¹Ù·½Ðû²¼
¾Ü¾øЧÀÍ
HTTP/2 ÐÒé±£´æ¾Ü¾øЧÀÍ©¶´(CVE-2023-44487)£¬´Ë©¶´ÔÊÐí¶ñÒâ¹¥»÷ÕßÌᳫÕë¶ÔHTTP/2 ЧÀÍÆ÷µÄDDoS¹¥»÷£¬Ê¹Óà HEADERS ºÍ RST_STREAM·¢ËÍÒ»×éHTTPÇëÇ󣬲¢Öظ´´ËģʽÒÔÔÚÄ¿±ê HTTP/2 ЧÀÍÆ÷ÉÏÉú³É´ó×ÚÁ÷Á¿¡£Í¨¹ýÔÚµ¥¸öÁ¬½ÓÖдò°ü¶à¸öHEADERSºÍRST_STREAMÖ¡£¬¿ÉÄܵ¼ÖÂÿÃëÇëÇóÁ¿ÏÔÖøÔö¼Ó£¬²¢µ¼ÖÂЧÀÍÆ÷ÉϵÄCPU ÀûÓÃÂʽϸߣ¬×îÖÕµ¼ÖÂ×ÊÔ´ºÄ¾¡£¬Ôì³É¾Ü¾øЧÀÍ¡£
CVSSÆÀ·Ö£º
CVE | V3.1 Vector(Base) | Base Score | V3.1 Vector(Temporal Score) | Temporal Score |
CVE-2023-44487 | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 7.5 | E:P/RL:O/RC:C | 6.7 |
ÊÜÓ°Ïì²úÆ·£º
²úÆ·Ãû³Æ | ÊÜÓ°Ïì°æ±¾ | »º½â¼Æ»® |
EDR6.0 | EDR6.0 | EDR6.0_CVE-2023-44487_install.sh |
IncloudOS | IncloudOS V6.x <= 6.8.1 | IncloudOS_CVE-2023-44487_Disable_HTP2.sh |
ÎÞ
©¶´½â¾ö¼Æ»®£ºÇëÓû§Ö±½ÓÁªÏµ¿Í»§Ð§ÀÍÈËÔ±£¬»ñÈ¡²¹¶¡ÒÔ¼°Ïà¹ØµÄ¼¼ÊõÖ§³Ö¡£
FAQ£ºÎÞ
¸üмͼ£º20231122-V1.0-Initial Release
pgµç×Ó¹ÙÍøÄþ¾²Ó¦¼±ÏìÓ¦¶ÔÍâЧÀÍ£º»ñÈ¡¼¼ÊõÖ§³Ö£º/lcjtww/2317452/2317456/2317460/index.html
±¾ÎĵµÌṩµÄËùÓÐÊý¾ÝºÍÐÅÏ¢½ö¹©²Î¿¼£¬ÇÒ"°´ÔÑù"Ìṩ£¬²»ÔÊÐíÈκÎÃ÷ʾ¡¢Ä¬Ê¾ºÍ·¨¶¨µÄµ£±££¬°üÀ¨(µ«²»ÏÞÓÚ)¶ÔÊÊÏúÐÔ¡¢ÊÊÓÃÐÔ¼°²»ÇÖȨµÄµ£±£¡£ÔÚÈκÎÇé¿öÏ£¬pgµç×Ó¹ÙÍø»òÆäÖ±½Ó»ò¼ä½Ó¿ØÖƵÄ×Ó¹«Ë¾£¬»òÆ乩ӦÉÌ£¬¾ù²î³ØÈκÎÒ»·½ÒòÒÀÀµ»òʹÓñ¾ÐÅÏ¢¶øÔâÊܵÄÈκÎËðʧµ£ÂôÁ¦ÈΣ¬°üÀ¨Ö±½Ó£¬¼ä½Ó£¬Å¼È»£¬Ò»¶¨µÄÉÌÒµÀûÈóËðʧ»òÌØÊâËðʧ¡£pgµç×Ó¹ÙÍø±£´æËæʱ¸ü¸Ä»ò¸üдËÎĵµµÄȨÀû¡£