OpenSSL 1.1.1g ืคื•ืจืกื ืขื ืชื™ืงื•ืŸ ืœืคื’ื™ืขื•ืช TLS 1.3

ื–ืžื™ืŸ ืฉื—ืจื•ืจ ืžืชืงืŸ ืฉืœ ืกืคืจื™ื™ืช ื”ื”ืฆืคื ื” OpenSSL 1.1.1g, ืฉื‘ื• ื”ื•ื ื‘ื•ื˜ืœ ืคื’ื™ืขื•ืช (CVE-2020-1967), ืžื” ืฉืžื•ื‘ื™ืœ ืœืžื ื™ืขืช ืฉื™ืจื•ืช ื‘ืขืช ื ื™ืกื™ื•ืŸ ืœื ื”ืœ ืžืฉื ื•ืžืชืŸ ืขืœ ื—ื™ื‘ื•ืจ TLS 1.3 ืขื ืฉืจืช ืื• ืœืงื•ื— ื”ื ืฉืœื˜ ืขืœ ื™ื“ื™ ืชื•ืงืฃ. ื”ืคื’ื™ืขื•ืช ืžื“ื•ืจื’ืช ื›ื—ื•ืžืจื” ื’ื‘ื•ื”ื”.

ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืจืง ื‘ืืคืœื™ืงืฆื™ื•ืช ื”ืžืฉืชืžืฉื•ืช ื‘ืคื•ื ืงืฆื™ื” SSL_check_chain() ื•ื’ื•ืจืžืช ืœืชื”ืœื™ืš ืœืงืจื•ืก ืื ื ืขืฉื” ืฉื™ืžื•ืฉ ืฉื’ื•ื™ ื‘ืชื•ืกืฃ TLS "signature_algorithms_cert". ื‘ืคืจื˜, ืื ืชื”ืœื™ืš ื”ืžืฉื ื•ืžืชืŸ ืขืœ ื”ื—ื™ื‘ื•ืจ ืžืงื‘ืœ ืขืจืš ืœื ื ืชืžืš ืื• ืฉื’ื•ื™ ืขื‘ื•ืจ ืืœื’ื•ืจื™ืชื ืขื™ื‘ื•ื“ ื”ื—ืชื™ืžื•ืช ื”ื“ื™ื’ื™ื˜ืœื™ื•ืช, ืžืชืจื—ืฉืช ื”ืคื ื™ื™ืช ืžืฆื‘ื™ืข NULL ื•ื”ืชื”ืœื™ืš ืงื•ืจืก. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืžืื– ื”ืฉืงืช OpenSSL 1.1.1d.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”