Exim Mail Server 5Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2021-05-070x00 ©¶´¸ÅÊö
EximÊÇÓɽ£ÇÅ´óѧ¿ª·¢µÄÏûÏ¢´«ÊäÊðÀí£¨MTA£©£¬Ö÷Òª±»¹¹½¨ÔÚÀàUnix²Ù×÷ϵͳÉÏ·¢ËͺͽÓÊÕµç×ÓÓʼþ¡£ºÃ±È£¬ËüÒÑԤװÔÚLinux¿¯Ðа棨ÈçDebian£©ÉÏ¡£Exim¿ÉÒÔ´¦ÖôóÁ¿»¥ÁªÍøÁ÷Á¿£¬ÆäʹÓ÷dz£¹ã·º¡£
2021Äê05ÔÂ04ÈÕ£¬Qualys¹ûÈ»Åû¶ÁËEximÓʼþ·þÎñÆ÷ÖеÄ21¸öÄþ¾²Â©¶´£¬¹¥»÷Õß¿ÉÒÔͨ¹ý×éºÏÀûÓÃÕâЩ©¶´½øÐÐδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©£¬»ñµÃrootÓû§È¨ÏÞºÍÈä³æʽºáÏòÒƶ¯¡£
0x01 ©¶´ÏêÇé
MTAÊǹ¥»÷Õ߸ÐÐËȤµÄÄ¿±ê£¬ÒòΪËüÃÇͨ³£¿ÉÒÔͨ¹ýInternet·ÃÎÊ£¬Ò»µ©±»ÀûÓ㬹¥»÷Õ߾ͿÉÒÔÐÞ¸ÄÓʼþ·þÎñÆ÷Éϵĵç×ÓÓʼþÉèÖ㬲¢ÔÚÄ¿±êÓʼþ·þÎñÆ÷ÉÏ´´½¨ÐÂÕÊ»§¡£È¥Ä꣬EximÖеÄ©¶´Ôø³ÉΪAPTµÄÄ¿±ê¡£Æ¾¾ÝShodanµÄËÑË÷£¬Ä¿Ç°Ô¼ÄªÓÐ400Íǫ̀Exim·þÎñÆ÷Ö±½Ó̻¶ÔÚ»¥ÁªÍøÉÏ¡£
ÔÚ±¾´Î¹ûÈ»µÄ21¸ö©¶´ÖУ¬ÆäÖÐ10¸ö¿ÉÒÔ±»Ô¶³ÌÀûÓá£ËäÈ»Qualys²¢Î´Ðû²¼ÈκÎÍêÕûµÄ©¶´Poc£¬µ«ÆäÖдó¶àÊý¶¼¿ÉÒÔÔÚĬÈÏÅäÖûò³£¼ûÅäÖÃÖб»ÀûÓã¬ÕâЩ©¶´»áÓ°ÏìEximÓÚ2004ÄêÖ®ºó¿ª·¢µÄËùÓа汾£¬¹¥»÷Õß¿ÉÒÔͨ¹ý×éºÏÀûÓÃÕâЩ©¶´»ñµÃ³õʼ·ÃÎÊȨÏÞ¡¢Ôì³ÉÈä³æÀûÓá¢È¨ÏÞÌáÉý¡¢°²×°·¨Ê½¡¢ÐÞ¸ÄÊý¾Ý²¢´´½¨ÐÂÕË»§¡£
21 Nails EximÖУ¬10¸ö¿ÉÔ¶³ÌÀûÓõÄ©¶´Îª£º
CVE-2020-28017£ºreceive_add_recipient£¨£©ÖеÄÕûÊýÒç³ö
CVE-2020-28020£ºreceive_msg£¨£©ÖеÄÕûÊýÒç³ö
CVE-2020-28023£ºÔÚsmtp_setup_msg£¨£©ÖжÁÈ¡Ô½½ç
CVE-2020-28021£ºÔÚspoolÍ·ÎļþÖÐ×¢ÈëÐÂÐÐ
CVE-2020-28022£ºextract_option£¨£©ÖжÑÔ½½ç¶ÁÈ¡ºÍдÈë
CVE-2020-28026£ºspool_read_header£¨£©ÖеÄÐнضϺÍ×¢Èë
CVE-2020-28019£ºBDAT´íÎóºóÎÞ·¨ÖØÖú¯ÊýÖ¸Õë
CVE-2020-28024£ºsmtp_ungetc£¨£©ÖеĶѻº³åÇøÏÂÒç
CVE-2020-28018£ºÔÚtls-openssl.cÖÐUse-after-free
CVE-2020-28025£ºÔÚpdkim_finish_bodyhash£¨£©ÖжÑÔ½½ç¶ÁÈ¡
21 Nails EximÖУ¬11¸öµ±µØÀûÓõÄ©¶´Îª£º
CVE-2020-28007£ºEximÈÕ־Ŀ¼ÖеÄÁ´½Ó¹¥»÷
CVE-2020-28008£ºEximµÄspoolĿ¼ÖеÄÖÖÖÖ¹¥»÷
CVE-2020-28014£ºÈÎÒâÎļþ´´½¨ºÍ¿ÚÁî¹¥»÷
CVE-2021-27216£ºÉ¾³ýÈÎÒâÎļþ
CVE-2020-28011£ºqueue_run£¨£©ÖеĶѻº³åÇøÒç³ö
CVE-2020-28010£ºmain()ÖеĶÑÔ½½çд²Ù×÷
CVE-2020-28013£ºparse_fix_phrase£¨£©ÖеĶѻº³åÇøÒç³ö
CVE-2020-28016£ºparse_fix_phrase()ÖеĶÑÔ½½çдÈë
CVE-2020-28015£ºÔÚspoolÍ·ÎļþÖÐ×¢ÈëÐÂÐÐ
CVE-2020-28012£ºÌØȨ¹ÜµÀȱÉÙÖ´ÐÐʱ¹Ø±ÕµÄ±êÖ¾
CVE-2020-28009£ºget_stdinput£¨£©ÖеÄÕûÊýÒç³ö
ÔÚÕâЩ©¶´ÖУ¬CVE-2020-28018ÊÇ×îÑÏÖصÄ©¶´Ö®Ò»£¬Èç¹ûExim·þÎñÆ÷ÊÇÓÃOpenSSL¹¹½¨µÄ£»Èç¹ûSTARTTLSºÍPIPELINING£¨Ä¬ÈÏ£©±»ÆôÓã»Èç¹ûX_PIPE_CONNECT±»½ûÓã¨Exim 4.94֮ǰµÄĬÈÏÉèÖã©£¬Ëü¾Í¿ÉÒÔ±»ÀûÓá£ÁíÒ»¸öÖµµÃ×¢ÒâµÄ©¶´ÊÇCVE-2020-28020£¬ËüÊÇÒ»¸öÕûÊýÒç³ö©¶´£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓÃËüÒÔ ¡°exim ¡±Óû§Éí·ÝÖ´ÐÐÈÎÒâÃüÁî²¢¿ú̽Êý¾Ý£¬Ëü´æÔÚÓÚreceive_msg£¨£©º¯ÊýÖУ¬¶øÇÒ¹¦Ð§Ç¿´ó£¬µ«Ò²ÊÇ21¸ö©¶´ÖÐ×îÄÑÀûÓõġ£¶øµ±CVE-2020-28021ÓëÆäËü©¶´×éºÏÀûÓÃʱ£¬¾¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÔÚspoolÍ·ÎļþÖÐ×¢ÈëÐÂÐУ¬²¢ÒÔrootÉí·ÝÖ´ÐÐÈÎÒâÃüÁî¡£
Ó°Ï췶Χ
2004ÄêÖ®ºó¿ª·¢µÄËùÓа汾
0x02 ´¦Öý¨Òé
QualysµÄÑо¿ÈËÔ±ºÍExim¹Ù·½¾ùÐû²¼ÁËÏà¹Ø²¹¶¡¡£ÖÁÓÚÖÖÖÖLinux¿¯Ðа棬×î¹ã·ºÊ¹Óõģ¨CentOS¡¢RHELºÍSuSE£©£¬ÒѾÍƳöÁËÐÞ¸´·¨Ê½¡£DebianÔÚ ¡°oldstable¡±£¨´úºÅStretch£©¡¢¡°stable¡±£¨Buster£©»ò ¡°Still-in-development¡±£¨Sid£©°æ±¾Öв»´æÔÚÕâЩ©¶´£¬¶ø¡°unstable¡±£¨Bullseye£©°æ±¾Ôò´æÔÚ©¶´£¬ÇÒÄ¿Ç°ÉÐδÐÞ¸´¡£
Ïà¹Ø©¶´µÄÐÞ¸´ÒªÁì»ò²¹¶¡½¨Òé²Î¿¼QualysÐû²¼µÄÄþ¾²×Éѯ£º
https://www.qualys.com/2021/05/04/21nails/21nails.txt
0x03 ²Î¿¼Á´½Ó
https://www.qualys.com/2021/05/04/21nails/21nails.txt
https://threatpost.com/exim-security-linux-mail-server-takeovers/165894/
http://www.exim.org/
0x04 ʱ¼äÏß
2021-05-04 Qualys¹ûÈ»Åû¶©¶´
2021-05-07 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/