Linux KDE 4ºÍ5ÏÂÁî×¢Èë0dayÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-08-08? Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
? Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
KDE Frameworks 5.60.0¼°¸üµÍ°æ±¾
? Îó²î¸ÅÊö
Çå¾²Ñо¿Ô±Dominik PennerÅû¶Linux KDEÖеÄÒ»¸öÉÐδÐÞ¸´µÄ0day£¬¹¥»÷Õß¿Éͨ¹ýÓÕʹÓû§ÏÂÔØÏ¢ÕùѹËõ¶ñÒâ.desktopºÍ.directoryÎļþÔÚÓû§µÄÅÌËã»úÉϾ²Ä¬Ö´ÐÐí§Òâ´úÂ룬ÉõÖÁÎÞÐèÓû§ÏÖʵ·¿ª¸ÃÎļþ¡£¸ÃÎó²îÓ°ÏìÁËKDE°æ±¾4ºÍ5£¬ÏÕЩËùÓеÄLinux¿¯Ðа涼±»²¨¼°¡£
KDE4/5Ò×ÊÜKDesktopFile ÀàÖÐÒ»¸öÏÂÁî×¢ÈëÎó²îµÄ¹¥»÷¡£µ±ÊµÀý»¯.desktop »ò .directory Îļþʱ£¬ËüÒÔ²»Çå¾²µÄ·½·¨Í¨¹ý KConfigGruop::readEntry()º¯ÊýʹÓà KConfigPrivate::expandString() ÆÀ¹ÀÇéÐαäÁ¿ºÍ shell À©Õ¹¡£Í¨¹ýÒ»¸öÌØÊâ½á¹¹µÄ.desktopÎļþ£¬Ô¶³ÌÓû§ÔÚÎļþÖÎÀíÆ÷ÖÐÏÂÔØ²¢Éó²éÎļþ£¬»òÕß½«Á´½ÓÍÏ×§µ½Îĵµ»ò×ÀÃæÉϼ´¿ÉÔâ¹¥ÏÝ¡£
.desktopºÍ.directory ÎļþÓÃÀ´ÉèÖÃÓ¦ÓúÍÎļþ¼ÐµÄÏÔʾ·½·¨¡£.desktop ÎļþÓÃÓÚÔÚKDEĿ¼ÖÐ×¢²áÓ¦Ó㬶ø.directory ÎļþÓÃÓÚ˵Ã÷ KDE Ó¦¸ÃÔõÑùÏÔʾÎļþ¼Ð¡£¹ØÓÚWindows Óû§¶øÑÔ£¬.directoryÎļþ¾ÍÀàËÆÓÚdesktop.ini Îļþ¡£Ã¿·ÝÎļþÖж¼ÓÐÖÖÖÖ×ֶΣ¬¼û¸æ×ÀÃæÇéÐÎÔõÑùÏÔʾĿ¼»òÓ¦Óá£ÆäÖÐÒ»¸ö×Ö¶ÎÊÇ¡°Icon¡±£¬ÔÚ.desktop ÎļþÖÐËüÖ¸¶¨ÁËKDE Ó¦¸ÃÔÚĿ¼ÖÐչʾµÄͼ±ê·¾¶£¬¶ø¹ØÓÚ.directory Îļþ¶øÑÔ£¬Ëü½«Ö¸¶¨ÔÚ Dolphin Éó²éÎļþ¼ÐʱËùʹÓõÄͼ±ê¡£
ÎÊÌâÔÚÓÚKDEÔÊÐíʹÓÃshellÀ©Õ¹Í¨¹ýij¸öÇéÐαäÁ¿»òÖ´ÐÐÏÂÁîµÄ·½·¨¶¯Ì¬µØÌìÉúÕâЩ×ֶεÄÖµ¡£ÓÉÓÚÔÚDolphin»ò´ÓDesktopÉó²éÎļþʱ£¬ËüÃǻᱻ×Ô¶¯¶ÁÈ¡£¬Òò´ËËü¿Éµ¼Ö¹¥»÷Õ߽ṹ¶ñÒâ.desktopºÍ.directory Îļþ¼Ð£¬Ö´ÐÐλÓÚ¡°Icon¡±×Ö¶ÎÖеÄÏÂÁî¡£
? Îó²îÑéÖ¤
PennerÐû²¼ÁËÎó²îʹÓôúÂ룺https://gist.githubusercontent.com/zeropwn/630832df151029cb8f22d5b6b9efaefb/raw/64aa3d30279acb207f787ce9c135eefd5e52643b/kde-kdesktopfile-command-injection.txt¡£
? ÐÞ¸´½¨Òé
Ñо¿Ö°Ô±ÔÚÐû²¼ÏêϸÐÅÏ¢ºÍPoCÎó²î֮ǰûÓÐÏòKDE¿ª·¢Ö°Ô±±¨¸æÎó²î£¬KDEÉçÇøÈÏ¿ÉÎó²î²¢ÏòÓû§°ü¹ÜÐÞ¸´ÊÂÇéÕýÔÚ¾ÙÐÐÖС£
Penner½¨ÒéÓû§¼ì²éËùÓÐ.desktop »ò .directory Îļþ²¢½ûÓÃí§Ò⶯̬ÌõÄ¿¡£
? ²Î¿¼Á´½Ó
https://www.bleepingcomputer.com/news/security/zero-day-bug-in-kde-4-5-executes-commands-by-opening-a-folder/


¾©¹«Íø°²±¸11010802024551ºÅ