ื”ืฆืคืช ืžืื’ืจ ื‘-OpenSSL ืžื ื•ืฆืœืช ื‘ืขืช ืื™ืžื•ืช ืื™ืฉื•ืจื™ X.509

ืคื•ืจืกื ืžื”ื“ื•ืจื” ืžืชืงื ืช ืฉืœ ืกืคืจื™ื™ืช ื”ื”ืฆืคื ื” OpenSSL 3.0.7, ืืฉืจ ืžืชืงืŸ ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื”. ืฉืชื™ ื”ื‘ืขื™ื•ืช ื ื’ืจืžื•ืช ื›ืชื•ืฆืื” ืžื”ืฆืคืช ืžืื’ืจ ื‘ืงื•ื“ ื”ืื™ืžื•ืช ืฉืœ ืฉื“ื” ื”ื“ื•ืืจ ื”ืืœืงื˜ืจื•ื ื™ ื‘ืชืขื•ื“ื•ืช X.509 ื•ืขืœื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืขืช ืขื™ื‘ื•ื“ ืื™ืฉื•ืจ ืžืžื•ืกื’ืจ ื‘ืžื™ื•ื—ื“. ื‘ื–ืžืŸ ืคืจืกื•ื ื”ืชื™ืงื•ืŸ, ืžืคืชื—ื™ OpenSSL ืœื ืจืฉืžื• ืฉื•ื ืขื“ื•ืช ืœื ื•ื›ื—ื•ืช ืฉืœ ื ื™ืฆื•ืœ ืขื•ื‘ื“ ืฉืขืœื•ืœ ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ื”ืงื•ื“ ืฉืœ ื”ืชื•ืงืฃ.

ืœืžืจื•ืช ื”ืขื•ื‘ื“ื” ืฉื”ื”ื•ื“ืขื” ื”ืžื•ืงื“ืžืช ืฉืœ ื”ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื” ื”ื–ื›ื™ืจื” ื ื•ื›ื—ื•ืช ืฉืœ ื‘ืขื™ื” ืงืจื™ื˜ื™ืช, ืœืžืขืฉื”, ื‘ืขื“ื›ื•ืŸ ืฉืฉื•ื—ืจืจ ืžืฆื‘ ื”ื—ื•ืœืฉื” ื”ืฆื˜ืžืฆื ืœืจืžื” ืฉืœ ื ืงื•ื“ืช ืชื•ืจืคื” ืžืกื•ื›ื ืช, ืืš ืœื ืงืจื™ื˜ื™ืช. ื‘ื”ืชืื ืœื›ืœืœื™ื ืฉืื•ืžืฆื• ื‘ืคืจื•ื™ืงื˜, ืจืžืช ื”ืกื›ื ื” ืžืฆื˜ืžืฆืžืช ืื ื”ื‘ืขื™ื” ืžืชื‘ื˜ืืช ื‘ืชืฆื•ืจื•ืช ืœื ื˜ื™ืคื•ืกื™ื•ืช ืื• ืื ื™ืฉื ื” ืกื‘ื™ืจื•ืช ื ืžื•ื›ื” ืœื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช ื‘ืคื•ืขืœ.

ื‘ืžืงืจื” ื–ื”, ืจืžืช ื”ื—ื•ืžืจื” ื”ื•ืคื—ืชื” ืžื›ื™ื•ื•ืŸ ืฉื ื™ืชื•ื— ืžืคื•ืจื˜ ืฉืœ ื”ืคื’ื™ืขื•ืช ืขืœ ื™ื“ื™ ืžืกืคืจ ืืจื’ื•ื ื™ื ื”ื’ื™ืข ืœืžืกืงื ื” ืฉื”ื™ื›ื•ืœืช ืœื”ืคืขื™ืœ ืงื•ื“ ื‘ืžื”ืœืš ื ื™ืฆื•ืœ ื ื—ืกืžื” ืขืœ ื™ื“ื™ ืžื ื’ื ื•ื ื™ ื”ื’ื ื” ืžืคื ื™ ื”ืฆืคืช ืžื—ืกื ื™ืช ื‘ืฉื™ืžื•ืฉ ื‘ืคืœื˜ืคื•ืจืžื•ืช ืจื‘ื•ืช. ื‘ื ื•ืกืฃ, ืคืจื™ืกืช ื”ืจืฉืช ื”ืžืฉืžืฉืช ื‘ื—ืœืง ืžื”ื”ืคืฆื•ืช ืฉืœ ืœื™ื ื•ืงืก ื’ื•ืจืžืช ืœื›ืš ืฉ-4 ื”ื‘ืชื™ื ืฉื™ื•ืฆืื™ื ืžื—ื•ืฅ ืœืชื—ื•ื ืžื•ืฆื‘ื™ื ืขืœ ื”ืžืื’ืจ ื”ื‘ื ื‘ืขืจื™ืžื”, ืฉืขื“ื™ื™ืŸ ืœื ื ืžืฆื ื‘ืฉื™ืžื•ืฉ. ืขื ื–ืืช, ื™ื™ืชื›ืŸ ืฉื™ืฉื ืŸ ืคืœื˜ืคื•ืจืžื•ืช ืฉื ื™ืชืŸ ืœื ืฆืœ ืœื‘ื™ืฆื•ืข ืงื•ื“.

ื‘ืขื™ื•ืช ืฉื–ื•ื”ื•:

  • CVE-2022-3602 - ืคื’ื™ืขื•ืช, ืฉื”ื•ืฆื’ื” ื‘ืชื—ื™ืœื” ื›ืงืจื™ื˜ื™ืช, ืžื•ื‘ื™ืœื” ืœื’ืœื™ืฉื” ืฉืœ ืžืื’ืจ ืฉืœ 4 ื‘ืชื™ื ื‘ืขืช ื‘ื“ื™ืงืช ืฉื“ื” ืขื ื›ืชื•ื‘ืช ื“ื•ืืจ ืืœืงื˜ืจื•ื ื™ ืฉืชื•ื›ื ื ื” ื‘ืžื™ื•ื—ื“ ื‘ืื™ืฉื•ืจ X.509. ื‘ืœืงื•ื— TLS, ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ื‘ืขืช ื”ืชื—ื‘ืจื•ืช ืœืฉืจืช ื”ื ืฉืœื˜ ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ. ื‘ืฉืจืช TLS, ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ืื ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืื™ืžื•ืช ืœืงื•ื— ื‘ืืžืฆืขื•ืช ืื™ืฉื•ืจื™ื. ื‘ืžืงืจื” ื–ื”, ื”ืคื’ื™ืขื•ืช ืžื•ืคื™ืขื” ื‘ืฉืœื‘ ืฉืœืื—ืจ ืื™ืžื•ืช ืฉืจืฉืจืช ื”ืืžื•ืŸ ื”ืงืฉื•ืจื” ืœืชืขื•ื“ื”, ื›ืœื•ืžืจ. ื”ื”ืชืงืคื” ืžื—ื™ื™ื‘ืช ืฉืจืฉื•ืช ื”ืื™ืฉื•ืจื™ื ืชืืžืช ืืช ื”ืื™ืฉื•ืจ ื”ื–ื“ื•ื ื™ ืฉืœ ื”ืชื•ืงืฃ.
  • CVE-2022-3786 ื”ื•ื ื•ืงื˜ื•ืจ ื ื•ืกืฃ ืœื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช ืฉืœ CVE-2022-3602, ืฉื–ื•ื”ืชื” ื‘ืžื”ืœืš ื ื™ืชื•ื— ื”ื‘ืขื™ื”. ื”ื”ื‘ื“ืœื™ื ืžืกืชื›ืžื™ื ื‘ืืคืฉืจื•ืช ืฉืœ ื”ืฆืคืช ืžืื’ืจ ื‘ืขืจื™ืžื” ื‘ืžืกืคืจ ืฉืจื™ืจื•ืชื™ ืฉืœ ื‘ืชื™ื ื”ืžื›ื™ืœื™ื ืืช "." (ื›ืœื•ืžืจ, ื”ืชื•ืงืฃ ืœื ื™ื›ื•ืœ ืœืฉืœื•ื˜ ื‘ืชื•ื›ืŸ ื”ื’ืœื™ืฉื” ื•ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื‘ืขื™ื” ืจืง โ€‹โ€‹ื›ื“ื™ ืœื’ืจื•ื ืœืืคืœื™ืงืฆื™ื” ืœืงืจื•ืก).

ื”ืคื’ื™ืขื•ื™ื•ืช ืžื•ืคื™ืขื•ืช ืจืง ื‘ืขื ืฃ OpenSSL 3.0.x (ื”ื‘ืื’ ื”ื•ืฆื’ ื‘ืงื•ื“ ื”ื”ืžืจื” ืฉืœ Unicode (punycode) ืฉื ื•ืกืฃ ืœืขื ืฃ 3.0.x). ืžื”ื“ื•ืจื•ืช ืฉืœ OpenSSL 1.1.1, ื›ืžื• ื’ื ืกืคืจื™ื•ืช ื”-OpenSSL fork LibreSSL ื•-BoringSSL, ืื™ื ืŸ ืžื•ืฉืคืขื•ืช ืžื”ื‘ืขื™ื”. ื‘ืžืงื‘ื™ืœ, ืฉื•ื—ืจืจ ืขื“ื›ื•ืŸ OpenSSL 1.1.1s, ื”ืžื›ื™ืœ ืจืง ืชื™ืงื•ื ื™ ื‘ืื’ื™ื ืฉืื™ื ื ืื‘ื˜ื—ื”.

ืขื ืฃ OpenSSL 3.0 ืžืฉืžืฉ ื‘ื”ืคืฆื•ืช ื›ื’ื•ืŸ ืื•ื‘ื•ื ื˜ื• 22.04, CentOS Stream 9, RHEL 9, OpenMandriva 4.2, Gentoo, Fedora 36, โ€‹โ€‹Debian Testing/Unstable. ืœืžืฉืชืžืฉื™ื ื‘ืžืขืจื›ื•ืช ืืœื• ืžื•ืžืœืฅ ืœื”ืชืงื™ืŸ ืขื“ื›ื•ื ื™ื ื‘ื”ืงื“ื ื”ืืคืฉืจื™ (Debian, Ubuntu, RHEL, SUSE/openSUSE, Fedora, Arch). ื‘-SUSE Linux Enterprise 15 SP4 ื•ื‘-openSUSE Leap 15.4, ื—ื‘ื™ืœื•ืช ืขื OpenSSL 3.0 ื–ืžื™ื ื•ืช ื‘ืื•ืคืŸ ืื•ืคืฆื™ื•ื ืœื™, ื—ื‘ื™ืœื•ืช ืžืขืจื›ืช ืžืฉืชืžืฉื•ืช ื‘ืขื ืฃ 1.1.1. Debian 1, Arch Linux, Void Linux, Ubuntu 11, Slackware, ALT Linux, RHEL 20.04, OpenWrt, Alpine Linux 8 ื•-FreeBSD ื ืฉืืจื• ื‘ืกื ื™ืคื™ OpenSSL 3.16.x.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”