ืขื“ื›ื•ืŸ OpenSSL 1.1.1l ืขื ืชื™ืงื•ื ื™ื ืœืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื”

ืžื”ื“ื•ืจื” ืžืชืงื ืช ืฉืœ ืกืคืจื™ื™ืช ื”ื”ืฆืคื ื” OpenSSL 1.1.1l ื–ืžื™ื ื” ืขื ื‘ื™ื˜ื•ืœ ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื”:

  • CVE-2021-3711 ื”ื•ื ื’ืœื™ืฉืช ืžืื’ืจ ื‘ืงื•ื“ ื”ืžื™ื™ืฉืžืช ืืช ื”ืืœื’ื•ืจื™ืชื ื”ื”ืฆืคื ื” SM2 (ื ืคื•ืฅ ื‘ืกื™ืŸ), ื”ืžืืคืฉืจ ืœื“ืจื•ืก ืขื“ 62 ื‘ืชื™ื ื‘ืื–ื•ืจ ืžืขื‘ืจ ืœื’ื‘ื•ืœ ื”ืžืื’ืจ ืขืงื‘ ืฉื’ื™ืื” ื‘ื—ื™ืฉื•ื‘ ื’ื•ื“ืœ ื”ืžืื’ืจ. ืชื•ืงืฃ ืขืœื•ืœ ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืงื•ื“ ืื• ืงืจื™ืกืช ื™ื™ืฉื•ื ืขืœ ื™ื“ื™ ื”ืขื‘ืจืช ื ืชื•ื ื™ ืคืขื ื•ื— ื‘ืขืœื™ ืžื‘ื ื” ืžื™ื•ื—ื“ ืœื™ื™ืฉื•ืžื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืคื•ื ืงืฆื™ื” EVP_PKEY_decrypt() ื›ื“ื™ ืœืคืขื ื— ื ืชื•ื ื™ SM2.
  • CVE-2021-3712 ื”ื•ื ื’ืœื™ืฉืช ืžืื’ืจ ื‘ืงื•ื“ ืขื™ื‘ื•ื“ ืžื—ืจื•ื–ืช ASN.1, ืฉืขืœื•ืœื” ืœื’ืจื•ื ืœืงืจื™ืกื” ืฉืœ ื™ื™ืฉื•ื ืื• ืœื—ืฉื•ืฃ ืืช ื”ืชื•ื›ืŸ ืฉืœ ื–ื™ื›ืจื•ืŸ ื”ืชื”ืœื™ืš (ืœื“ื•ื’ืžื”, ื›ื“ื™ ืœื–ื”ื•ืช ืžืคืชื—ื•ืช ื”ืžืื•ื—ืกื ื™ื ื‘ื–ื™ื›ืจื•ืŸ) ืื ื”ืชื•ืงืฃ ืžืกื•ื’ืœ ืื™ื›ืฉื”ื• ืœื™ืฆื•ืจ ืžื—ืจื•ื–ืช ื‘ืžื‘ื ื” ื”ืคื ื™ืžื™ ืฉืœ ASN1_STRING. ืœื ืžืกืชื™ื™ืžืช ืขืœ ื™ื“ื™ ืชื• null, ื•ืžืขื‘ื“ื™ื ืื•ืชื” ื‘ืคื•ื ืงืฆื™ื•ืช OpenSSL ืฉืžื“ืคื™ืกื•ืช ืื™ืฉื•ืจื™ื, ื›ื’ื•ืŸ X509_aux_print(), X509_get1_email(), X509_REQ_get1_email() ื•-X509_get1_ocsp().

ื‘ืžืงื‘ื™ืœ, ืคื•ืจืกืžื• ื’ืจืกืื•ืช ื—ื“ืฉื•ืช ืฉืœ ืกืคืจื™ื™ืช LibreSSL 3.3.4 ื•-3.2.6, ืฉืื™ื ืŸ ืžื–ื›ื™ืจื•ืช ื‘ืžืคื•ืจืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื”, ืืš ืื ืœืฉืคื•ื˜ ืœืคื™ ืจืฉื™ืžืช ื”ืฉื™ื ื•ื™ื™ื, ื”ืคื’ื™ืขื•ืช CVE-2021-3712 ื‘ื•ื˜ืœื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”