{"id":12450,"date":"2016-02-26T15:44:19","date_gmt":"2016-02-26T07:44:19","guid":{"rendered":"https:\/\/www.deepin.org\/?p=9724"},"modified":"2017-01-18T10:07:44","modified_gmt":"2017-01-18T02:07:44","slug":"security-update%ef%bc%88cve-2015-7547%ef%bc%89","status":"publish","type":"post","link":"https:\/\/www.deepin.org.cn\/zh\/security-update%ef%bc%88cve-2015-7547%ef%bc%89\/","title":{"rendered":"\u5b89\u5168\u66f4\u65b0\uff08CVE-2015-7547\uff09"},"content":{"rendered":"\u5b89\u5168\u4eba\u5458\u53d1\u73b0GNU C Library (glibc)\u4e2d\u5b58\u5728\u4e25\u91cd\u7684\u5b89\u5168\u6f0f\u6d1e\uff0c\u53ef\u5bfc\u81f4Linux\u8f6f\u4ef6\u88ab\u653b\u51fb\u8005\u52ab\u6301\uff0c\u8fdb\u800c\u5728Linux\u5e73\u53f0\u4e0a\u6267\u884c\u4efb\u610f\u4ee3\u7801\uff0c\u83b7\u53d6\u5bc6\u7801\u3001\u76d1\u89c6\u7528\u6237\uff0c\u751a\u81f3\u63a7\u5236\u8ba1\u7b97\u673a\uff08CVE\u7f16\u53f7\u4e3aCVE-2015-7547\uff09\u3002<\/p>\n<p>&nbsp;<\/p>\n<h2>\u5f71\u54cd<\/h2>\n<p>glibc\u662fGNU\u53d1\u5e03\u7684libc\u5e93\uff0c\u5373c\u8fd0\u884c\u5e93\u3002\u5b83\u662fLinux\u7cfb\u7edf\u4e2d\u6700\u5e95\u5c42\u7684API\uff0c\u51e0\u4e4e\u5176\u5b83\u8fd0\u884c\u5e93\u90fd\u4f1a\u4f9d\u8d56\u4e8eglibc\u3002\u5e76\u4e14glibc\u5e94\u7528\u4e8e\u4f17\u591aLinux\u53d1\u884c\u7248\u672c\u4e2d\uff0c\u6240\u4ee5\u6b64\u7c7b\u6f0f\u6d1e\u5f71\u54cd\u8303\u56f4\u5341\u5206\u5e7f\u6cdb\u3002<\/p>\n<p>&nbsp;<\/p>\n<h2>\u6f0f\u6d1e\u6982\u8ff0<\/h2>\n<p>glibc\u7684DNS\u5ba2\u6237\u7aef\u89e3\u6790\u5668\u4e2d\u5b58\u5728\u57fa\u4e8e\u6808\u7684\u7f13\u51b2\u533a\u6ea2\u51fa\u6f0f\u6d1e\u3002\u5f53\u8f6f\u4ef6\u7528\u5230getaddrinfo\u5e93\u51fd\u6570\uff08\u5904\u7406\u540d\u5b57\u5230\u5730\u5740\u4ee5\u53ca\u670d\u52a1\u5230\u7aef\u53e3\u7684\u8f6c\u6362\uff09\u65f6\uff0c\u653b\u51fb\u8005\u4fbf\u53ef\u501f\u52a9\u7279\u5236\u7684\u57df\u540d\u3001DNS\u670d\u52a1\u5668\u6216\u4e2d\u95f4\u4eba\u653b\u51fb\u5229\u7528\u8be5\u6f0f\u6d1e\uff0c\u63a7\u5236\u8f6f\u4ef6\uff0c\u5e76\u8bd5\u56fe\u63a7\u5236\u6574\u4e2a\u7cfb\u7edf\u3002\u653b\u51fb\u8005\u4f7f\u7528\u6076\u610f\u7684DNS\u57df\u540d\u670d\u52a1\u5668\u521b\u5efa\u7c7b\u4f3c\u4e8eevildomain.com\u7684\u57df\u540d\uff0c\u7136\u540e\u5411\u76ee\u6807\u7528\u6237\u53d1\u9001\u5e26\u6709\u6307\u5411\u8be5\u57df\u540d\u7684\u94fe\u63a5\u7684\u90ae\u4ef6\uff0c\u4e00\u65e6\u7528\u6237\u70b9\u51fb\u8be5\u94fe\u63a5\uff0c\u5ba2\u6237\u7aef\u6216\u6d4f\u89c8\u5668\u5c06\u4f1a\u5f00\u59cb\u67e5\u627eildomain.com\uff0c\u5e76\u6700\u7ec8\u5f97\u5230\u6076\u610f\u670d\u52a1\u5668\u7684buffer-busting\u54cd\u5e94\u3002\u8be5\u57df\u540d\u88ab\u5d4c\u5165\u670d\u52a1\u5668\u65e5\u5fd7\u4e2d\uff0c\u4e00\u65e6\u89e3\u6790\u5c31\u4f1a\u89e6\u53d1\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\uff0cSH\u5ba2\u6237\u7aef\u4e5f\u4f1a\u56e0\u6b64\u88ab\u63a7\u5236\u3002\u6216\u8005\uff0c\u4f4d\u4e8e\u76ee\u6807\u7528\u6237\u7f51\u7edc\u4e2d\u7684\u4e2d\u95f4\u4eba\u653b\u51fb\u8005\u53ef\u4ee5\u7be1\u6539DNS\u54cd\u5e94\uff0c\u5411\u6076\u610f\u4ee3\u7801\u4e2d\u52a8\u6001\u6ce8\u5165\u8d1f\u8f7d\u3002<\/p>\n<p>&nbsp;<\/p>\n<h2>\u4fee\u590d\u60c5\u51b5<\/h2>\n<p>\u5df2\u4fee\u590d<\/p>\n<p>&nbsp;","protected":false},"excerpt":{"rendered":"<p>\u5b89\u5168\u4eba\u5458\u53d1\u73b0GNU C Library (glibc)\u4e2d\u5b58\u5728\u4e25\u91cd\u7684\u5b89\u5168\u6f0f\u6d1e\uff0c\u53ef\u5bfc\u81f4Linux\u8f6f\u4ef6\u88ab\u653b\u51fb\u8005\u52ab\u6301\uff0c\u8fdb\u800c\u5728Linux\u5e73\u53f0\u4e0a\u6267\u884c\u4efb\u610f\u4ee3\u7801\uff0c\u83b7\u53d6\u5bc6\u7801\u3001\u76d1\u89c6\u7528\u6237\uff0c\u751a\u81f3\u63a7\u5236\u8ba1\u7b97\u673a\uff08CVE\u7f16\u53f7\u4e3aCVE-2015-7547\uff09\u3002 &nbsp; \u5f71\u54cd glibc\u662fGNU\u53d1\u5e03\u7684libc\u5e93\uff0c\u5373c\u8fd0\u884c\u5e93\u3002\u5b83\u662fLinux\u7cfb\u7edf\u4e2d\u6700\u5e95\u5c42\u7684API\uff0c\u51e0\u4e4e\u5176\u5b83\u8fd0\u884c\u5e93\u90fd\u4f1a\u4f9d\u8d56\u4e8eglibc\u3002\u5e76\u4e14glibc\u5e94\u7528\u4e8e\u4f17\u591aLinux ...<a href=https:\/\/www.deepin.org.cn\/zh\/security-update%ef%bc%88cve-2015-7547%ef%bc%89\/>\u9605\u8bfb\u66f4\u591a<\/a><\/p>\n","protected":false},"author":1,"featured_media":12465,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[75],"tags":[],"_links":{"self":[{"href":"https:\/\/www.deepin.org.cn\/zh\/wp-json\/wp\/v2\/posts\/12450"}],"collection":[{"href":"https:\/\/www.deepin.org.cn\/zh\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.deepin.org.cn\/zh\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.deepin.org.cn\/zh\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.deepin.org.cn\/zh\/wp-json\/wp\/v2\/comments?post=12450"}],"version-history":[{"count":4,"href":"https:\/\/www.deepin.org.cn\/zh\/wp-json\/wp\/v2\/posts\/12450\/revisions"}],"predecessor-version":[{"id":21522,"href":"https:\/\/www.deepin.org.cn\/zh\/wp-json\/wp\/v2\/posts\/12450\/revisions\/21522"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.deepin.org.cn\/zh\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/www.deepin.org.cn\/zh\/wp-json\/wp\/v2\/media?parent=12450"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.deepin.org.cn\/zh\/wp-json\/wp\/v2\/categories?post=12450"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.deepin.org.cn\/zh\/wp-json\/wp\/v2\/tags?post=12450"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}