ׯÏÐÓÎÏ·

֤ȯ¼ò³Æ£º×¯ÏÐÓÎÏ· ֤ȯ´úÂ룺002212
È«Ììºò7x24СʱЧÀÍ£º 400-777-0777

CactiÏÂÁîÖ´ÐÐÎó²îÆØ¹â£¬ £¬£¬ £¬×¯ÏÐÓÎϷΪÄúÌṩÃâ·ÑÅŲ鼯»®£¡

¿ËÈÕ£¬ £¬£¬ £¬×¯ÏÐÓÎÏ·°¢¶û·¨ÊµÑéÊÒ¼à²âµ½»¥ÁªÍøÉϹûÕæÐû²¼Á˹ØÓÚCacti±£´æÏÂÁîÖ´ÐÐÎó²îµÄÐÂÎÅ¡£¡£¡£¸ÃÎó²î±£´æÓÚ¡°remote_agent.php¡±ÎļþÖУ¬ £¬£¬ £¬¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤¼´¿É»á¼û´ËÎļþ¡£¡£¡£

CactiÏÂÁîÖ´ÐÐÎó²îÆØ¹â£¬ £¬£¬ £¬×¯ÏÐÓÎϷΪÄúÌṩÃâ·ÑÅŲ鼯»®£¡

Ðû²¼Ê±¼ä£º2022-12-09
ä¯ÀÀ´ÎÊý£º4050
·ÖÏí£º

CactiÊÇÒ»Ì×»ùÓÚPHP£¬ £¬£¬ £¬MySQL£¬ £¬£¬ £¬SNMP¼°RRDTool¿ª·¢µÄ¿ªÔ´ÍøÂçÁ÷Á¿¼à²âͼÐÎÆÊÎö¹¤¾ß£¬ £¬£¬ £¬ÌṩÁ˺ÜÊÇǿʢµÄÊý¾ÝºÍÓû§ÖÎÀí¹¦Ð§£¬ £¬£¬ £¬¿ÉÒÔÖ¸¶¨Ã¿Ò»¸öÓû§Éó²éÊ÷×´½á¹¹¡¢hostÒÔ¼°ÈκÎÒ»ÕÅͼ¡£¡£¡£

¿ËÈÕ£¬ £¬£¬ £¬×¯ÏÐÓÎÏ·°¢¶û·¨ÊµÑéÊÒ¼à²âµ½»¥ÁªÍøÉϹûÕæÐû²¼Á˹ØÓÚCacti±£´æÏÂÁîÖ´ÐÐÎó²îµÄÐÂÎÅ¡£¡£¡£¸ÃÎó²î±£´æÓÚ¡°remote_agent.php¡±ÎļþÖУ¬ £¬£¬ £¬¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤¼´¿É»á¼û´ËÎļþ¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃget_nfilter_request_var()º¯Êý¼ìË÷µÄ²ÎÊý$poller_id£¬ £¬£¬ £¬À´Öª×ãpoller_item =POLLER_ACTION_SCRIPT_PHPÌõ¼þ£¬ £¬£¬ £¬´¥·¢proc_open()º¯Êý£¬ £¬£¬ £¬´Ó¶øµ¼ÖÂÏÂÁîÖ´ÐС£¡£¡£Îó²îʹÓÃÀֳɺó£¬ £¬£¬ £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔÚÔËÐÐ Cacti µÄЧÀÍÆ÷ÉÏÖ´ÐÐí§Òâ´úÂ룬 £¬£¬ £¬ÆäΣº¦Ö®´ó£¬ £¬£¬ £¬Ð§¹û²»¿°ÉèÏ룬 £¬£¬ £¬½¨Òé¿Í»§¾¡¿ì¿ªÕ¹×Բ鲢¸üÐÂÖÁ×îа汾»òÆôÓÃÇå¾²·À»¤²úÆ·ÒÔ·ÀÓùÎó²î¡£¡£¡£

Îó²îÐÅÏ¢

ÅŲéÒªÁìÒ»

ͨ¹ýׯÏÐÓÎÏ·×Ô˳ӦÇå¾²·ÀÓùϵͳ´ÓÇå¾²ÔËÓªÊÓ½Ç×Ô¶¯»¯¹¹½¨Ö÷»ú×ʲúÖ¸ÎÆ¿â£¬ £¬£¬ £¬¿ÉÖÜÈ«ÍøÂçWebЧÀÍ¡¢WebÓ¦Óá¢Web¿ò¼ÜµÈÐÅÏ¢£¬ £¬£¬ £¬¿ìËÙ¶¨Î»ÊÜÓ°ÏìÖ÷»ú¼°Cacti°æ±¾£¬ £¬£¬ £¬ÓÐÓÃÌáÉýÇå¾²Îó²îÏìӦЧÂÊ¡£¡£¡£

ÅŲéÒªÁì¶þ

ׯÏÐÓÎϷųÈõÐÔɨÃèÓëÖÎÀíϵͳ¼¯³Éϵͳ©ɨ¡¢Web©ɨ¡¢Êý¾Ý¿â©ɨ¡¢Èõ¿ÚÁî¼ì²â¡¢»ùÏߺ˲éµÈ¹¦Ð§£¬ £¬£¬ £¬¶ÔÐÅÏ¢×ʲú¾ÙÐÐÖÜÈ«µÄųÈõÐÔ¼ì²é£¬ £¬£¬ £¬ÌṩרҵµÄÇå¾²ÆÊÎöºÍÐÞ²¹½¨Òé¡£¡£¡£

ÏÖÔÚׯÏÐÓÎϷųÈõÐÔɨÃèÓëÖÎÀíϵͳÒѽôÆÈ¸üÐÂCactiÎó²î¼ì²é²å¼þ£¬ £¬£¬ £¬¿É½«Îó²î¹æÔò¿âÉý¼¶ÖÁvas-sys-v1.0-2022.12.08.tir°æ±¾£¬ £¬£¬ £¬Ï·¢É¨ÃèʹÃüºó¿ìËÙÅŲéCactiÎó²î¡£¡£¡£

ÐÞ¸´½¨Òé

1¡¢Çå¾²²¹¶¡

ÏÖÔÚCacti¹Ù·½ÒÑÐû²¼Çå¾²²¹¶¡£¬ £¬£¬ £¬µ«ÔÝδÐû²¼°æ±¾¸üУ¬ £¬£¬ £¬½¨ÒéÊÜÓ°ÏìÓû§¹Ø×¢¹Ù·½¸üлò²Î¿¼¹Ù·½²¹¶¡´úÂë¾ÙÐÐÐÞ¸´£º

https://github.com/Cacti/cacti/commit/7f0e16312dd5ce20f93744ef8b9c3b0f1ece2216

https://github.com/Cacti/cacti/commit/b43f13ae7f1e6bfe4e8e56a80a7cd867cf2db52b

×¢ÖØ£º¹ØÓÚÔÚPHP<7.0ÏÂÔËÐеÄ1.2.xʵÀý£¬ £¬£¬ £¬»¹ÐèÒª½øÒ»²½¸ü¸Ä£º

https://github.com/Cacti/cacti/commit/a8d59e8fa5f0054aa9c6981b1cbe30ef0e2a0ec9

2¡¢»º½â¼Æ»®

(1) ͨ¹ý¸üÐÂlib/functions.phpÖÐget_client_addrº¯Êý±ÜÃâÊÚÈ¨ÈÆ¹ý£¬ £¬£¬ £¬¿É²Î¿¼¹Ù·½²¹¶¡´úÂ룻£»£»

(2) ͨ¹ý¸ü¸Äremote_agent.phpÎļþ±ÜÃâÏÂÁî×¢È룬 £¬£¬ £¬¼ìË÷$poller_id²ÎÊýʱʹÓÃget_filter_request_varº¯ÊýÈ¡´úget_nfilter_request_var£º

(3) ÔÚ²ÎÊý$poller_id´«Èëproc_open()º¯Êý֮ǰͨ¹ýescapeshellarg()º¯Êý¾ÙÐÐתÒ壺

²Î¿¼Á´½Ó£º

https://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf

½üÄêÀ´£¬ £¬£¬ £¬ÐÂÐÍWebÎó²îƵ·¢£¬ £¬£¬ £¬¹ØÓÚÔõÑùÔÚÕⳡ²î³ØµÈµÄ¹¥·ÀÕ½ÕùÖÐÌáÉý×Ô¶¯·ÀÓùÄÜÁ¦£¬ £¬£¬ £¬Ï¸¿ÅÁ£¶ÈµÄ×ʲúÖÎÀíÓëÒ»Á¬µÄ¼ì²âÏìÓ¦Êǽ¹µãÒªº¦¡£¡£¡£

Ãâ ·Ñ ÊÔ ÓÃ

ׯÏÐÓÎÏ·×Ô˳ӦÇå¾²·ÀÓùϵͳÊÇÒ»¿î»ùÓÚ×Ô˳ӦÇå¾²¼Ü¹¹µÄÖ÷»úÇå¾²¸ÐÖª·À»¤Æ½Ì¨£¬ £¬£¬ £¬ÏµÍ³ÓɹܿØÖÐÐĺÍÇ徲̽ÕëAgent×é³É£¬ £¬£¬ £¬¿É¿ìËÙ¹¹½¨Ö÷»úÇå¾²¸ÐÖª·À»¤Æ½Ì¨£¬ £¬£¬ £¬´ÓÕ¹Íû¡¢·ÀÓù¡¢¼ì²â¡¢ÏìÓ¦²ãÃæÖÜÈ«ÔöÇ¿Çå¾²¼à¿Ø¡¢Çå¾²ÆÊÎöºÍÏìÓ¦ÄÜÁ¦£¬ £¬£¬ £¬ÔÚ×ʲúÊáÀíµÄ»ù´¡ÉÏÌṩȫջ±£»£»£»¤ÄÜÁ¦£¬ £¬£¬ £¬ÓÐÓÃ×ÊÖú¿Í»§µÖÓù¸ß¼¶Íþв¹¥»÷£¬ £¬£¬ £¬ÖÜÈ«ÌáÉýÇå¾²ÔËÓªÄÜÁ¦¡£¡£¡£

2022Äê12ÔÂ9ÈÕ¡ª2023Äê3ÔÂ9ÈÕ

¡¸Ê¶±ð¶þάÂ롹

ׯÏÐÓÎÏ·×Ô˳ӦÇå¾²·ÀÓùϵͳ

ÂíÉÏÔ¤Ô¼ÊÔÓÃ~

TOPSEC

×÷ΪÖйúÍøÂçÇå¾²¡¢´óÊý¾ÝºÍÔÆÐ§ÀÍÌṩÉÌ£¬ £¬£¬ £¬×¯ÏÐÓÎϷʼÖÕÒÔº´ÎÀÍøÂç¿Õ¼äÇ徲Ϊ¼ºÈΣ¬ £¬£¬ £¬Ò»Ö±ÍƳöÖª×ãÆóÒµ¿Í»§Çå¾²ÐèÇóµÄ²úÆ·ÓëЧÀÍ£¬ £¬£¬ £¬Æð¾¢Ó¦¶ÔеÄÇå¾²ÍþвÓëÌôÕ½£¬ £¬£¬ £¬Îª°ü¹Ü¹ú¼ÒÍøÂç¿Õ¼äÇ徲Т˳ÆóҵʵÁ¦¡£¡£¡£

Òªº¦´Ê±êÇ©£º
ׯÏÐÓÎÏ·°¢¶û·¨ÊµÑéÊÒ CactiÏÂÁîÖ´ÐÐÎó²î Ãâ·ÑÅŲ鼯»®
¿Í»§Ð§ÀÍÈÈÏß

400-777-0777
7*24СʱЧÀÍ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿