BIND»º³åÇøÒç³ö©¶´£¨CVE-2021-25216£©
Ðû²¼Ê±¼ä 2021-04-300x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-25216 | ʱ ¼ä | 2021-04-30 |
Àà ÐÍ | »º³åÇøÒç³ö | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ©¶´ÏêÇé
BIND£¨Berkeley Internet Name Domain£¬²®¿ËÀûÒòÌØÍøÃû³ÆÓò£©·þÎñÊÇÈ«Çò·¶Î§ÄÚʹÓÃ×î¹ã·º¡¢ ×îÄþ¾²¿É¿¿ÇÒ¸ßЧµÄÓòÃû½âÎö·þÎñ·¨Ê½¡£
2021Äê04ÔÂ28ÈÕ£¬ISCÐû²¼Äþ¾²Í¨¸æ£¬¹ûÈ»ÁËBINDÖеÄÒ»¸ö»º³åÇøÒç³ö©¶´£¨CVE-2021-25216£©£¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1¡£¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´´¥·¢»º³åÇøÒç³ö£¬×îÖÕµ¼Ö·þÎñÆ÷±ÀÀ£»òÔ¶³Ì´úÂëÖ´ÐС£
©¶´Ï¸½Ú
¸Ã©¶´´æÔÚÓÚBINDʹÓõÄSPNEGOÖУ¬Èç¹ûBIND·þÎñÆ÷ÅäÖÃΪʹÓÃGSS-TSIG¹¦Ð§£¬Ôò´æÔÚ´Ë©¶´¡£GSS-TSIGÊǶÔTSIGÐÒéµÄÀ©Õ¹£¬Ö¼ÔÚÖ§³ÖÄþ¾²½»»»ÃÜÔ¿£¬ÓÃÓÚÑéÖ¤ÍøÂçÉϸ÷·½Ö®¼äͨÐŵÄÕæÊµÐÔ£¬SPNEGOÊÇGSSAPIʹÓõÄÒ»ÖÖÐÉÌ»úÖÆ£¬ÊÇGSS-TSIGµÄÓ¦ÓÃÐÒé½Ó¿Ú¡£
BINDĬÈÏÅäÖò»»á̻¶Ò×Êܹ¥»÷µÄ´úÂë·¾¶£¬µ«Í¨¹ýÉèÖÃtkey-gssapi-keytab»òtkey-gssapi-credentialÅäÖÃÑ¡ÏîµÄÖµ£¬¿ÉÒÔʹ·þÎñÆ÷Êܵ½¹¥»÷¡£´ËÍ⣬GSS-TSIG¾³£±»ÓÃÓÚBINDÓëSamba¼¯³ÉµÄÍøÂçÖУ¬ÒÔ¼°BIND·þÎñÆ÷ÓëActive DirectoryÓò¿ØÖÆÆ÷½áºÏµÄ»ìºÏ·þÎñÆ÷»·¾³ÖУ¬ÕâÖÖ»·¾³ÏµÄISC SPNEGOÈÝÒ×Êܵ½Õë¶Ô´Ë©¶´µÄ¹¥»÷£¬¾ßÌåÓ°ÏìÈ¡¾öÓÚBINDËùʹÓõÄCPU¼Ü¹¹£º
Named£¨64룩£ºCVSSÆÀ·Ö7.4£¬´Ë©¶´¿É´¥·¢»º³åÇøÒç³ö£¬´Ó¶øµ¼Ö·þÎñÆ÷Í߽⡣
Named£¨32룩£ºCVSSÆÀ·Ö8.1£¬´Ë©¶´¿É´¥·¢»º³åÇøÒç³öµ¼Ö·þÎñÆ÷Í߽⣬²¢Ô¶³ÌÖ´ÐдúÂë¡£
Ó°Ï췶Χ
BIND 9.5.0 - 9.11.29
BIND 9.12.0- 9.16.13
BINDÖ§³ÖµÄÔ¤ÀÀ°æ9.11.3-S1 - 9.11.29-S1ºÍ 9.16.8-S1 - 9.16.13-S1
ÒÔ¼°BIND 9.17·ÖÖ§¿¯ÐаæBIND 9.17.0 - 9.17.1¡£
0x02 ´¦Öý¨Òé
Ŀǰ´Ë©¶´ÒѾÐÞ¸´£¬½¨ÒéÉý¼¶µ½ÒÔϰ汾£º
BIND 9.11.31
BIND 9.16.15
BINDÖ§³ÖµÄÔ¤ÀÀ°æ£¨ÊÊÓÃÓÚÇкÏÌõ¼þµÄISCÖ§³Ö¿Í»§£©£º
BIND 9.11.31-S1
BIND 9.16.15-S1
½â¾öÒªÁ죺
´Ë©¶´½öÓ°ÏìÅäÖÃΪʹÓÃGSS-TSIGµÄ·þÎñÆ÷£¬¿ÉÒÔͨ¹ýÑ¡Ôñ²»ÆôÓÃGSS-TSIG¹¦Ð§À´ÖÆÖ¹¸Ã©¶´¡£
ÔÚ2021Äê4ÔµÄBINDÐû²¼Ö®ºó£¬ËùÓÐÖ§³ÖµÄ·ÖÖ§¶¼É¾³ýÁËisc-spnego£¬ÒÔÖÆÖ¹´Ë©¶´£¬µ«ÐèҪϵͳʹÓÃÆäËü¿âºÍÍ·ÎļþÀ´Ö§³ÖGSS-TSIG¹¦Ð§£¬³ý·ÇÔÚÑ¡Ôñ¹¹½¨Ñ¡ÏîʱÏò./configure½Å±¾Ìṩ--without-gssapi²ÎÊýÀ´½ûÓÃÕâÖÖ¹¦Ð§¡£
ÏÂÔØÁ´½Ó£º
https://gitlab.isc.org/isc-projects/bind9/-/blob/v9_11_31/HISTORY.md
https://gitlab.isc.org/isc-projects/bind9/-/blob/v9_16_15/HISTORY.md
0x03 ²Î¿¼Á´½Ó
https://kb.isc.org/docs/cve-2021-25216
https://us-cert.cisa.gov/ncas/current-activity/2021/04/29/isc-releases-security-advisory-bind
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25216
0x04 ʱ¼äÏß
2021-04-28 ISCÐû²¼Äþ¾²Í¨¸æ
2021-04-30 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/