[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"solution-scenes-menu":3,"tech-detail-2363":4},true,{"id":5,"title":6,"content":7,"picUrl":8,"tagIds":9,"keyWords":10,"htmlDescribe":11,"htmlUrl":12,"gmtCreate":13,"gmtModified":13,"articleInfoId":14},"2363","美畅物联丨OpenSSH安全漏洞及Nginx缓冲区错误漏洞的修复","\u003Ch1 style=\"text-align:justify\">\u003Cstrong>概述\u003C\u002Fstrong>\u003C\u002Fh1>\u003Cp style=\"text-align:center\">\u003Cimg src=\"https:\u002F\u002Fqu-link.oss-cn-hangzhou.aliyuncs.com\u002F2024\u002F11\u002F26\u002F5eca13aa-a922-4fc8-b5df-b91853977a64.png\" alt=\"\" loading=\"lazy\" \u002F>\u003C\u002Fp>\u003Cp style=\"text-indent:2em;text-align:justify\">系统安全扫描时，发现了以下漏洞:\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>1、Nginx 缓冲区错误漏洞；\u003C\u002Fstrong>\u003C\u002Fspan>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>2、OpenSSH 安全漏洞\u003C\u002Fstrong>\u003C\u002Fspan>\u003C\u002Fp>\u003Cp style=\"text-indent:2em;text-align:justify\">并给出了修复建议:\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>1、升级Nginx至1.26.0以后版本；\u003C\u002Fstrong>\u003C\u002Fspan>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>2、升级openSSH至9.8及以后版本。\u003C\u002Fstrong>\u003C\u002Fspan>\u003C\u002Fp>\u003Cp style=\"text-indent:2em;text-align:justify\">以下记录了 Nginx 升级至 1.26.2 和 OpenSSH 升级至 9.8p1的过程，操作系统为：centOS 7。\u003C\u002Fp>\u003Ch1 style=\"text-align:justify\">\u003Cstrong>一、升级 Nginx 到 1.26.2\u003C\u002Fstrong>\u003C\u002Fh1>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>步骤 1：\u003C\u002Fstrong>\u003C\u002Fspan>检查当前 Nginx 版本\u003C\u002Fp>\u003Cpre style=\"text-align:justify\">\u003Ccode style=\"text-align:left\">nginx -v\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>步骤 2：\u003C\u002Fstrong>\u003C\u002Fspan>备份现有配置文件\u003C\u002Fp>\u003Cp style=\"text-indent:2em;text-align:justify\">在升级前，备份现有 Nginx 配置文件：\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cpre>\u003Ccode>cp \u002Fetc\u002Fnginx\u002Fnginx.conf \u002Fetc\u002Fnginx\u002Fnginx.conf.bak\ncp -r \u002Fetc\u002Fnginx\u002Fconf.d \u002Fetc\u002Fnginx\u002Fconf.d.bak\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>步骤 3：\u003C\u002Fstrong>\u003C\u002Fspan>下载 Nginx 1.26.2\u003C\u002Fp>\u003Cpre style=\"text-align:justify\">\u003Ccode style=\"text-align:left\">wget http:\u002F\u002Fnginx.org\u002Fdownload\u002Fnginx-1.26.2.tar.gz\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>步骤 4：\u003C\u002Fstrong>\u003C\u002Fspan>解压源码包：\u003C\u002Fp>\u003Cpre>\u003Ccode>tar -zxvf nginx-1.26.2.tar.gz\ncd nginx-1.26.2\n.\u002Fconfigure \\\n&gt; --prefix=\u002Fusr\u002Flocal\u002Fnginx \\\n&gt; --with-http_ssl_module \\\n&gt; --with-http_v2_module \\\n&gt; --with-http_gzip_static_module \\\n&gt; --with-pcre \\\n&gt; --with-zlib \\\n&gt; --with-openssl\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>执行提示：\u003C\u002Fstrong>\u003C\u002Fspan>\u003Cspan style=\"font-size:19px\"> \u003C\u002Fspan>.\u002Fconfigure: error: invalid option “–with-zlib”。\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>下载：\u003C\u002Fstrong>\u003C\u002Fspan>zlib\u003C\u002Fp>\u003Cpre style=\"text-align:justify\">\u003Ccode style=\"text-align:left\">wget https:\u002F\u002Fzlib.net\u002Ffossils\u002Fzlib-1.2.13.tar.gz\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>解压：\u003C\u002Fstrong>\u003C\u002Fspan>\u003C\u002Fp>\u003Cpre style=\"text-align:justify\">\u003Ccode style=\"text-align:left\">tar -zxvf zlib-1.3.tar.gz\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>再次执行：\u003C\u002Fstrong>\u003C\u002Fspan>\u003C\u002Fp>\u003Cpre>\u003Ccode>.\u002Fconfigure --prefix=\u002Fusr\u002Flocal\u002Fnginx --with-http_ssl_module --with-http_v2_module --with-http_gzip_static_module --with-pcre --with-zlib=.\u002Fzlib-1.2.13  --with-openssl\n.\u002Fconfigure: error: invalid option “–with-openssl”\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>说明:\u003C\u002Fstrong>\u003C\u002Fspan>\u003C\u002Fp>\u003Cp style=\"text-indent:2em;text-align:justify\">Nginx 1.26.2 官方支持 OpenSSL 1.1.1 系列和 3.x 系列。\u003C\u002Fp>\u003Cp style=\"text-align:justify\">• 如果你的系统依赖的是 OpenSSL 1.1.1 系列，建议使用最新的 1.1.1v。\u003C\u002Fp>\u003Cp style=\"text-align:justify\">• 如果你希望采用 OpenSSL 最新特性，选择 OpenSSL 3.1.x（最新为 3.1.3，同时需要确保系统和依赖支持）。\u003C\u002Fp>\u003Cp style=\"text-indent:2em;text-align:justify\">OpenSSL 3.x 系列改动较大，仅适用于对兼容性有较高要求或希望使用最新特性的情况。只为解决Nginx缓冲区错误漏洞；所以我选择OpenSSL 1.1.1\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>解压 并再次执行：\u003C\u002Fstrong>\u003C\u002Fspan>\u003C\u002Fp>\u003Cpre>\u003Ccode>tar -zxvf openssl-1.1.1v.tar.gz \n.\u002Fconfigure --prefix=\u002Fusr\u002Flocal\u002Fnginx --with-http_ssl_module --with-http_v2_module --with-http_gzip_static_module --with-pcre --with-zlib=.\u002Fzlib-1.2.13  --with-openssl=.\u002Fopenssl-1.1.1v\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>说明：\u003C\u002Fstrong>\u003C\u002Fspan>由于指定了zlib和openssl的位置，这里不需要到相关的目录编译和安装zlib和openssl\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>步骤 5：\u003C\u002Fstrong>\u003C\u002Fspan>编译并安装 Nginx：\u003C\u002Fp>\u003Cp style=\"text-align:justify\">完成配置后，继续执行以下命令完成编译和安装：\u003C\u002Fp>\u003Cpre>\u003Ccode>make \nmake install\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>步骤 6：\u003C\u002Fstrong>\u003C\u002Fspan> 配置并启动新版本：\u003C\u002Fp>\u003Cpre style=\"text-align:justify\">\u003Ccode style=\"text-align:left\">\u002Fusr\u002Flocal\u002Fnginx\u002Fsbin\u002Fnginx -v\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>示例输出：\u003C\u002Fstrong>\u003C\u002Fspan>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">nginx version: nginx\u002F1.26.2\u003C\u002Fp>\u003Cp style=\"text-align:justify\">。替换备份的配置文件到新路径：\u003C\u002Fp>\u003Cpre>\u003Ccode>cp \u002Fetc\u002Fnginx\u002Fnginx.conf.bak \u002Fusr\u002Flocal\u002Fnginx\u002Fconf\u002Fnginx.conf\ncp -r \u002Fetc\u002Fnginx\u002Fconf.d.bak \u002Fusr\u002Flocal\u002Fnginx\u002Fconf\u002Fconf.d\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">启动 Nginx：\u003C\u002Fp>\u003Cpre style=\"text-align:justify\">\u003Ccode style=\"text-align:left\">\u002Fusr\u002Flocal\u002Fnginx\u002Fsbin\u002Fnginx\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">检查 Nginx 是否启动成功：\u003C\u002Fp>\u003Cpre style=\"text-align:justify\">\u003Ccode style=\"text-align:left\">ps aux | grep nginx\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Ch1 style=\"text-align:justify\">\u003Cstrong>二、升级 OpenSSH 到 9.8p1\u003C\u002Fstrong>\u003C\u002Fh1>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>步骤 1：\u003C\u002Fstrong>\u003C\u002Fspan>检查OpenSSH版本并下载指定版本\u003C\u002Fp>\u003Cpre style=\"text-align:justify\">\u003Ccode style=\"text-align:left\">ssh -V\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-indent:2em;text-align:justify\">从 OpenSSH 官方网站 下载源码：\u003C\u002Fp>\u003Cpre style=\"text-align:justify\">\u003Ccode style=\"text-align:left\">wget https:\u002F\u002Fcdn.openbsd.org\u002Fpub\u002FOpenBSD\u002FOpenSSH\u002Fportable\u002Fopenssh-9.8p1.tar.gz\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>步骤 2：\u003C\u002Fstrong>\u003C\u002Fspan>\u003Cspan style=\"font-size:19px\"> \u003C\u002Fspan>解压源码包：\u003C\u002Fp>\u003Cpre>\u003Ccode>tar -zxvf openssh-9.8p1.tar.gz\ncd openssh-9.8p1\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>步骤 3：\u003C\u002Fstrong>\u003C\u002Fspan> 编译并安装 OpenSSH：\u003C\u002Fp>\u003Cpre>\u003Ccode>.\u002Fconfigure\nmake\nmake install\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cspan style=\"font-size:19px\">\u003Cstrong>步骤 4：\u003C\u002Fstrong>\u003C\u002Fspan>配置环境变量：\u003C\u002Fp>\u003Cp style=\"text-align:justify\">编辑文件\u003C\u002Fp>\u003Cpre style=\"text-align:justify\">\u003Ccode style=\"text-align:left\">vi ~\u002F.bashrc\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">输入：\u003C\u002Fp>\u003Cpre>\u003Ccode>export PATH=\u002Fusr\u002Flocal\u002Fopenssl\u002Fbin:$PATH\nexport LD_LIBRARY_PATH=\u002Fusr\u002Flocal\u002Fopenssl\u002Flib:$LD_LIBRARY_PATH\nexport CFLAGS=\"-I\u002Fusr\u002Flocal\u002Fopenssl\u002Finclude\"\nexport LDFLAGS=\"-L\u002Fusr\u002Flocal\u002Fopenssl\u002Flib\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">修改生效：\u003C\u002Fp>\u003Cpre style=\"text-align:justify\">\u003Ccode style=\"text-align:left\">source ~\u002F.bashrc\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:justify\">\u003Cstrong>步骤 5：\u003C\u002Fstrong>验证版本：\u003C\u002Fp>\u003Cpre style=\"text-align:justify\">\u003Ccode style=\"text-align:left\">ssh -V\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp style=\"text-align:justify\">\u003Cbr \u002F>\u003C\u002Fp>\u003Cp style=\"text-align:center\">\u003Cimg src=\"https:\u002F\u002Fqu-link.oss-cn-hangzhou.aliyuncs.com\u002F2024\u002F11\u002F26\u002F4ab99008-971a-4c66-b0eb-e475f813ef23.png\" alt=\"\" loading=\"lazy\" \u002F>\u003C\u002Fp>\u003Cp style=\"text-indent:2em;text-align:left\">通过以上步骤完成升级后，您的系统将更安全，已知漏洞将被修复。\u003C\u002Fp>\u003Cp style=\"text-align:left;line-height:2\">————————————————\u003C\u002Fp>\u003Cp style=\"text-align:left;line-height:2\">\u003Cspan style=\"color:rgb(0, 0, 0);background-color:rgb(255, 255, 255);font-size:16px\">关注\u003C\u002Fspan>\u003Cspan style=\"color:rgb(66, 144, 247);background-color:rgb(255, 255, 255);font-size:16px\">\u003Cstrong>“美畅物联”\u003C\u002Fstrong>\u003C\u002Fspan>\u003Cspan style=\"color:rgb(0, 0, 0);background-color:rgb(255, 255, 255);font-size:16px\">，了解更多视频汇聚及AIoT底座解决方案。\u003C\u002Fspan>\u003C\u002Fp>","https:\u002F\u002Fqu-link.oss-cn-hangzhou.aliyuncs.com\u002F2024\u002F11\u002F26\u002F22248453-bcec-4bf2-a786-586585eb1b9d.jpg","9","美畅，美畅物联，畅联，畅联云平台，视频监控云平台，云视频监控，视频云平台，视频开放平台，视频感知云，视频接入网关，AIoT综合接入网关，视频中台，物联网中台，无插件播放，H265播放，Ehome，ISUP， GB28181，GB35114，gat1400，JT808，JT1078","原创技术分享丨美畅物联周工","http:\u002F\u002Fwww.24hlink.cn\u002Fweb-index\u002F4DQWNP0.html","2024-11-26 15:16:39","793"]