¾ÅÓÎÀϸç

¾ÅÓÎÀϸç

¾ÅÓÎÀÏ¸ç¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¡¾Íþвͨ¸æ¡¿Linux PolkitȨÏÞÌáÉýÎó²î£¨CVE-2021-4034£©

2022-01-27

Ò».  Îó²î¸ÅÊö

1ÔÂ26ÈÕ £¬¾ÅÓÎÀÏ¸ç¿Æ¼¼CERT¼à²âµ½QualysÑо¿ÍŶӹûÕæÅû¶ÁËÔÚPolkitµÄpkexec Öз¢Ã÷µÄÒ»¸öȨÏÞÌáÉýÎó²î£¨CVE-2021-4034) £¬Ò²±»³ÆÎªPwnKit ¡£¸ÃÎó²îÊÇÓÉÓÚpkexec ÎÞ·¨×¼È·´¦Öóͷ£Å²ÓòÎÊý £¬´Ó¶ø½«ÇéÐαäÁ¿×÷ΪÏÂÁîÖ´ÐÐ £¬¾ßÓÐí§ÒâÓû§È¨Ï޵Ĺ¥»÷Õß¶¼¿ÉÒÔÔÚĬÈÏÉèÖÃÏÂͨ¹ýÐÞ¸ÄÇéÐαäÁ¿À´Ê¹ÓôËÎó²î £¬´Ó¶ø»ñµÃÊÜÓ°ÏìÖ÷»úµÄroot È¨ÏÞ ¡£ÏÖÔÚ¸ÃÎó²îµÄϸ½ÚºÍPoCÒѹûÕæ £¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤ ¡£

Polkit£¨PolicyKit£©ÊÇÀàUnixϵͳÖÐÒ»¸öÓ¦ÓóÌÐò¼¶±ðµÄ¹¤¾ß¼¯ £¬Í¨¹ý½ç˵ºÍÉóºËȨÏÞ¹æÔò £¬ÊµÏÖ²î±ðÓÅÏȼ¶Àú³Ì¼äµÄͨѶ ¡£pkexecÊÇPolkit¿ªÔ´Ó¦Óÿò¼ÜµÄÒ»²¿·Ö £¬¿ÉÒÔʹÊÚȨ·ÇÌØÈ¨Óû§Æ¾Ö¤½ç˵µÄÕ½ÂÔÒÔÌØÈ¨Óû§µÄÉí·ÝÖ´ÐÐÏÂÁî ¡£

¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒѵÚһʱ¼äÀֳɸ´ÏÖ ¡£

 

 

²Î¿¼Á´½Ó£º

https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt

¶þ.  Ó°Ïì¹æÄ£

ÊÜÓ°Ïì°æ±¾

2009Äê5ÔÂÖÁ½ñÐû²¼µÄËùÓÐ Polkit °æ±¾

×¢£ºPolkitԤװÔÚCentOS¡¢Ubuntu¡¢Debian¡¢Redhat¡¢Fedora¡¢Gentoo¡¢MageiaµÈ¶à¸öLinux¿¯ÐаæÉÏ £¬ËùÓб£´æPolkitµÄLinuxϵͳ¾ùÊÜÓ°Ïì ¡£

 

²»ÊÜÓ°Ïì°æ±¾

CentOS£º

CentOS 6£ºpolkit-0.96-11.el6_10.2

CentOS 7£ºpolkit-0.112-26.el7_9.1

CentOS 8.0£ºpolkit-0.115-13.el8_5.1

CentOS 8.2£ºpolkit-0.115-11.el8_2.2

CentOS 8.4£ºpolkit-0.115-11.el8_4.2

 

Ubuntu£º

Ubuntu 14.04 ESM£ºpolicykit-1-0.105-4ubuntu3.14.04.6+esm1

Ubuntu 16.04 ESM£ºpolicykit-1-0.105-14.1ubuntu0.5+esm1

Ubuntu 18.04 LTS£ºpolicykit-1-0.105-20ubuntu0.18.04.6

Ubuntu 20.04 LTS£ºpolicykit-1-0.105-26ubuntu1.2

Ubuntu 21.10£ºpolicykit-1-0.105-31ubuntu0.1

 

Debain£º

Debain stretch£ºpolicykit-1 0.105-18+deb9u2

Debain buster£ºpolicykit-1 0.105-25+deb10u1

Debain bullseye£ºpolicykit-1 0.105-31+deb11u1

Debain bookworm,bullseye£ºpolicykit-1 0.105-31.1

Èý.  Îó²î¼ì²â

3.1  °æ±¾¼ì²â

LinuxϵͳÓû§¿ÉÒÔͨ¹ýÉó²éPolkit°æÔ­À´ÅжÏÄ¿½ñϵͳÊÇ·ñÔÚÊÜÓ°Ïì¹æÄ£ÄÚ £¬Ö÷Á÷Linux¿¯ÐаæÏÂÁîÈçÏ£º

CentOS£º

rpm -qa polkit

Ubuntu£º

dpkg -l policykit-1

 

ËÄ.  Îó²î·À»¤

4.1  ¹Ù·½Éý¼¶

1¡¢ÏÖÔÚ¹Ù·½ÒÑÐû²¼²¹¶¡ÐÞ¸´´ËÎó²î £¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±×°ÖþÙÐзÀ»¤ ¡£ÏÂÔØÁ´½Ó£ºhttps://gitlab.freedesktop.org/polkit/polkit/-/commit/a2bf5c9c83b6ae46cbd5c779d3055bff81ded683

2¡¢ÏÖÔÚÖ÷Á÷Linux¿¯Ðаæ¾ùÒÑÐû²¼Çå¾²²¹¶¡»ò¸üа汾ÐÞ¸´´ËÎó²î £¬½¨ÒéÓû§¾¡¿ì×°Öò¹¶¡»ò²ÎÕÕ¹Ù·½²½·¥¾ÙÐзÀ»¤£º

Linux¿¯Ðаæ

¹Ù·½Í¨¸æ

Ubuntu

https://ubuntu.com/security/CVE-2021-4034

Debain

https://security-tracker.debian.org/tracker/CVE-2021-4034

Redhat

https://access.redhat.com/security/cve/CVE-2021-4034

Gentoo

https://bugs.gentoo.org/show_bug.cgi?id=CVE-2021-4034

Mageia

https://advisories.mageia.org/CVE-2021-4034.html

×¢£ºÈçCentOS¡¢Ubuntu¡¢DebianµÈʹÓðü¹ÜÀíÆ÷¸üÐÂPolkitµÄLinux¿¯Ðаæ £¬¿ÉÖ±½ÓÔËÐÐÏÂÁÐÏÂÁî¾ÙÐиüÐÂÐÞ¸´£º

CentOS£º

yum clean all && yum makecache

yum update polkit -y

Ubuntu£º

sudo apt-get update

sudo apt-get install policykit-1

Debian£º

apt upgrade policykit-1

 

4.2  ÔÝʱ·À»¤²½·¥

ÈôÊÜÓ°ÏìÓû§Ê¹ÓõIJÙ×÷ϵͳ»¹Î´Ðû²¼ÐÞ¸´³ÌÐò £¬»òÔÝʱÎÞ·¨×°Öò¹¶¡¸üР£¬ÔÚ²»Ó°ÏìÓªÒµµÄÇéÐÎÏ¿ÉʹÓÃÒÔϲ½·¥¾ÙÐÐÔÝʱ·À»¤ ¡£

Ö´ÐÐÏÂÁÐϵͳÏÂÁîÒÆ³ý pkexec µÄ suidλ£º

chmod 0755 /usr/bin/pkexec

 

ÉùÃ÷

±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌâ £¬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí ¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ £¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ £¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈÎ ¡£

¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ £¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ £¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ ¡£Î´¾­¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí £¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ £¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ ¡£

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈë¾ÅÓÎÀÏ¸ç¿Æ¼¼ £¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
  • Ìá½»µ½ÓÊÏä
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼