OpenSSL 3.4.1 Update with Vulnerability Fixes

Corrective releases of the OpenSSL cryptographic library versions 3.0.16, 3.1.8, 3.2.4, 3.3.3, and 3.4.1 are now available. Vulnerability (CVE-2024-12797), categorized as high severity, has been addressed in versions 3.2.4, 3.3.3, and 3.4.1. This vulnerability allows for a MITM attack on TLS and DTLS connections. The issue only affects systems using Raw Public Key (RPK, RFC 7250) for client authentication. By default, RPK support is disabled on the client side and server.

The vulnerability is caused by OpenSSL not returning authentication failure information to the client when establishing a connection using the SSL_VERIFY_PEER verification mode, as the connection negotiation process does not terminate properly. An attacker could execute a MITM attack and redirect traffic to their host instead of the target server, while the client does not receive information that server the connection has not been authenticated. The issue arises starting from the OpenSSL 3.2 branch, where RPK can be used instead of X.509 certificates.

Additionally, OpenSSL updates have fixed vulnerability CVE-2024-13176, which allows an attack through side channels to reconstruct the ECDSA private key via timing analysis during digital signature generation. The essence of the vulnerability is that for certain types of elliptic curves, such as NIST P-521, calculations with zero high bits of the inverted nonce value can be distinguished, with processing times differing by 300 nanoseconds.

In the case of ECDSA, determining even a few bits of information about the nonce is sufficient for an attack to sequentially recover the entire private key. For the attack to be successful, the attacker must have access to the local system where the application generating digital signatures is executed, or high-speed network access to the application with very low latency. The attacker must also be able to analyze the timing of a large number of digital signatures generated over known data with high precision.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster