Intel Wi-FiÇý¶¯·ì϶·ÖÎö
°ä²¼¹¦·ò 2021-04-27Intel Wi-FiоƬ¿í·ºÀûÓÃÓÚÓ×ÎұʼDZ¾µçÄÔ²úÆ·£¬£¬£¬£¬£¬£¬ÈçThinkPad¡¢Dell±Ê¼Ç±¾µÈ¡£¡£¡£¡£¡£¡£¡£¡£2020Ä꣬£¬£¬£¬£¬£¬ZDI×éÖ¯Åû¶ÁËIntelÎÞÏßÍø¿¨WindowsÇý¶¯·¨Ê½ÖдæÔÚCVE-2020-0557 ºÍ CVE-2020-0558·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬CVE-2020-0557µÄCVSS v3.0ÆÀ·ÖΪ 8.1 ·Ö£¬£¬£¬£¬£¬£¬CVE-2020-0558µÄCVSS v3.0ÆÀ·ÖΪ 8.2 ·Ö¡£¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÕâÁ½¸ö·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÔÚÊܺ¦ÕßµçÄÔÖÐÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
| ·ì϶±àºÅ | Ó°ÏìµÄÎÞÏßÍø¿¨ | Ó°ÏìÇý¶¯ |
| CVE-2020-0557 | AC 7265 Rev D¡¢AC 3168¡¢AC 8265ºÍAC8260 | Intel PROSet/Wireless WiFi Software 21.70֮ǰ°æ±¾ |
| CVE-2020-0558 | AC8265 | Intel PROSet/Wireless WiFi Software 21.70֮ǰ°æ±¾ |
CVE-2020-0558·ì϶·ÖÎö
1¡¢·ì϶µÀÀí
µ±APÈȵ㴦ÖÃAssocReqʱ£¬£¬£¬£¬£¬£¬»áŲÓÃprvhPanClientSaveAssocRespº¯Êý±£ÁôAssocReqÖ¡ÖÐSSIDµÄÖµ£¬£¬£¬£¬£¬£¬ÔÚ´¦ÖÃSSIDµÄ¹ý³ÌÖУ¬£¬£¬£¬£¬£¬»áŲÓÃparse_ieº¯Êý´ÓÊý¾ÝÖ¡ÖÐÈ¡³össidµÄTLV½á¹¹£¬£¬£¬£¬£¬£¬²¢Å²ÓÃmemcpy_sº¯Êý½«ssidµÄÄÚÈݸ´Ôìµ½Ö¸±ê»º³åÇø¡£¡£¡£¡£¡£¡£¡£¡£ÔÚŲÓÃmemcpy_sº¯ÊýµÄʱ³½£¬£¬£¬£¬£¬£¬ÃýÎóµØÊ¹ÓÃssidµÄlength×÷ΪÊý¾Ý¸´Ô쳤¶È£¬£¬£¬£¬£¬£¬µ±ssidµÄ³¤¶È´óÓÚÖ¸±ê»º³åÇøµÄ³¤¶Èʱ£¬£¬£¬£¬£¬£¬»áµ¼Ö»º³åÇøÒç³ö¡£¡£¡£¡£¡£¡£¡£¡£º¯ÊýŲÓÃͼÈçÏÂËùʾ£º

2¡¢ÎÊÌâ´úÂë
ŲÓÃparse_ieº¯Êý´ÓÊý¾ÝÖ¡ÖÐÈ¡³össidµÄTLV½á¹¹£¬£¬£¬£¬£¬£¬²¢Å²ÓÃmemcpy_sº¯Êý½«ssidµÄÄÚÈݸ´Ôìµ½Ö¸±ê»º³åÇø¡£¡£¡£¡£¡£¡£¡£¡£ÔÚŲÓÃmemcpy_sº¯ÊýµÄʱ³½£¬£¬£¬£¬£¬£¬ÃýÎóµØÊ¹ÓÃssidµÄlength×÷ΪÊý¾Ý¸´Ô쳤¶È£¬£¬£¬£¬£¬£¬µ±ssidµÄ³¤¶È´óÓÚÖ¸±ê»º³åÇøµÄ³¤¶Èʱ£¬£¬£¬£¬£¬£¬»áµ¼Ö»º³åÇøÒç³ö¡£¡£¡£¡£¡£¡£¡£¡£±ÉÈËͼÖУ¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»½ÚÔì*(v8+1)µÄÖµ£¬£¬£¬£¬£¬£¬Äܹ»¿½±´³¬³¤µÄÊý¾Ý¸´Ôìµ½Ö¸±êµØÖ·ÖУ¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö»º³åÇøÒç³ö¡£¡£¡£¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

3¡¢·ì϶½¨¸´
а汾µÄ´úÂëÖÐʹÓÃosalMemoryCopyº¯Êý´úÌæÁËÔÀ´µÄmemcpy_sº¯Êý£¬£¬£¬£¬£¬£¬Áí±í°ÑSSID¿½±´µÄ×î´ó³¤¶ÈÇ¿ÔìÉèΪ32×Ö½Ú£¬£¬£¬£¬£¬£¬ÕâÑù¾ÍÔ¤·ÀÁË»º´æÇøÒç³öµÄÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

CVE-2020-0557·ì϶·ÖÎö
1¡¢·ì϶µÀÀí
µ±APÈȵ㴦ÖÃAssocReqʱ£¬£¬£¬£¬£¬£¬»áŲÓÃprvhPanClientSaveAssocRespº¯Êý´¦ÖÃAssocReqÖ¡ÖеÄÊý¾Ý£¬£¬£¬£¬£¬£¬ÆäÖÐÔÚº¯ÊýÖлáŲÓÃprvGoVifClientAssocStoreSupportedChannelsº¯ÊýÀ´´¦Öü°±£ÁôÒªÇó¶Ëͨ·ÐÅÏ¢£¬£¬£¬£¬£¬£¬ÕâÆäÖÐprvGoVifClientAssocStoreSupportedChannelsº¯Êý»áÑ»·Å²ÓÃutilRegulatoryClassToChannelListÀ´´¦ÖÃRegulatoryClass£¨¹ÜÔìÒªÇó£©ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÔÚÑ»·´¦ÖÃûÓÐ˼¿¼Ö¸±êµÄÆ«ÒÆÊÇ·ñÔ½½ç£¬£¬£¬£¬£¬£¬µ±APÈȵã½Ó¹Üµ½AssocReqÊý¾ÝÖ¡ÖÐRegulatoryClassÐÅÏ¢µ¥ÔªÓжà¸öÐÅ·Êý¾Ýʱ»áµ¼ÖÂÔ½½çд¡£¡£¡£¡£¡£¡£¡£¡£º¯ÊýŲÓÃͼÈçÏÂͼËùʾ£º

2¡¢ÎÊÌâ´úÂë
prvGoVifClientAssocStoreSupportedChannelsº¯Êý£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


3¡¢·ì϶½¨¸´
ÔÚа汾 ÍÆ½øÁ˶Ե±Ç°indexµÄÅжϣ¬£¬£¬£¬£¬£¬ÈôÊÇindex´óÓÚ255ÔòÍ˳öÑ»·¡£¡£¡£¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

4¡¢·ì϶ÑéÖ¤
²Î¿¼Á´½Ó£º
¡¾1¡¿https://www.thezdi.com/blog/2020/5/4/analyzing-a-trio-of-remote-code-execution-bugs-in-intel-wireless-adapters
8827Ì«Ñô¼¯ÍÅ»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©
ADLab³ÉÁ¢ÓÚ1999Ä꣬£¬£¬£¬£¬£¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬£¬£¬£¬£¬£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬£¬£¬£¬£¬£¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£¡£¡£¡£¡£¡£¡£¡£½ØÖ¹Ä¿Ç°£¬£¬£¬£¬£¬£¬ADLabÒÑͨ¹ýCVEÀۼư䲼°²È«·ì϶½ü1100¸ö£¬£¬£¬£¬£¬£¬Í¨¹ý CNVD/CNNVDÀۼư䲼°²È«·ì϶1000Óà¸ö£¬£¬£¬£¬£¬£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£¡£¡£¡£¡£¡£¡£¡£³¢ÊÔÊÒ×êÑз½Ïòº¸Ç²Ù×÷ϵͳÓëÀûÓÃϵͳ°²È«×êÑÓ×¢ÖÇÄÜÖն˰²È«×êÑÓ×¢ÎïÁªÍøÖÇÄÜÉ豸°²È«×êÑÓ×¢Web°²È«×êÑÓ×¢¹¤¿ØÏµÍ³°²È«×êÑÓ×¢ÔÆ°²È«×êÑС£¡£¡£¡£¡£¡£¡£¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£¡£¡£¡£¡£¡£¡£¡£



¾©¹«Íø°²±¸11010802024551ºÅ