SQLite Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-05-13

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5018£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ß¼¶£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.1£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾

SQLite 3.26.0¡¢3.27.0


Îó²î¸ÅÊö


SQLiteÊÇÒ»¿îÊ¢ÐеÄSQLÊý¾Ý¿âÒýÇæ£¬£¬£¬£¬£¬¾ßÓÐСÐÍ£¬£¬£¬£¬£¬¿ìËÙ£¬£¬£¬£¬£¬¿É¿¿µÄÌØµã£¬£¬£¬£¬£¬ÆÕ±éÓÃÓÚÒÆ¶¯×°±¸£¬£¬£¬£¬£¬ä¯ÀÀÆ÷£¬£¬£¬£¬£¬Ó²¼þ×°±¸ÒÔ¼°Óû§Ó¦ÓóÌÐò¡£¡£¡£


SQLiteµÄ´°¿Úº¯ÊýÖб£´æ¿É±»Ê¹ÓõÄuse-after-freeÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâSQLÏÂÁîÀ´´¥·¢´ËÎó²î£¬£¬£¬£¬£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£


Îó²îÑéÖ¤


Ïêϸϸ½ÚΪ£¬£¬£¬£¬£¬SQLiteÔÚ¶Ô°üÀ¨´°¿Úº¯ÊýµÄSELECTÓï¾ä¾ÙÐÐÆÊÎöºó£¬£¬£¬£¬£¬Ê¹ÓÃsqlite3WindowRewriteº¯Êý¶Ô¸ÃSELECTÓï¾ä¾ÙÐÐת»»¡£¡£¡£


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ôڴ˺¯ÊýÖУ¬£¬£¬£¬£¬ÈôÊǸÃSELECTÓï¾ä°üÀ¨¾ÛºÏº¯Êý£¨COUNT£¬£¬£¬£¬£¬MAX£¬£¬£¬£¬£¬MIN£¬£¬£¬£¬£¬AVG£¬£¬£¬£¬£¬SUM£©£¬£¬£¬£¬£¬ÔòÖØÐ´SELECT¹¤¾ßÉúÑĵıí´ïʽÁÐ±í£¨ÏÂͼÖеÚ[0]ÐУ©¡£¡£¡£


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ö÷´°¿Ú¹¤¾ßpMWinÈ¡×ÔSELECT¹¤¾ß£¬£¬£¬£¬£¬²¢ÔÚÖØÐ´Ê±´ú±»Ê¹ÓÃ[1]¡£¡£¡£±éÀúSELECT¹¤¾ßµÄ±í´ïʽÁÐ±í£¬£¬£¬£¬£¬ÖØÐ´´°¿Úº¯ÊýÒÔ±ãÓÚ´¦Öóͷ£¡£¡£¡£


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


×¢ÖØÖ÷´°¿Ú¹¤¾ßÔÚWindowRewrite¹¤¾ßÖÐʹÓᣡ£¡£ÔÚÑ­»·´¦Öóͷ£Ã¿Ò»¸ö±í´ïʽʱ£¬£¬£¬£¬£¬½«xExprCallbackº¯Êý×÷Ϊ»Øµ÷º¯Êý¡£¡£¡£µ±´¦Öóͷ£¾ÛºÏº¯Êý£¨TK AGG FUNCTION£©ºó£¬£¬£¬£¬£¬±í´ïʽ±»É¾³ý[2]¡£¡£¡£


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÈôÊDZ»É¾³ýµÄ±í´ïʽ±»±ê¼ÇΪ´°¿Úº¯Êý£¬£¬£¬£¬£¬ÔòÒ²»áɾ³ý¹ØÁªµÄWindow¹¤¾ß¡£¡£¡£


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


²¢É¾³ý¸ÃWindow¹¤¾ß¹ØÁªµÄ·ÖÇø¡£¡£¡£


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


»ØÊ׳õʼµÄsqlite3WindowRewriteº¯Êý£¬£¬£¬£¬£¬·¢Ã÷¸Ãº¯ÊýÔÚÖØÐ´±í´ïʽÁбí[4]Ö®ºóͨ¹ýexprListAppendListÖØÓÃÕâ¸ö±»É¾³ýµÄ·ÖÇø[5]£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂuse-after-freeºÍ¾Ü¾øÐ§ÀÍ¡£¡£¡£ÈôÊǹ¥»÷Õß¿ÉÒÔ¿ØÖÆfreeºóµÄÄڴ棬£¬£¬£¬£¬Ôò¿ÉÄÜÆÆËð¸ü´ó¶¼¾Ý£¬£¬£¬£¬£¬´Ó¶øµ¼Ö´úÂëÖ´ÐС£¡£¡£


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¿ÉÒÔʹÓÃDebug°æ±¾µÄsqlite3ÏÈÇå¿Õ±»freeµÄ»º³åÇøµÄÄÚÈÝ£¬£¬£¬£¬£¬ÒÔ¸üºÃµØ¾ÙÐÐÑÝʾ[5]¡£¡£¡£


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ͨ¹ýgdb sqlite3ÔËÐÐPoC£¬£¬£¬£¬£¬¿ÉÊӲ쵽0xfafafafafafafafaÖÜΧ±¬·¢Í߽⣬£¬£¬£¬£¬ÕâÒâζ×ŶÔÒÑÊͷŵĻº³åÇøµÄÔٴλá¼û£º


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ʹÓÃsqlite3 shellÔËÐÐPoC£º


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÐÞ¸´½¨Òé


ÏÖÔÚSQLite³§ÉÌÕë¶Ô¸ÃÎó²îÐû²¼ÁËÎó²î²¹¶¡£¡£¡£¬£¬£¬£¬£¬Çë¸üÐÂÖÁSQLite3 3.28.0£ºhttps://www.sqlite.org/src/info/69bad9257f8db6a2¡£¡£¡£


²Î¿¼Á´½Ó


https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0777/