Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article?

Amazon Web Services ããã° ããã»ããµã®ææ©çå®è¡ã«é¢ãã調æ»ã®å ¬éã«ã¤ã㦠ãæ¥æ¬èªè¨³ãæ¥æ¬æé 2018å¹´02æ14æ¥19:30 é¢é£ãã CVE: CVE-2017-5715, CVE-2017-5753, CVE-2017-5754 æ¥æ¬æé 2018å¹´02æ06æ¥09:30 以ä¸ã¯æ¬ä»¶ã«é¢ããã¢ãããã¼ãã§ãã Amazon Linux ç¨ã®æ´æ°ãããã«ã¼ãã«ã¯ãAmazon Linux ã®ãªãã¸ããªã«ã¦å ¥æã§ãã¾ãã2018å¹´1æ13æ¥ä»¥éã«ããã©ã«ãã® Amazon Linux è¨å®ã§èµ·åããã EC2 ã¤ã³ã¹ã¿ã³ã¹ã«ã¯èªåçã«ææ°ã®ããã±ã¼ã¸ãå«ã¾ãã¦ãã¾ãã ææ°ã®ããã±ã¼ã¸ã§ã¯ã CVE-2017-5715 ã«å¯¾å¦ããããã®å®å®çãªã¼ãã³ã½ã¼ã¹ Linux ã»ãã¥ãªãã£ã®æ¹åãã«ã¼ãã«å ã«çµã¿è¾¼ã¾ãã¦ãã¾ããã¾ã 以ååãè¾¼ã¾ãã CVE-2017-
2018å¹´1æ3æ¥ã«CPUã«é¢é£ãã3ã¤ã®èå¼±æ§æ å ±ãå ¬éããã¾ãããå ±åè ã«ããã¨ãããã®èå¼±æ§ã¯MeltdownãSpectreã¨å¼ç§°ããã¦ãã¾ããããã§ã¯é¢é£æ å ±ãã¾ã¨ãã¾ãã èå¼±æ§ã®æ¦è¦ å ±åè ãèå¼±æ§æ å ±ã次ã®å°ç¨ãµã¤ãã§å ¬éããã Meltdown and Spectre (ã¾ãã¯ãã¡ã) 3ã¤ã®èå¼±æ§ã®æ¦è¦ãã¾ã¨ããã¨æ¬¡ã®éãã èå¼±æ§ã®å称 Meltdown Spectre CVE CVE-2017-5754ï¼Rogue data cache loadï¼ CVE-2017-5753ï¼Bounds check bypassï¼ CVE-2017-5715ï¼Branch target injectionï¼ å½±é¿ãåããCPU Intel IntelãAMDãARM CVSSv3 åºæ¬å¤ 4.7(JPCERT/CC) 5.6(NIST) âã«åã PoC å ±åè éå ¬é è«æä¸ã«x
ã¾ãOGNL絡ã¿ã®èå¼±æ§ãè¦ã¤ããã¾ããã ã¢ã¦ãã©ã¤ã³ã¯id:Kangoæ°ãã¾ã¨ãã¦ãããã¡ããåèã«ãªãã¾ãã http://d.hatena.ne.jp/Kango/20170307/1488907259 ãã¦ããã®èå¼±æ§ã®åä½åçã調ã¹ã¦ã¿ã¾ããã ãã¡ã¤ã«ã¢ãããã¼ãæã®ãããã®å¦çæ¹å¼ã«åé¡ãããããã§ãã åè¿°ã®URLã§è¿°ã¹ããã¦ããPoCã¯ãããªæãã import requests import sys def poc(url): payload = "%{(#test='multipart/form-data').(#[email protected]text@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context['com.opensymphony.xwork2.
OpenSSL 1.1.0a ããåã®ãã¼ã¸ã§ã³ OpenSSL 1.0.2i ããåã®ãã¼ã¸ã§ã³ OpenSSL 1.0.1u ããåã®ãã¼ã¸ã§ã³ OpenSSL ã¯ã次ã®è¤æ°ã®èå¼±æ§ããã³å¦çãä¿®æ£ããã¢ãããã¼ãããªãªã¼ã¹ãã¾ããã OCSP Status Request ã«ãµã¼ãã¹éç¨å¦¨å®³ (DoS) - CVE-2016-6304 (éè¦åº¦ï¼é«) SSL_peek() é¢æ°ã®å¼åºãå¦çã«ãµã¼ãã¹éç¨å¦¨å®³ (DoS) - CVE-2016-6305 (éè¦åº¦ï¼ä¸) ãããã¯é·ã 64bit ã®ãããã¯æå·ã«å¯¾ããèªçæ¥æ»æ (Sweet32) ã¸ã®ç·©åç - CVE-2016-2183 (éè¦åº¦ï¼ä½) MDC2_Update() é¢æ°ã®å¼åºãå¦çã«ãã¼ããã¼ã¹ã®ãããã¡ãªã¼ãã¼ããã¼ - CVE-2016-6303 (éè¦åº¦ï¼ä½) SHA512 ã使ç¨ããä¸æ£ãªå½¢å¼ã® TLS ã»ã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãç¥ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}