Coremail·þÎñδÊÚȨ»á¼ûºÍ·þÎñ½Ó¿Ú²ÎÊý×¢ÈëÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-19

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾

ÊÊÓÃÓÚCoremail XT 3.0.4ÖÁ XT 5.0.8A°æ±¾¡£


Îó²î¸ÅÊö


CoremailÓʼþϵͳÊÇÂۿͿƼ¼£¨¹ãÖÝ£©ÓÐÏÞ¹«Ë¾£¨ÒÔϼò³ÆÂۿ͹«Ë¾£©×ÔÖ÷Ñз¢µÄ´óÐÍÆóÒµÓʼþϵͳ£¬Coremail²»µ«ÎªÍøÒ×£¨126¡¢163¡¢yeah£©¡¢Òƶ¯£¬ÁªÍ¨µÈ×ÅÃûÔËÓªÉÌÌṩµç×ÓÓʼþÕûÌåÊÖÒÕ½â¾ö¼Æ»®¼°ÆóÒµÓʾÖÔËÓª·þÎñ£¬»¹ÎªÊ¯ÓÍ¡¢¸ÖÌú¡¢µçÁ¦¡¢Õþ¸®¡¢½ðÈÚ¡¢½ÌÓý¡¢¼â¶ËÖÆÔìÆóÒµµÈÓû§ÌṩÓʼþϵͳÈí¼þºÍ·´À¬»ø·þÎñ¡£


CoremailÓʼþϵͳ±£´æ·þÎñδÊÚȨ»á¼ûÎó²î£¨CNVD-C-2019-78549£©ºÍ·þÎñ½Ó¿Ú²ÎÊý×¢ÈëÎó²î£¨CNVD-C-2019-78550£©¡£CoremailÓʼþϵͳapiwsÄ£¿éÉϵIJ¿·ÖWebService·þÎñ±£´æ»á¼ûÕ½ÂÔȱÏݺÍijAPI·þÎñ²ÎÊý±£´æ×¢ÈëȱÏÝ£¬Ê¹µÃ¹¥»÷Õß×ÛºÏʹÓÃÉÏÊöÎó²î£¬ÔÚδÊÚȨµÄÇéÐÎÏÂÔ¶³Ì»á¼ûCoremail²¿·Ö·þÎñ½Ó¿Ú£¬Í¨¹ý²ÎÊý½á¹¹×¢Èë¾ÙÐÐÎļþ²Ù×÷¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ£¬Âۿ͹«Ë¾ÒÑÐû²¼²¹¶¡¾ÙÐÐÐÞ¸´£º


1¡¢Õë¶ÔCoremail XT3/CM5°æ±¾£¬²¹¶¡±àºÅΪCMXT3-2019-0001£¬³ÌÐò°æ±¾ºÅXT3.0.8 dev build 20190610(cb3344cf)£»
2¡¢Õë¶ÔCoremail XT5£¬²¹¶¡±àºÅΪCMXT5-2019-0001£¬³ÌÐò°æ±¾ºÅXT5.0.9a build 20190604(696d1518)¡£
ÈçÒÑ×°ÖõijÌÐò°üµÄ°æ±¾ºÅÈÕÆÚÔçÓÚ20190604£¬½¨ÒéÓû§ÊµÊ±¸üв¹¶¡£ºÓû§¿ÉÒÔÔÚCoremailÔÆ·þÎñÖÐÐĵIJ¹¶¡¹ÜÀíÄ£¿é£¬Æ¾Ö¤²¹¶¡±àºÅÏÂÔØ²¢Æ¾Ö¤²Ù×÷Ö¸Òý¾ÙÐÐÊÖ¶¯¸üС£
ÔÝʱÐÞ²¹¼Æ»®ÈçÏ£º
1¡¢ÔÚ²»Ó°ÏìÕý³£Ê¹ÓõÄÇéÐÎÏ£¬Í¨¹ý°²ÅÅVPN·þÎñÏÞÖÆ¶ÔCoremail·þÎñÆ÷µÄ¹«Íø»á¼û£»
2¡¢ÔÚWeb·þÎñÆ÷£¨nginx/apache£©ÉÏÏÞÖÆÍâÍø¶Ô /apiws ·¾¶µÄ»á¼û¡£

½¨ÒéʹÓÃCoremail²úÆ·¹¹½¨Óʼþ·þÎñµÄÐÅϢϵͳÔËÓªÕߣ¬Á¬Ã¦×Լ죬·¢Ã÷±£´æÎó²îʵʱÐÞ¸´¡£


²Î¿¼Á´½Ó


 https://mp.weixin.qq.com/s/cU4wSGQ_dNSoOk0VjEJffA