Zip Slip·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-06-06·ì϶±àºÅ
CVE-2018-8008
CVE-2018-8009
CVE-2018-1261
CVE-2018-1263
CVE-2018-1002200
CVE-2018-1002201
CVE-2018-1002202
CVE-2018-1002203
CVE-2018-1002204
CVE-2018-1002205
CVE-2018-1002206
CVE-2018-1002207
·ì϶¼¶±ð
ÑϳÁ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
Zip Slip·ì϶ ¡°ËÁÒâÎļþ¸²¸Ç¡±ºÍ¡°Ä¿Â¼±éÀú¡±ÎÊÌâµÄ½áºÏ£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö¹¥»÷ÕßÄܹ»½«Îļþ½âѹËõµ½Õý³£½âѹËõõè¾¶Ö®±í²¢¸²¸ÇÃô¸ÐÎļþ£¬£¬£¬£¬£¬£¬£¬Èç¹Ø¼üOS¿â»ò·þÎñÆ÷ÅäÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£¹ÌȻʹÓü¸ÖÖ±à³Ì˵»°±àдµÄ¿âÒÑÖª»áÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬ÀýÈçJavaScript£¬£¬£¬£¬£¬£¬£¬Python£¬£¬£¬£¬£¬£¬£¬Ruby£¬£¬£¬£¬£¬£¬£¬.NET£¬£¬£¬£¬£¬£¬£¬GoºÍGroovy£¬£¬£¬£¬£¬£¬£¬µ«Õâ¸öÎÊÌâÖØÒªÓ°ÏìJavaÉú̬ϵͳ¡£¡£¡£¡£¡£¡£¡£
Zip Slip·ì϶ÊÇÔÚ±àÂëÆ÷¡¢²å¼þºÍ¿âʵÏÖ½âѹ¹éµµÎļþµÄ¹ý³ÌÖеÄÒ»¸öÎÊÌâ¡£¡£¡£¡£¡£¡£¡£ ºÜ¶à´ò°üÌåʽ£¬£¬£¬£¬£¬£¬£¬Ô̺¬tar£¬£¬£¬£¬£¬£¬£¬jar£¬£¬£¬£¬£¬£¬£¬war£¬£¬£¬£¬£¬£¬£¬cpio£¬£¬£¬£¬£¬£¬£¬apk£¬£¬£¬£¬£¬£¬£¬rarºÍ7z³ÇÊÐÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÕâ¸üÏñÊÇÂß¼ÎÊÌ⣬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇÌØ¶¨µÄ±àÂëÃýÎ󡣡£¡£¡£¡£¡£¡£
¶à¸ö´óÐ͹«Ë¾£¬£¬£¬£¬£¬£¬£¬Ô̺¬Google¡¢Oracle¡¢IBM¡¢Apache¡¢ÑÇÂíÑ·µÈÔÚÄÚµÄÊýǧ¸öÏîÄ¿ÊÜÓ°Ï죨¼û£ºhttps://github.com/snyk/zip-slip-vulnerability£©¡£¡£¡£¡£¡£¡£¡£µ±È»£¬£¬£¬£¬£¬£¬£¬ÕâÖÖÀàÐ͵ķì϶ÔçÒÑ´æÔÚ£¬£¬£¬£¬£¬£¬£¬µ«×î½üËüÒѾÔÚ¸ü¶àµÄÏîÄ¿ºÍ¿âÖвû·¢³öÀ´¡£¡£¡£¡£¡£¡£¡£
ÊÜÓ°ÏìµÄ¿âºÍÏîÄ¿£º
ÊÜÓ°ÏìµÄ¿â£º
ÊÜÓ°ÏìµÄÏîÄ¿£º
·ìϼûèÊö
Zip SlipÊÇĿ¼±éÀúµÄÒ»ÖÖ´ó¾Ö£¬£¬£¬£¬£¬£¬£¬Äܹ»Í¨¹ý´Ó´ò°üÎļþÖÐÌáÈ¡ÎļþÀ´ÀûÓᣡ£¡£¡£¡£¡£¡£ Ŀ¼±éÀú·ì϶µÄǰÌáÊǹ¥»÷ÕßÄܹ»½Ó¼ûÎļþϵͳÖÐÓ¦¸ÃפÁôµÄÖ¸±êÎļþ¼ÐÖ®±íµÄ²¿ÃÅÎļþϵͳ¡£¡£¡£¡£¡£¡£¡£ ¶øºó£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»¸²¸Ç¿ÉÖ´ÐÐÎļþ²¢Ô¶³ÌŲÓÃËüÃÇ£¬£¬£¬£¬£¬£¬£¬»òÕßÆÚ´ýϵͳ»òÓû§Å²ÓÃËüÃÇ£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖÊܺ¦Õß»úеÉϵÄÔ¶³ÌºÅÁîÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£´Ë·ì϶»¹¿ÉÄÜͨ¹ý¸²¸ÇÅäÖÃÎļþ»òÆäËûÃô¸Ð×ÊÔ´¶øÔì³ÉÇÖº¦£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜ»áÔÚ¿Í»§¶Ë£¨Óû§£©»úеºÍ·þÎñÆ÷ÉÏÊܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£
Ò²¾ÍÊÇ˵£¬£¬£¬£¬£¬£¬£¬Zip SlipÊÇ¡°ËÁÒâÎļþ¸²¸Ç¡±ºÍ¡°Ä¿Â¼±éÀú¡±ÎÊÌâµÄ½áºÏ£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö¹¥»÷ÕßÄܹ»½«Îļþ½âѹËõµ½Õý³£½âѹËõõè¾¶Ö®±í²¢¸²¸ÇÃô¸ÐÎļþ£¬£¬£¬£¬£¬£¬£¬Èç¹Ø¼üOS¿â»ò·þÎñÆ÷ÅäÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£
·ì϶POC£ºhttps://github.com/snyk/zip-slip-vulnerability/tree/master/archives
ÀûÓô˷ì϶±ØÒªµÄÁ½¸ö²¿ÃÅÊDz»Ö´ÐÐÑéÖ¤²é³µÄ¶ñÒâ¹éµµºÍÌáÈ¡´úÂë¡£¡£¡£¡£¡£¡£¡£ÈÃÎÒÃÇ˳´Î²é¿´ÕâÁ½²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£Ê×ÏÈ£¬£¬£¬£¬£¬£¬£¬zipÎļþµÄÄÚÈÝÔÚÌáȡʱ±ØÒªÓÐÒ»¸ö»ò¶à¸öÍÑÀëÖ¸±êĿ¼µÄÎļþ¡£¡£¡£¡£¡£¡£¡£±ÉÈËÃæµÄÀý×ÓÖУ¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÄܹ»¿´µ½Ò»¸özipÎļþµÄÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£ËüÓÐÁ½¸öÎļþ£¬£¬£¬£¬£¬£¬£¬Ò»¸ögood.shÎļþ½«±»½âѹËõµ½Ö¸±êĿ¼ÖУ¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öevil.shÎļþÔÚ³¢ÊÔ±éÀúĿ¼Ê÷ÒÔ´ò¿ª¸ùĿ¼£¬£¬£¬£¬£¬£¬£¬¶øºó½«ÎļþÔö³¤µ½tmpĿ¼ÖÓ×£¡£¡£¡£¡£¡£¡£µ±Äú³¢ÊÔcd .. ÔÚ¸ùĿ¼ÖÐʱ£¬£¬£¬£¬£¬£¬£¬ÒÀÈ»»á·¢ÏÖ×Ô¼ºÎ»ÓÚ¸ùĿ¼ÖУ¬£¬£¬£¬£¬£¬£¬Òò¶ø¶ñÒâõè¾¶¿ÉÄÜÔ̺¬¶à¸ö¼¶´ËÍâĿ¼ ../ ÔÚ³¢ÊÔ±éÀúÃô¸ÐÎļþ֮ǰ£¬£¬£¬£¬£¬£¬£¬ÓиüºÃµÄ»úÓö´ïµ½¸ùĿ¼¡£¡£¡£¡£¡£¡£¡£
Õâ¸özipÎļþµÄÄÚÈݱØÐëÊÖ¹¤Ôì×÷¡£¡£¡£¡£¡£¡£¡£Ö»¹Üzip¹æ·¶ÔÊÐí£¬£¬£¬£¬£¬£¬£¬µµ°¸´´½¨¹¤¾ßͨ³£²»ÔÊÐíÓû§Ê¹ÓÃÕâЩõè¾¶Ôö³¤Îļþ¡£¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÌØ¶¨µÄ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÕâЩõè¾¶´´½¨ÎļþºÜÈÝÒס£¡£¡£¡£¡£¡£¡£
Äú±ØÒªÀûÓô˷ì϶µÄµÚ¶þ¼þÊÂÊÇʹÓÃÄú×Ô¼ºµÄ´úÂë»ò¿âÀ´ÌáÈ¡¹éµµÎļþ¡£¡£¡£¡£¡£¡£¡£½âѹËõ´úÂëºöÂÔ´æµµÖÐÎļþõè¾¶µÄÑé֤ʱ´æÔÚ´Ë·ì϶¡£¡£¡£¡£¡£¡£¡£ÏÂÃæÊÇÒ»¸öÒ×Êܹ¥»÷µÄ´úÂëÆ¬¶ÎµÄʾÀý£¨ÒÔJavaÏÔʾµÄʾÀý£©¡£¡£¡£¡£¡£¡£¡£
½â¾ö´ëÊ©
Òѽ¨¸´µÄ¿âºÍÏîÄ¿Á´½Ó¼û£ºhttps://github.com/snyk/zip-slip-vulnerability
²Î¿¼×ÊÁÏ
https://github.com/snyk/zip-slip-vulnerability
http://7xkk1o.com1.z0.glb.clouddn.com/technical-whitepaper.pdf#page=8&zoom=auto,-99,199
https://github.com/snyk/zip-slip-vulnerability/tree/master/archives


¾©¹«Íø°²±¸11010802024551ºÅ