×ðÁú¿­Ê±

֤ȯ¼ò³Æ£º×ðÁú¿­Ê± ֤ȯ´úÂ룺002212
È«Ììºò7x24Сʱ·þÎñ£º 400-777-0777

CactiÏÂÁîÖ´ÐÐÎó²îÆØ¹â £¬×ðÁú¿­Ê±ÎªÄúÌṩÃâ·ÑÅŲ鼯»®£¡

¿ËÈÕ £¬×ðÁú¿­Ê±°¢¶û·¨ÊµÑéÊÒ¼à²âµ½»¥ÁªÍøÉϹûÕæÐû²¼Á˹ØÓÚCacti±£´æÏÂÁîÖ´ÐÐÎó²îµÄÐÂÎÅ¡£¸ÃÎó²î±£´æÓÚ¡°remote_agent.php¡±ÎļþÖÐ £¬¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤¼´¿É»á¼û´ËÎļþ¡£

CactiÏÂÁîÖ´ÐÐÎó²îÆØ¹â £¬×ðÁú¿­Ê±ÎªÄúÌṩÃâ·ÑÅŲ鼯»®£¡

Ðû²¼Ê±¼ä£º2022-12-09
ä¯ÀÀ´ÎÊý£º3740
·ÖÏí£º

CactiÊÇÒ»Ì×»ùÓÚPHP £¬MySQL £¬SNMP¼°RRDTool¿ª·¢µÄ¿ªÔ´ÍøÂçÁ÷Á¿¼à²âͼÐÎÆÊÎö¹¤¾ß £¬ÌṩÁ˺ÜÊÇǿʢµÄÊý¾ÝºÍÓû§¹ÜÀí¹¦Ð§ £¬¿ÉÒÔÖ¸¶¨Ã¿Ò»¸öÓû§Éó²éÊ÷×´½á¹¹¡¢hostÒÔ¼°ÈκÎÒ»ÕÅͼ¡£

¿ËÈÕ £¬×ðÁú¿­Ê±°¢¶û·¨ÊµÑéÊÒ¼à²âµ½»¥ÁªÍøÉϹûÕæÐû²¼Á˹ØÓÚCacti±£´æÏÂÁîÖ´ÐÐÎó²îµÄÐÂÎÅ¡£¸ÃÎó²î±£´æÓÚ¡°remote_agent.php¡±ÎļþÖÐ £¬¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤¼´¿É»á¼û´ËÎļþ¡£¹¥»÷Õß¿ÉʹÓÃget_nfilter_request_var()º¯Êý¼ìË÷µÄ²ÎÊý$poller_id £¬À´Öª×ãpoller_item =POLLER_ACTION_SCRIPT_PHPÌõ¼þ £¬´¥·¢proc_open()º¯Êý £¬´Ó¶øµ¼ÖÂÏÂÁîÖ´ÐС£Îó²îʹÓÃÀֳɺó £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔÚÔËÐÐ Cacti µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë £¬ÆäΣº¦Ö®´ó £¬Ð§¹û²»¿°ÉèÏë £¬½¨Òé¿Í»§¾¡¿ì¿ªÕ¹×Բ鲢¸üÐÂÖÁ×îа汾»òÆôÓÃÇå¾²·À»¤²úÆ·ÒÔ·ÀÓùÎó²î¡£

Îó²îÐÅÏ¢

ÅŲéÒªÁìÒ»

ͨ¹ý×ðÁú¿­Ê±×Ô˳ӦÇå¾²·ÀÓùϵͳ´ÓÇå¾²ÔËÓªÊÓ½Ç×Ô¶¯»¯¹¹½¨Ö÷»ú×ʲúÖ¸ÎÆ¿â £¬¿ÉÖÜÈ«ÍøÂçWeb·þÎñ¡¢WebÓ¦Óá¢Web¿ò¼ÜµÈÐÅÏ¢ £¬¿ìËÙ¶¨Î»ÊÜÓ°ÏìÖ÷»ú¼°Cacti°æ±¾ £¬ÓÐÓÃÌáÉýÇå¾²Îó²îÏìӦЧÂÊ¡£

ÅŲéÒªÁì¶þ

×ðÁú¿­Ê±Å³ÈõÐÔɨÃèÓë¹ÜÀíϵͳ¼¯³Éϵͳ©ɨ¡¢Web©ɨ¡¢Êý¾Ý¿â©ɨ¡¢Èõ¿ÚÁî¼ì²â¡¢»ùÏߺ˲éµÈ¹¦Ð§ £¬¶ÔÐÅÏ¢×ʲú¾ÙÐÐÖÜÈ«µÄųÈõÐÔ¼ì²é £¬ÌṩרҵµÄÇå¾²ÆÊÎöºÍÐÞ²¹½¨Òé¡£

ÏÖÔÚ×ðÁú¿­Ê±Å³ÈõÐÔɨÃèÓë¹ÜÀíϵͳÒѽôÆÈ¸üÐÂCactiÎó²î¼ì²é²å¼þ £¬¿É½«Îó²î¹æÔò¿âÉý¼¶ÖÁvas-sys-v1.0-2022.12.08.tir°æ±¾ £¬Ï·¢É¨ÃèʹÃüºó¿ìËÙÅŲéCactiÎó²î¡£

ÐÞ¸´½¨Òé

1¡¢Çå¾²²¹¶¡

ÏÖÔÚCacti¹Ù·½ÒÑÐû²¼Çå¾²²¹¶¡ £¬µ«ÔÝδÐû²¼°æ±¾¸üР£¬½¨ÒéÊÜÓ°ÏìÓû§¹Ø×¢¹Ù·½¸üлò²Î¿¼¹Ù·½²¹¶¡´úÂë¾ÙÐÐÐÞ¸´£º

https://github.com/Cacti/cacti/commit/7f0e16312dd5ce20f93744ef8b9c3b0f1ece2216

https://github.com/Cacti/cacti/commit/b43f13ae7f1e6bfe4e8e56a80a7cd867cf2db52b

×¢ÖØ£º¹ØÓÚÔÚPHP<7.0ÏÂÔËÐеÄ1.2.xʵÀý £¬»¹ÐèÒª½øÒ»²½¸ü¸Ä£º

https://github.com/Cacti/cacti/commit/a8d59e8fa5f0054aa9c6981b1cbe30ef0e2a0ec9

2¡¢»º½â¼Æ»®

(1) ͨ¹ý¸üÐÂlib/functions.phpÖÐget_client_addrº¯Êý±ÜÃâÊÚÈ¨ÈÆ¹ý £¬¿É²Î¿¼¹Ù·½²¹¶¡´úÂë £»

(2) ͨ¹ý¸ü¸Äremote_agent.phpÎļþ±ÜÃâÏÂÁî×¢Èë £¬¼ìË÷$poller_id²ÎÊýʱʹÓÃget_filter_request_varº¯ÊýÈ¡´úget_nfilter_request_var£º

(3) ÔÚ²ÎÊý$poller_id´«Èëproc_open()º¯Êý֮ǰͨ¹ýescapeshellarg()º¯Êý¾ÙÐÐתÒ壺

²Î¿¼Á´½Ó£º

https://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf

½üÄêÀ´ £¬ÐÂÐÍWebÎó²îƵ·¢ £¬¹ØÓÚÔõÑùÔÚÕⳡ²î³ØµÈµÄ¹¥·ÀÕ½ÕùÖÐÌáÉý×Ô¶¯·ÀÓùÄÜÁ¦ £¬Ï¸¿ÅÁ£¶ÈµÄ×ʲú¹ÜÀíÓëÒ»Á¬µÄ¼ì²âÏìÓ¦Êǽ¹µãÒªº¦¡£

Ãâ ·Ñ ÊÔ ÓÃ

×ðÁú¿­Ê±×Ô˳ӦÇå¾²·ÀÓùϵͳÊÇÒ»¿î»ùÓÚ×Ô˳ӦÇå¾²¼Ü¹¹µÄÖ÷»úÇå¾²¸ÐÖª·À»¤Æ½Ì¨ £¬ÏµÍ³ÓɹܿØÖÐÐĺÍÇ徲̽ÕëAgent×é³É £¬¿É¿ìËÙ¹¹½¨Ö÷»úÇå¾²¸ÐÖª·À»¤Æ½Ì¨ £¬´ÓÕ¹Íû¡¢·ÀÓù¡¢¼ì²â¡¢ÏìÓ¦²ãÃæÖÜÈ«ÔöÇ¿Çå¾²¼à¿Ø¡¢Çå¾²ÆÊÎöºÍÏìÓ¦ÄÜÁ¦ £¬ÔÚ×ʲúÊáÀíµÄ»ù´¡ÉÏÌṩȫջ± £»¤ÄÜÁ¦ £¬ÓÐÓÃ×ÊÖú¿Í»§µÖÓù¸ß¼¶Íþв¹¥»÷ £¬ÖÜÈ«ÌáÉýÇå¾²ÔËÓªÄÜÁ¦¡£

2022Äê12ÔÂ9ÈÕ¡ª2023Äê3ÔÂ9ÈÕ

¡¸Ê¶±ð¶þάÂ롹

×ðÁú¿­Ê±×Ô˳ӦÇå¾²·ÀÓùϵͳ

ÂíÉÏÔ¤Ô¼ÊÔÓÃ~

TOPSEC

×÷ΪÖйúÍøÂçÇå¾²¡¢´óÊý¾ÝºÍÔÆ·þÎñÌṩÉÌ £¬×ðÁú¿­Ê±Ê¼ÖÕÒÔº´ÎÀÍøÂç¿Õ¼äÇ徲Ϊ¼ºÈÎ £¬Ò»Ö±ÍƳöÖª×ãÆóÒµ¿Í»§Çå¾²ÐèÇóµÄ²úÆ·Óë·þÎñ £¬Æð¾¢Ó¦¶ÔеÄÇå¾²ÍþвÓëÌôÕ½ £¬Îª°ü¹Ü¹ú¼ÒÍøÂç¿Õ¼äÇ徲Т˳ÆóÒµÁ¦Á¿¡£

Òªº¦´Ê±êÇ©£º
×ðÁú¿­Ê±°¢¶û·¨ÊµÑéÊÒ CactiÏÂÁîÖ´ÐÐÎó²î Ãâ·ÑÅŲ鼯»®
¿Í»§·þÎñÈÈÏß

400-777-0777
7*24Сʱ·þÎñ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
ÍøÕ¾µØÍ¼