OPENWRT/LEDEÔ¶³Ì´úÂëÖ´ÐÐÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-03-25

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-7982£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º8.1


Ó°Ïì°æ±¾


OPENWRT 18.06.0µ½18.06.6°æ±¾ÒÔ¼°OPENWRT 19.07.0°æ±¾

»ùÓÚOPENWRT¹Ì¼þÖÆ×÷µÄLEDE¹Ì¼þ 17.01.0µ½17.01.7 °æ±¾

½ÏÁ¿ÀϵÄÒѾ­²»ÊÜÖ§³ÖµÄ°æ±¾ÀýÈçOPENWRT 15.05 ÒÔ¼°LEDE 17.01 ÊÜÎó²îÓ°ÏìÇÒ²»ÊÜÖ§³ÖÎÞ·¨ÐÞ¸´


Îó²î¸ÅÊö


OpenWrtÊÇÒ»Ì×Õë¶ÔǶÈëʽװ±¸µÄLinux²Ù×÷ϵͳ¡£


OPENWRT¹Ì¼þʹÓõİüÆÊÎöÖÎÀíÆ÷OPKG FORK±£´æÂß¼­¹ýʧ£¬ÖÎÀíÆ÷ºöÂÔÁËÊðÃû¿âÖаüÀ¨µÄSHA-256УÑéÖµ¡£ÕâÒâζ×ÅÖ±½Óͨ¹ýÖÎÀíÆ÷×°Öà IPKÀëÏß×°ÖðüʱÊDz»¾­ÓÉУÑéµÄ£¬¶ø¹¥»÷ÕßÔò¿ÉÒÔʹÓÃÕâ¸öÎó²î×°ÖÃΣÏÕµÄÄÚÈÝ¡£ÓÉÓÚ°üÆÊÎöÖÎÀíÆ÷×Ô¼ºÊÇÒÔROOTȨÏÞÔËÐеÄÒò´ËȨÏÞºÜÊǸߣ¬ÆäȨÏÞ¿ÉÒÔÕë¶ÔÕû¸öÎļþϵͳ²»»áÊܵ½È¨ÏÞÖÎÀí¡£¹¥»÷ÕßÈôÊÇͨ¹ýαÔìµÄ·½·¨×°ÖþßÓжñÒâ´úÂëµÄ .IPK×°ÖðüÔò¿ÉÒÔ»ñµÃROOTȨÏÞ£¬½ø¶øÒ²¿ÉÒÔ¿ØÖÆÕû¸ö·ÓÉÆ÷¡£


ΪÁËʹÓôËÎó²î£¬¹¥»÷ÕßÐèÒª·¢¶¯ÖÐÐÄÈ˹¥»÷ (MITM)£¬ÌṩÓÐÓÃÇÒÒÑÊðÃûµÄ°üË÷Òý£¨ÀýÈ磬´Ódownloads.openwrt.or g»ñµÃµÄË÷Òý£©ºÍÒ»¸ö»ò¶à¸ö¾ßÓÐÓë´æ´¢¿âË÷ÒýÖÐÖ¸¶¨µÄÏàͬ¾ÞϸµÄαÔì.ipk°ü£¬Í¬Ê±ÔÚÊܺ¦ÏµÍ³ÉÏŲÓá°opkg install¡±ÏÂÁî¡£


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼OpenWrtа汾£¬Á´½Ó£ºhttps://openwrt.org/advisory/2020-01-31-1¡£

»òÕߣ¬ÒªÔÚ²»Éý¼¶Õû¸ö¹Ì¼þµÄÇéÐÎϸüÐÂopkg°ü×Ô¼º£¬¿ÉÒÔÔÚ¸üÐÂËùÓд洢¿âºóʹÓÃÒÔÏÂÏÂÁ

cd /tmp

opkg update

opkg download opkg

zcat ./opkg-lists/openwrt_base | grep -A10 "Package: opkg" | grep SHA256sum

sha256sum ./opkg_2020-01-25-c09fe209-1_*.ipk

½ÏÁ¿Á½¸öУÑéºÍ£¬ÈôÊÇÆ¥Å䣬¼ÌÐø×°ÖóÌÐò°ü£º

opkg install ./opkg_2020-01-25-c09fe209-1_*.ipk


²Î¿¼Á´½Ó


https://openwrt.org/advisory/2020-01-31-1