Alpine Linux DockerÇå¾²Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-05-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-5021£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬ £¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬ £¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾

Alpine Linux Docker 3.3°æ±¾£¬ £¬£¬3.4°æ±¾£¬ £¬£¬3.5°æ±¾£¬ £¬£¬3.6°æ±¾£¬ £¬£¬3.7°æ±¾£¬ £¬£¬3.8°æ±¾£¬ £¬£¬3.9°æ±¾£¬ £¬£¬Edge°æ±¾


Îó²î¸ÅÊö


Alpine Linux DockerÊÇÒ»¸öAlpine LinuxϵͳµÄ¾µÏñ¡£¡£¡£¡£¡£¡£¡£¡£


Alpine Linux Docker¾µÏñµÄ°æ±¾£¨×Ôv3.3Æð£©°üÀ¨rootÓû§µÄNULLÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£Õâ¸öÎó²îÔâʹÓõĿÉÄÜÐÔÒÀÀµÓÚÇéÐΣ¬ £¬£¬ÀÖ³ÉʹÓÃÒªÇó±»Ì»Â¶µÄЧÀÍ»òÓ¦ÓóÌÐòʹÓÃLinux PAM»òÕ߯äËüʹÓÃϵͳshadowÎļþ×÷ΪÈÏÖ¤Êý¾Ý¿âµÄ»úÖÆ¡£¡£¡£¡£¡£¡£¡£¡£


Õâ¸öÎó²î×î³õ¾Ý³Æ±£´æÓÚAlpine Linux Docker¾µÏñ3.2°æ±¾Öв¢ÓÚ2015Äê11ÔÂÐÞ¸´£¬ £¬£¬Í¨¹ýÌí¼Ó»Ø¹é²âÊÔ×èÖ¹ÆäÔٴα¬·¢¡£¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬ £¬£¬2015ÄêÄê⣬ £¬£¬Ò»¸öеÄÌá½»Ðû²¼ÒÔ¼ò»¯¸Ã»Ø¹é²âÊÔ¡£¡£¡£¡£¡£¡£¡£¡£ºóÐøÌá½»´Ó¡®edge¡¯¹¹½¨ÊôÐÔÎļþÖÐɾ³ýÁË¡°Ä¬ÈÏÇéÐÎϽûÓÃroot¡±µÄ±ê¼Ç£¬ £¬£¬µ¼Ö¸ÃbugÔÚ¾µÏñµÄÏÂÒ»Åú°æ±¾£¨v3.3µ½3.9£©Öлع顣¡£¡£¡£¡£¡£¡£¡£Ð§¹û¾ÍÊÇ/etc/shadowÖзºÆð¿Õsp_pwdp×ֶΣ¬ £¬£¬¼´½«ÃÜÂëÒÔ¼ÓÃÜÐÎʽÉúÑĵÄÉèÖÃÎļþÓû§ÕË»§ÖÎÀí£¬ £¬£¬´Ó¶øÔÊÐíÔÚÎÞÐèÊäÈëÈκÎÃÜÂëµÄÇéÐÎÏÂÒÔ¸ùȨÏ޵Ǽ¡£¡£¡£¡£¡£¡£¡£¡£


Alpine Linux Docker ¹Ù·½¾µÏñµÄÏ´δÎÊýÒÑÁè¼Ý1000Íò´Î¡£¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼ÒÔϰ汾½â¾ö´ËÇå¾²ÎÊÌ⣺https://alpinelinux.org/posts/Docker-image-vulnerability-CVE-2019-5021.html¡£¡£¡£¡£¡£¡£¡£¡£


edge (20190228 snapshot)
v3.9.2
v3.8.4
v3.7.3

v3.6.5


Èçϰ汾ûÓнâ¾ö´ËÇå¾²ÎÊÌ⣺
v3.5
v3.4

v3.3


ÈôÊÇʹÓÃÈκνϾɵIJ»ÊÜÖ§³ÖµÄ°æ±¾£¬ £¬£¬ÄÇôÄú¿ÉÒÔͨ¹ý½«´ËÐÐÌí¼Óµ½DockerfileÀ´ÐÞ¸´Ëü£¬ £¬£¬È·±£½ûÓÃrootµÇ¼£º

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


²Î¿¼Á´½Ó


https://alpinelinux.org/posts/Docker-image-vulnerability-CVE-2019-5021.html


https://talosintelligence.com/vulnerability_reports/TALOS-2019-0782