Mwepụta nke sava Dropbear SSH 2020.79

Ewebata ọhụrụ ntọhapụ Ọnụ ego nke 2020.79, Kọmpat MIT-ikike SSH nkesa na onye ahịa na-eji nke ọma na sistemụ agbakwunyere dị ka ndị na-anya ikuku ikuku. A na-eji Dropbear site na oriri ebe nchekwa dị ala (mgbe ejikọtara ya na uClibc ọ na-ewe naanị 110kB), ikike iji gbanyụọ ọrụ na-adịghị mkpa n'oge a na-ewu ụlọ, yana nkwado maka iwulite onye ahịa na ihe nkesa n'otu faịlụ nwere ike ime, dị ka igbe ọrụ. Dropbear na-akwado mbugharị X11, dakọtara na faịlụ igodo OpenSSH (~/.ssh/authorized_keys) ma nwee ike ịmepụta ọtụtụ njikọ na mbugharị site na onye na-ebugharị njem.

В ọhụrụ ntọhapụ:

  • Nkwado agbakwunyere maka Ed25519 dijitalụ mbinye aka algọridim na igodo nnabata na igodo ikike.
  • Nkwado agbakwunyere maka protocol nyocha dabere na ChaCha20 iyi cipher na Poly1305 algọridim nyocha ozi nke Daniel Bernstein mepụtara.
  • Nkwado agbakwunyere maka usoro mbinye aka dijitalụ rsa-sha2, nke, n'ihi njedebe nke nkwado sha-1, ga-adị mkpa n'oge na-adịghị anya maka OpenSSH (igodo RSA dị ugbu a ga-enwe ike ịrụ ọrụ na usoro ọhụrụ na-enweghị ịgbanwe igodo ọbịa / ikike_keys).
  • Ejiri ụdị kọmpat karịa site na ọrụ TweetNaCl dochie mmejuputa nke curve25519.
  • Nkwado agbakwunyere maka AES GCM (nwere nkwarụ na ndabara).
  • Nkwarụ na ndabara bụ CBC ciphers, 3DES, hmac-sha1-96, na x11 ebugharị.
  • Ekpebiri nsogbu ndakọrịta na IRIX OS.
  • Agbakwunyere API iji kọwapụta igodo ọha ozugbo kama iji igodo nwere ikike.
  • Edobere adịghị ike na SCP CVE-2018-20685, nke na-enye ohere ịgbanwe ikike ịnweta na ndekọ ndekọ aha mgbe ihe nkesa na-eweghachite ndekọ na aha efu ma ọ bụ oge efu. Mgbe ị na-enweta iwu "D0777 0 \n" ma ọ bụ "D0777 0 .\n" site na sava ahụ, onye ahịa ahụ tinyere mgbanwe na ikike ịnweta na ndekọ aha ugbu a.

isi: opennet.ru

Tinye a comment