BIND»º³åÇøÒç³öÎó²î£¨CVE-2021-25216£©

Ðû²¼Ê±¼ä 2021-04-30

0x00 Îó²î¸ÅÊö

CVE  ID

CVE-2021-25216

ʱ   ¼ä

2021-04-30

Àà   ÐÍ

»º³åÇøÒç³ö

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

BIND£¨Berkeley Internet Name Domain £¬£¬£¬ £¬£¬£¬²®¿ËÀûÒòÌØÍøÃû³ÆÓò£©Ð§ÀÍÊÇÈ«Çò¹æÄ£ÄÚʹÓÃ×îÆÕ±é¡¢ ×îÇå¾²¿É¿¿ÇÒ¸ßЧµÄÓòÃûÆÊÎöЧÀͳÌÐò¡£¡£¡£¡£ ¡£¡£

2021Äê04ÔÂ28ÈÕ £¬£¬£¬ £¬£¬£¬ISCÐû²¼Ç徲ͨ¸æ £¬£¬£¬ £¬£¬£¬¹ûÕæÁËBINDÖеÄÒ»¸ö»º³åÇøÒç³öÎó²î£¨CVE-2021-25216£© £¬£¬£¬ £¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.1¡£¡£¡£¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î´¥·¢»º³åÇøÒç³ö £¬£¬£¬ £¬£¬£¬×îÖÕµ¼ÖÂЧÀÍÆ÷±ÀÀ£»£»£» £»òÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£ ¡£¡£

 

Îó²îϸ½Ú

¸ÃÎó²î±£´æÓÚBINDʹÓõÄSPNEGOÖÐ £¬£¬£¬ £¬£¬£¬ÈôÊÇBINDЧÀÍÆ÷ÉèÖÃΪʹÓÃGSS-TSIG¹¦Ð§ £¬£¬£¬ £¬£¬£¬Ôò±£´æ´ËÎó²î¡£¡£¡£¡£ ¡£¡£GSS-TSIGÊǶÔTSIGЭÒéµÄÀ©Õ¹ £¬£¬£¬ £¬£¬£¬Ö¼ÔÚÖ§³ÖÇå¾²½»Á÷ÃÜÔ¿ £¬£¬£¬ £¬£¬£¬ÓÃÓÚÑéÖ¤ÍøÂçÉϸ÷·½Ö®¼äͨѶµÄÕæÊµÐÔ £¬£¬£¬ £¬£¬£¬SPNEGOÊÇGSSAPIʹÓõÄÒ»ÖÖЭÉÌ»úÖÆ £¬£¬£¬ £¬£¬£¬ÊÇGSS-TSIGµÄÓ¦ÓÃЭÒé½Ó¿Ú¡£¡£¡£¡£ ¡£¡£

BINDĬÈÏÉèÖò»»á̻¶Ò×Êܹ¥»÷µÄ´úÂë·¾¶ £¬£¬£¬ £¬£¬£¬µ«Í¨¹ýÉèÖÃtkey-gssapi-keytab»òtkey-gssapi-credentialÉèÖÃÑ¡ÏîµÄÖµ £¬£¬£¬ £¬£¬£¬¿ÉÒÔʹЧÀÍÆ÷Êܵ½¹¥»÷¡£¡£¡£¡£ ¡£¡£±ðµÄ £¬£¬£¬ £¬£¬£¬GSS-TSIG¾­³£±»ÓÃÓÚBINDÓëSamba¼¯³ÉµÄÍøÂçÖÐ £¬£¬£¬ £¬£¬£¬ÒÔ¼°BINDЧÀÍÆ÷ÓëActive DirectoryÓò¿ØÖÆÆ÷Á¬ÏµµÄ»ìÏýЧÀÍÆ÷ÇéÐÎÖÐ £¬£¬£¬ £¬£¬£¬ÕâÖÖÇéÐÎϵÄISC SPNEGOÈÝÒ×Êܵ½Õë¶Ô´ËÎó²îµÄ¹¥»÷ £¬£¬£¬ £¬£¬£¬ÏêϸӰÏìÈ¡¾öÓÚBINDËùʹÓõÄCPU¼Ü¹¹£º

Named£¨64룩£ºCVSSÆÀ·Ö7.4 £¬£¬£¬ £¬£¬£¬´ËÎó²î¿É´¥·¢»º³åÇøÒç³ö £¬£¬£¬ £¬£¬£¬´Ó¶øµ¼ÖÂЧÀÍÆ÷Í߽⡣¡£¡£¡£ ¡£¡£

Named£¨32룩£ºCVSSÆÀ·Ö8.1 £¬£¬£¬ £¬£¬£¬´ËÎó²î¿É´¥·¢»º³åÇøÒç³öµ¼ÖÂЧÀÍÆ÷Í߽⠣¬£¬£¬ £¬£¬£¬²¢Ô¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£ ¡£¡£

 

Ó°Ïì¹æÄ£

BIND 9.5.0 - 9.11.29

BIND 9.12.0- 9.16.13

BINDÖ§³ÖµÄÔ¤ÀÀ°æ9.11.3-S1 - 9.11.29-S1ºÍ 9.16.8-S1 - 9.16.13-S1

ÒÔ¼°BIND 9.17·ÖÖ§¿¯ÐаæBIND 9.17.0 - 9.17.1¡£¡£¡£¡£ ¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ´ËÎó²îÒѾ­ÐÞ¸´ £¬£¬£¬ £¬£¬£¬½¨ÒéÉý¼¶µ½ÒÔϰ汾£º

BIND 9.11.31

BIND 9.16.15

BINDÖ§³ÖµÄÔ¤ÀÀ°æ£¨ÊÊÓÃÓÚÇкÏÌõ¼þµÄISCÖ§³Ö¿Í»§£©£º

BIND 9.11.31-S1

BIND 9.16.15-S1

 

½â¾öÒªÁ죺

´ËÎó²î½öÓ°ÏìÉèÖÃΪʹÓÃGSS-TSIGµÄЧÀÍÆ÷ £¬£¬£¬ £¬£¬£¬¿ÉÒÔͨ¹ýÑ¡Ôñ²»ÆôÓÃGSS-TSIG¹¦Ð§À´×èÖ¹¸ÃÎó²î¡£¡£¡£¡£ ¡£¡£

ÔÚ2021Äê4ÔµÄBINDÐû²¼Ö®ºó £¬£¬£¬ £¬£¬£¬ËùÓÐÖ§³ÖµÄ·ÖÖ§¶¼É¾³ýÁËisc-spnego £¬£¬£¬ £¬£¬£¬ÒÔ×èÖ¹´ËÎó²î £¬£¬£¬ £¬£¬£¬µ«ÐèҪϵͳʹÓÃÆäËü¿âºÍÍ·ÎļþÀ´Ö§³ÖGSS-TSIG¹¦Ð§ £¬£¬£¬ £¬£¬£¬³ý·ÇÔÚÑ¡Ôñ¹¹½¨Ñ¡ÏîʱÏò./configure¾ç±¾Ìṩ--without-gssapi²ÎÊýÀ´½ûÓÃÕâÖÖ¹¦Ð§¡£¡£¡£¡£ ¡£¡£

 

ÏÂÔØÁ´½Ó£º

https://gitlab.isc.org/isc-projects/bind9/-/blob/v9_11_31/HISTORY.md

https://gitlab.isc.org/isc-projects/bind9/-/blob/v9_16_15/HISTORY.md

 

0x03 ²Î¿¼Á´½Ó

https://kb.isc.org/docs/cve-2021-25216

https://us-cert.cisa.gov/ncas/current-activity/2021/04/29/isc-releases-security-advisory-bind

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25216

 

0x04 ʱ¼äÏß

2021-04-28  ISCÐû²¼Ç徲ͨ¸æ

2021-04-30  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png