Exim Mail Server 5Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-05-07

0x00 Îó²î¸ÅÊö

EximÊÇÓɽ£ÇÅ´óѧ¿ª·¢µÄÐÂÎÅ´«Êä´úÀí£¨MTA£©£¬Ö÷Òª±»¹¹½¨ÔÚÀàUnix²Ù×÷ϵͳÉÏ·¢ËͺÍÎüÊÕµç×ÓÓʼþ ¡£ºÃ±È£¬ËüÒÑԤװÔÚLinux¿¯Ðа棨ÈçDebian£©ÉÏ ¡£Exim¿ÉÒÔ´¦Öóͷ£´ó×Ú»¥ÁªÍøÁ÷Á¿£¬ÆäʹÓúÜÊÇÆÕ±é ¡£

2021Äê05ÔÂ04ÈÕ£¬Qualys¹ûÕæÅû¶ÁËEximÓʼþ·þÎñÆ÷ÖеÄ21¸öÇå¾²Îó²î£¬¹¥»÷Õß¿ÉÒÔͨ¹ý×éºÏʹÓÃÕâЩÎó²î¾ÙÐÐδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©£¬»ñµÃrootÓû§È¨ÏÞºÍÈä³æÊ½ºáÏòÒÆ¶¯ ¡£

 

0x01 Îó²îÏêÇé

image.png

MTAÊǹ¥»÷Õ߸ÐÐËȤµÄÄ¿µÄ£¬ÓÉÓÚËüÃÇͨ³£¿ÉÒÔͨ¹ýInternet»á¼û£¬Ò»µ©±»Ê¹Ó㬹¥»÷Õ߾ͿÉÒÔÐÞ¸ÄÓʼþ·þÎñÆ÷Éϵĵç×ÓÓʼþÉèÖ㬲¢ÔÚÄ¿µÄÓʼþ·þÎñÆ÷ÉϽ¨ÉèÐÂÕÊ»§ ¡£È¥Ä꣬EximÖеÄÎó²îÔø³ÉΪAPTµÄÄ¿µÄ ¡£Æ¾Ö¤ShodanµÄËÑË÷£¬ÏÖÔÚԼĪÓÐ400Íǫ̀Exim·þÎñÆ÷Ö±½Ó̻¶ÔÚ»¥ÁªÍøÉÏ ¡£

ÔÚ±¾´Î¹ûÕæµÄ21¸öÎó²îÖУ¬ÆäÖÐ10¸ö¿ÉÒÔ±»Ô¶³ÌʹÓà ¡£ËäÈ»Qualys²¢Î´Ðû²¼ÈκÎÍêÕûµÄÎó²îPoc£¬µ«ÆäÖдó´ó¶¼¶¼¿ÉÒÔÔÚĬÈÏÉèÖûò³£¼ûÉèÖÃÖб»Ê¹Óã¬ÕâЩÎó²î»áÓ°ÏìEximÓÚ2004ÄêÖ®ºó¿ª·¢µÄËùÓа汾£¬¹¥»÷Õß¿ÉÒÔͨ¹ý×éºÏʹÓÃÕâЩÎó²î»ñµÃ³õʼ»á¼ûȨÏÞ¡¢Ôì³ÉÈä³æÊ¹Óá¢È¨ÏÞÌáÉý¡¢×°ÖóÌÐò¡¢ÐÞ¸ÄÊý¾Ý²¢½¨ÉèÐÂÕË»§ ¡£

21 Nails EximÖУ¬10¸ö¿ÉÔ¶³ÌʹÓõÄÎó²îΪ£º

CVE-2020-28017£ºreceive_add_recipient£¨£©ÖеÄÕûÊýÒç³ö

CVE-2020-28020£ºreceive_msg£¨£©ÖеÄÕûÊýÒç³ö

CVE-2020-28023£ºÔÚsmtp_setup_msg£¨£©ÖжÁȡԽ½ç

CVE-2020-28021£ºÔÚspoolÍ·ÎļþÖÐ×¢ÈëÐÂÐÐ

CVE-2020-28022£ºextract_option£¨£©ÖжÑÔ½½ç¶ÁÈ¡ºÍдÈë

CVE-2020-28026£ºspool_read_header£¨£©ÖеÄÐнضϺÍ×¢Èë

CVE-2020-28019£ºBDAT¹ýʧºóÎÞ·¨ÖØÖú¯ÊýÖ¸Õë

CVE-2020-28024£ºsmtp_ungetc£¨£©ÖеĶѻº³åÇøÏÂÒç

CVE-2020-28018£ºÔÚtls-openssl.cÖÐUse-after-free

CVE-2020-28025£ºÔÚpdkim_finish_bodyhash£¨£©ÖжÑÔ½½ç¶ÁÈ¡

 

21 Nails EximÖУ¬11¸öÍâµØÊ¹ÓõÄÎó²îΪ£º

CVE-2020-28007£ºEximÈÕ־Ŀ¼ÖеÄÁ´½Ó¹¥»÷

CVE-2020-28008£ºEximµÄspoolĿ¼ÖеÄÖÖÖÖ¹¥»÷

CVE-2020-28014£ºí§ÒâÎļþ½¨ÉèºÍ¿ÚÁî¹¥»÷

CVE-2021-27216£ºÉ¾³ýí§ÒâÎļþ

CVE-2020-28011£ºqueue_run£¨£©ÖеĶѻº³åÇøÒç³ö

CVE-2020-28010£ºmain()ÖеĶÑÔ½½çд²Ù×÷

CVE-2020-28013£ºparse_fix_phrase£¨£©ÖеĶѻº³åÇøÒç³ö

CVE-2020-28016£ºparse_fix_phrase()ÖеĶÑÔ½½çдÈë

CVE-2020-28015£ºÔÚspoolÍ·ÎļþÖÐ×¢ÈëÐÂÐÐ

CVE-2020-28012£ºÌØÈ¨¹ÜµÀȱÉÙÖ´ÐÐʱ¹Ø±ÕµÄ±ê¼Ç

CVE-2020-28009£ºget_stdinput£¨£©ÖеÄÕûÊýÒç³ö

 

ÔÚÕâЩÎó²îÖУ¬CVE-2020-28018ÊÇ×îÑÏÖØµÄÎó²îÖ®Ò»£¬ÈôÊÇExim·þÎñÆ÷ÊÇÓÃOpenSSL¹¹½¨µÄ£»ÈôÊÇSTARTTLSºÍPIPELINING£¨Ä¬ÈÏ£©±»ÆôÓã»ÈôÊÇX_PIPE_CONNECT±»½ûÓã¨Exim 4.94֮ǰµÄĬÈÏÉèÖã©£¬Ëü¾Í¿ÉÒÔ±»Ê¹Óà ¡£ÁíÒ»¸öÖµµÃ×¢ÖØµÄÎó²îÊÇCVE-2020-28020£¬ËüÊÇÒ»¸öÕûÊýÒç³öÎó²î£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃËüÒÔ ¡°exim ¡±Óû§Éí·ÝÖ´ÐÐí§ÒâÏÂÁî²¢¿ú̽Êý¾Ý£¬Ëü±£´æÓÚreceive_msg£¨£©º¯ÊýÖУ¬²¢ÇÒ¹¦Ð§Ç¿Ê¢£¬µ«Ò²ÊÇ21¸öÎó²îÖÐ×îÄÑʹÓõÄ ¡£¶øµ±CVE-2020-28021ÓëÆäËüÎó²î×éºÏʹÓÃʱ£¬¾­ÓÉÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔÔÚspoolÍ·ÎļþÖÐ×¢ÈëÐÂÐУ¬²¢ÒÔrootÉí·ÝÖ´ÐÐí§ÒâÏÂÁî ¡£

 

Ó°Ïì¹æÄ£

2004ÄêÖ®ºó¿ª·¢µÄËùÓа汾

 

0x02 ´¦Öóͷ£½¨Òé

QualysµÄÑо¿Ö°Ô±ºÍExim¹Ù·½¾ùÐû²¼ÁËÏà¹Ø²¹¶¡ ¡£ÖÁÓÚÖÖÖÖLinux¿¯Ðаæ£¬×îÆÕ±éʹÓõģ¨CentOS¡¢RHELºÍSuSE£©£¬ÒѾ­ÍƳöÁËÐÞ¸´³ÌÐò ¡£DebianÔÚ ¡°oldstable¡±£¨´úºÅStretch£©¡¢¡°stable¡±£¨Buster£©»ò ¡°Still-in-development¡±£¨Sid£©°æ±¾Öв»±£´æÕâЩÎó²î£¬¶ø¡°unstable¡±£¨Bullseye£©°æ±¾Ôò±£´æÎó²î£¬ÇÒÏÖÔÚÉÐδÐÞ¸´ ¡£

Ïà¹ØÎó²îµÄÐÞ¸´ÒªÁì»ò²¹¶¡½¨Òé²Î¿¼QualysÐû²¼µÄÇå¾²×Éѯ£º

https://www.qualys.com/2021/05/04/21nails/21nails.txt

 

0x03 ²Î¿¼Á´½Ó

https://www.qualys.com/2021/05/04/21nails/21nails.txt

https://threatpost.com/exim-security-linux-mail-server-takeovers/165894/

http://www.exim.org/

 

0x04 ʱ¼äÏß

2021-05-04  Qualys¹ûÕæÅû¶Îó²î

2021-05-07  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png