
ºóÃż¼Êõ·ÖÎö£º
CVE-2024-3094 ©¶´µÄºóÃÅÖÆÔìÕߣ¬ÔÚÉÏ´«µÄÍêÕû°æµÄÔ´´úÂëѹËõ°üÖУ¬°üº¬Ò»¸öBuild-to-Host.m4Îļþ£¨Õâ¸öÎļþ²»ÔÚgit²Ö¿âÖУ©£¬Èç¹ûͨ¹ýѹËõ°üÏÂÔØÔ´´úÂ룬»á´¥·¢ºóÃŹ¹½¨¹ý³Ì¡£
Build-to-Host.m4 ÎļþÖаüº¬£º
gl_[$1]config='sed"r\n" $gl_am_configmake | eval $gl_path_map | $gl[$1]_prefix -d 2>/dev/null'.
Ä¿µÄÊÇÔÚ xz-utils µÄ¹¹½¨¹ý³ÌÖÐÇÄÇÄ×¢ÈëÒ»¸ö»ìÏý½Å±¾£¬Õâ¸ö½Å±¾ÔÚ configure ½Å±¾µÄ×îºóÔËÐУ¬¸ºÔð´´½¨ xz-utils ºÍ liblzma µÄ MakeFiles¡£ÓÉÓÚÕâ¶Î´úÂëµÄ¸´ÔÓÐԺͻìÏýÐÔ£¬ËüÔö¼ÓÁËÑо¿ÈËÔ±·ÖÎö¹ý³ÌµÄÄѶȣ¬²¢Ê¹µÃºóÃŵļì²âºÍÀí½â¸ü¼ÓÀ§ÄÑ¡£
¾¹ýһЩÌõ¼þ
if ! (echo "$build" | grep -Eq "^x86_64"> /dev/null 2>&1) && (echo "$build" | grep -Eq"linux-gnu$" > /dev/null 2>&1); then
if test -f "$srcdir/debian/rules" || test "x$RPM_ARCH" = "xx86_64"; then
ÅжϺó£¬ÐÞ¸ÄliblzmaµÄMakeFile£¬ÒÔ¸ÉÔ¤ÆäÔËÐÐʱµÄ·ûºÅ½âÎö£¬½«RSA_public_decrypt·ûºÅÖØ¶¨Ïòµ½¶ñÒâºóÃÅ´úÂë¡£ÔÚsshdµÄ¹«Ô¿ÈÏÖ¤¹ý³ÌÖлáµ÷Óà RSA_public_decryptº¯Êý£¬´Ó¶øÖ´Ðй¥»÷ÕߵĴúÂë¡£Ëæºó£¬¸Ã´úÂë»Øµ÷libcrypto ÒÔ½øÐÐÕý³£ÈÏÖ¤£¬ÓпÉÄÜÈù¥»÷ÕßÔÚÌØ¶¨Ìõ¼þÏÂÈÆ¹ýÈÏÖ¤£¬µ¼ÖÂÒ×Êܹ¥»÷µÄ·þÎñPGµç¾º¹ÙÍøÉÏ·¢ÉúÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£
ÎÒÃÇ·¢ÏÖ£¬ºóÃŵÄ×÷ÕßΪÁ˸üÒþ±ÎʵÏÖºóÃÅ×¢È룬×öµ½ÁËÒÔÏÂÁ½µã£º
ÊÂǰ£º¶ñÒâ´úÂëÊÇ»ìÏýµÄ£¬Ö»ÄÜÔÚÍêÕûµÄÏÂÔØ°üÖÐÕÒµ½£¬¶ø²»ÄÜÔÚȱÉÙ M4 ºêµÄ Git ·¢ÐаæÖÐÕÒµ½£¬½µµÍÊÂǰ±»·¢ÏֵĿÉÄÜÐÔ¡£
ʺ󣺾ݱ¨µÀ£¬ºóÃŵÄ×÷Õß»¹Ïò oss-fuzz ÏîÄ¿Ìá½»ÁË´úÂ룬ÕâЩ´úÂë¿ÉÄÜרÃÅ×èÖ¹Á˸ÃÄ£ºýPGµç¾º¹ÙÍøÄܹ»¼ì²âµ½ËûÃÇÔÚxz-utils ÖÐÖ²ÈëµÄºóÃÅ£¬½µµÍʺ󱻼ì²é³öÀ´µÄ¿ÉÄÜÐÔ¡£
ͨ¹ýÕâ´ÎºóÃŵķÖÎö£¬¿ªÔ´Èí¼þµÄʹÓÃÕߣ¨¹¹½¨Õߣ©Ó¦¸ÃÌá¸ß°²È«Òâʶ£¬ÔÚ¹¹½¨Èí¼þ¹©Ó¦Á´°²È«¹ý³ÌÖУ¬²»ÄܺöÂÔÈκÎÒ»²½ÍêÕûÐÔУÑé¡£
KOSÒ»Ö±½«¿Í»§°²È«ºÍÊý¾Ý±£»¤·ÅÔÚÊ×λ¡£ÎÒÃdzÖÐø¼à¿Ø°²È«¶¯Ì¬£¬²¢²ÉȡһÇбØÒª´ëÊ©À´±£»¤ÎÒÃǵIJúÆ·ºÍ·þÎñ²»ÊÜÈκÎDZÔÚÍþвµÄÓ°Ïì¡£
ÎÒÃǵÄÍŶӽ«³ÖÐø¶ÔËùÓеÚÈý·½×é¼þ½øÐÐÑϸñµÄ°²È«ÉóºË£¬²¢ÔÚ±ØÒªÊ±¼°Ê±½øÐиüкÍÉý¼¶¡£Í¬Ê±£¬ÎÒÃÇÒ²½«¼ÌÐøÓ밲ȫÉçÇø½ôÃܺÏ×÷²ÎÓëÈí¼þ¹©Ó¦Á´°²È«½¨É裬ÒÔÈ·±£ÎÒÃÇÄܵÚһʱ¼äÁ˽ⲢӦ¶Ô¸÷ÖÖ°²È«ÌôÕ½¡£
¸ÐлÄú¶ÔÎÒÃǹ«Ë¾µÄÐÅÈκÍÖ§³Ö¡£Èç¹ûÄúÓÐÈκÎÒÉÎÊ»òÐèÒª¸ü¶àÐÅÏ¢£¬ÇëËæÊ±ÁªÏµÎÒÃǵĿͻ§·þÎñÍŶӡ£
²úÆ·ÏÂÔØ
²úÆ·¼¤»î
ÊÛǰ×Éѯ
ÊÛºó·þÎñ
»Øµ½¶¥²¿
ÊÛǰ×Éѯ
ÊÛºó·þÎñ