®Qualysã¯ãã®èå¼±æ§ã®å®è¨¼ã³ã¼ããå ¬éããªãæ¹éã¨ãã¦ããããã¤ã³ã¿ã¼ãããä¸ã§ã¯PoC
{{#tags}}- {{label}}
{{/tags}}