ืคื’ื™ืขื•ืช ืฉืœ ื‘ื™ืฆื•ืข ืงื•ื“ ื‘-Mozilla NSS ื‘ืขืช ืขื™ื‘ื•ื“ ืื™ืฉื•ืจื™ื

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2021-43527) ื‘-NSS (ืฉื™ืจื•ืชื™ ืื‘ื˜ื—ืช ืจืฉืช) ืฉืœ ืกืคืจื™ื•ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ื•ืช ืฉืคื•ืชื—ื• ืขืœ ื™ื“ื™ Mozilla, ืฉื™ื›ื•ืœื” ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“ ืชื•ืงืฃ ื‘ืขืช ืขื™ื‘ื•ื“ ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช DSA ืื• RSA-PSS ืฉืฆื•ื™ื ื• ื‘ืืžืฆืขื•ืช ืฉื™ื˜ืช ืงื™ื“ื•ื“ DER (ื—ื•ืงื™ ืงื™ื“ื•ื“ ืžื•ื‘ื—ื ื™ื). ื”ื‘ืขื™ื”, ื‘ืฉื ื”ืงื•ื“ BigSig, ื ืคืชืจื” ื‘-NSS 3.73 ื•-NSS ESR 3.68.1. ืขื“ื›ื•ื ื™ ื—ื‘ื™ืœื•ืช ื‘ื”ืคืฆื•ืช ื–ืžื™ื ื™ื ืขื‘ื•ืจ Debian, RHEL, Ubuntu, SUSE, Arch Linux, Gentoo, FreeBSD. ืื™ืŸ ืขื“ื›ื•ื ื™ื ื–ืžื™ื ื™ื ืขื‘ื•ืจ ืคื“ื•ืจื” ืขื“ื™ื™ืŸ.

ื”ื‘ืขื™ื” ืžืชืจื—ืฉืช ื‘ื™ื™ืฉื•ืžื™ื ื”ืžืฉืชืžืฉื™ื ื‘-NSS ืœื˜ื™ืคื•ืœ ื‘ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ืฉืœ CMS, S/MIME, PKCS #7 ื•-PKCS #12, ืื• ื‘ืขืช ืื™ืžื•ืช ืื™ืฉื•ืจื™ื ื‘ื™ื™ืฉื•ืžื™ TLS, X.509, OCSP ื•-CRL. ื”ืคื’ื™ืขื•ืช ื™ื›ื•ืœื” ืœื”ื•ืคื™ืข ื‘ื™ื™ืฉื•ืžื™ ืœืงื•ื— ื•ืฉืจืช ืฉื•ื ื™ื ื”ืชื•ืžื›ื™ื ื‘-TLS, DTLS ื•-S/MIME, ืœืงื•ื—ื•ืช ื“ื•ื"ืœ ื•ืžืฆื™ื’ื™ PDF ื”ืžืฉืชืžืฉื™ื ื‘ืงืจื™ืื” NSS CERT_VerifyCertificate() ืœืื™ืžื•ืช ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช.

LibreOffice, Evolution ื•-Evince ืžื•ื–ื›ืจื•ืช ื›ื“ื•ื’ืžืื•ืช ืœื™ื™ืฉื•ืžื™ื ืคื’ื™ืขื™ื. ืคื•ื˜ื ืฆื™ืืœื™ืช, ื”ื‘ืขื™ื” ืขืฉื•ื™ื” ืœื”ืฉืคื™ืข ื’ื ืขืœ ืคืจื•ื™ืงื˜ื™ื ื›ื’ื•ืŸ Pidgin, Apache OpenOffice, Suricata, Curl, Chrony, Red Hat Directory Server, Red Hat Certificate System, mod_nss ืขื‘ื•ืจ ืฉืจืช Apache http, Oracle Communications Messaging Server, Oracle Directory Server Enterprise Edition. ืขื ื–ืืช, ื”ืคื’ื™ืขื•ืช ืื™ื ื” ืžื•ืคื™ืขื” ื‘-Firefox, Thunderbird ื•- Tor Browser, ื”ืžืฉืชืžืฉื™ื ื‘ืกืคืจื™ื™ืช mozilla::pkix ื ืคืจื“ืช, ื”ื›ืœื•ืœื” ื’ื ื”ื™ื ื‘-NSS, ืœืฆื•ืจืš ืื™ืžื•ืช. ื“ืคื“ืคื ื™ื ืžื‘ื•ืกืกื™ ื›ืจื•ื (ืืœื ืื ื›ืŸ ื”ื ื‘ื ื•ื™ื™ื ืกืคืฆื™ืคื™ืช ืขื NSS), ืฉื”ืฉืชืžืฉื• ื‘-NSS ืขื“ 2015, ืื‘ืœ ืื– ืขื‘ืจื• ืœ-BoringSSL, ื’ื ื”ื ืื™ื ื ืžื•ืฉืคืขื™ื ืžื”ื‘ืขื™ื”.

ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืขืœ ื™ื“ื™ ืฉื’ื™ืื” ื‘ืงื•ื“ ื”ืื™ืžื•ืช ืฉืœ ื”ืื™ืฉื•ืจ ื‘ืคื•ื ืงืฆื™ื” vfy_CreateContext ืžื”ืงื•ื‘ืฅ secvfy.c. ื”ืฉื’ื™ืื” ืžืชืจื—ืฉืช ื”ืŸ ื›ืืฉืจ ื”ืœืงื•ื— ืงื•ืจื ืื™ืฉื•ืจ ืžื”ืฉืจืช ื•ื”ืŸ ื›ืืฉืจ ื”ืฉืจืช ืžืขื‘ื“ ืื™ืฉื•ืจื™ ืœืงื•ื—. ื‘ืขืช ืื™ืžื•ืช ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ืžืงื•ื“ื“ืช DER, NSS ืžืคืขื ื— ืืช ื”ื—ืชื™ืžื” ืœืžืื’ืจ ื‘ื’ื•ื“ืœ ืงื‘ื•ืข ื•ืžืขื‘ื™ืจ ืืช ื”ืžืื’ืจ ืœืžื•ื“ื•ืœ PKCS #11. ื‘ืžื”ืœืš ืขื™ื‘ื•ื“ ื ื•ืกืฃ, ื”ื’ื•ื“ืœ ื ื‘ื“ืง ื‘ืฆื•ืจื” ืฉื’ื•ื™ื” ืขื‘ื•ืจ ื—ืชื™ืžื•ืช DSA ื•-RSA-PSS, ืžื” ืฉืžื•ื‘ื™ืœ ืœื’ืœื™ืฉื” ืฉืœ ื”ืžืื’ืจ ื”ืžื•ืงืฆื” ืœืžื‘ื ื” VFYContextStr ืื ื’ื•ื“ืœ ื”ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช ืขื•ืœื” ืขืœ 16384 ืกื™ื‘ื™ื•ืช (2048 ื‘ืชื™ื ืžื•ืงืฆื™ื ืœืžืื’ืจ, ืืš ืœื ืžืกื•ืžืŸ ืฉื”ื—ืชื™ืžื” ื™ื›ื•ืœื” ืœื”ื™ื•ืช ื’ื“ื•ืœื” ื™ื•ืชืจ) ).

ื ื™ืชืŸ ืœืืชืจ ืืช ื”ืงื•ื“ ื”ืžื›ื™ืœ ืืช ื”ืคื’ื™ืขื•ืช ืขื“ ืœืฉื ืช 2003, ืืš ื”ื•ื ืœื ื”ื™ื•ื•ื” ืื™ื•ื ืขื“ ืœืขื™ื‘ื•ื“ ืžื—ื“ืฉ ืฉื‘ื•ืฆืข ื‘-2012. ื‘ืฉื ืช 2017, ืื•ืชื” ื˜ืขื•ืช ื ืคืœื” ื‘ืขืช ื”ื˜ืžืขืช ืชืžื™ื›ืช RSA-PSS. ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื”, ืœื ื ื“ืจืฉ ื™ืฆื™ืจื” ืขืชื™ืจืช ืžืฉืื‘ื™ื ืฉืœ ืžืคืชื—ื•ืช ืžืกื•ื™ืžื™ื ื›ื“ื™ ืœื”ืฉื™ื’ ืืช ื”ื ืชื•ื ื™ื ื”ื“ืจื•ืฉื™ื, ืฉื›ืŸ ื”ื”ืฆืคื” ืžืชืจื—ืฉืช ื‘ืฉืœื‘ ืฉืœืคื ื™ ื‘ื“ื™ืงืช ื ื›ื•ื ื•ืช ื”ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช. ื”ื—ืœืง ืฉืœ ื”ื ืชื•ื ื™ื ืฉื—ื•ืจื’ ืžื”ื’ื‘ื•ืœื•ืช ื ื›ืชื‘ ืœืื–ื•ืจ ื–ื™ื›ืจื•ืŸ ื”ืžื›ื™ืœ ืžืฆื‘ื™ืขื™ื ืœืคื•ื ืงืฆื™ื•ืช, ืžื” ืฉืžืคืฉื˜ ืืช ื”ื™ืฆื™ืจื” ืฉืœ ื ื™ืฆื•ืœ ืขื‘ื•ื“ื”.

ื”ืคื’ื™ืขื•ืช ื”ืชื’ืœืชื” ืขืœ ื™ื“ื™ ื—ื•ืงืจื™ื ืž-Google Project Zero ืชื•ืš ื›ื“ื™ ื ื™ืกื•ื™ ื‘ืฉื™ื˜ื•ืช ื‘ื“ื™ืงื” ืžืขื•ืจืคืœื•ืช ื—ื“ืฉื•ืช ื•ืžื”ื•ื•ื” ื”ื“ื’ืžื” ื˜ื•ื‘ื” ืœืื•ืคืŸ ืฉื‘ื• ืคื’ื™ืขื•ื™ื•ืช ื˜ืจื™ื•ื•ื™ืืœื™ื•ืช ื™ื›ื•ืœื•ืช ืœื”ื™ืฉืืจ ืœืœื ื–ื™ื”ื•ื™ ื‘ืžืฉืš ื–ืžืŸ ืจื‘ ื‘ืคืจื•ื™ืงื˜ ื™ื“ื•ืข ืฉื ื‘ื“ืง ื ืจื—ื‘:

  • ืงื•ื“ ื”-NSS ืžืชื•ื—ื–ืง ืขืœ ื™ื“ื™ ืฆื•ื•ืช ืื‘ื˜ื—ื” ืžื ื•ืกื” ืชื•ืš ืฉื™ืžื•ืฉ ื‘ื˜ื›ื ื™ืงื•ืช ืžืชืงื“ืžื•ืช ืฉืœ ื‘ื“ื™ืงื•ืช ื•ื ื™ืชื•ื— ืฉื’ื™ืื•ืช. ืงื™ื™ืžื•ืช ืžืกืคืจ ืชื•ื›ื ื™ื•ืช ืœืชื’ืžื•ืœ ืžืฉืžืขื•ืชื™ ืขื‘ื•ืจ ื–ื™ื”ื•ื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-NSS.
  • NSS ื”ื™ื” ืื—ื“ ื”ืคืจื•ื™ืงื˜ื™ื ื”ืจืืฉื•ื ื™ื ืฉื”ืฆื˜ืจืคื• ืœื™ื•ื–ืžืช oss-fuzz ืฉืœ ื’ื•ื’ืœ ื•ื’ื ื ื‘ื“ืง ื‘ืžืขืจื›ืช ื‘ื“ื™ืงื•ืช fuzz ื”ืžื‘ื•ืกืกืช ืขืœ libFuzzer ืฉืœ ืžื•ื–ื™ืœื”.
  • ืงื•ื“ ื”ืกืคืจื™ื™ื” ื ื‘ื“ืง ืคืขืžื™ื ืจื‘ื•ืช ื‘ืžื ืชื—ื™ื ืกื˜ื˜ื™ื™ื ืฉื•ื ื™ื, ื›ื•ืœืœ ืžืขืงื‘ ืขืœ ื™ื“ื™ ืฉื™ืจื•ืช Coverity ืžืื– 2008.
  • ืขื“ 2015, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘-NSS ื‘-Google Chrome ื•ื”ื•ื ืื•ืžืช ื‘ืื•ืคืŸ ืขืฆืžืื™ ืขืœ ื™ื“ื™ ืฆื•ื•ืช ื’ื•ื’ืœ ืœืœื ืชืœื•ืช ื‘ืžื•ื–ื™ืœื” (ืžืื– 2015, Chrome ืขื‘ืจ ืœ-BoringSSL, ืืš ื ื•ืชืจื” ืชืžื™ื›ื” ื‘ื™ืฆื™ืื” ืžื‘ื•ืกืกืช NSS).

ื”ื‘ืขื™ื•ืช ื”ืขื™ืงืจื™ื•ืช ืฉื‘ื’ืœืœืŸ ื”ื‘ืขื™ื” ืœื ื–ื•ื”ืชื” ื‘ืžืฉืš ื–ืžืŸ ืจื‘:

  • ื”ืกืคืจื™ื™ื” ื”ืžื•ื“ื•ืœืจื™ืช ืฉืœ NSS ื•ื‘ื“ื™ืงื•ืช ื”-Fzzing ื‘ื•ืฆืขื• ืœื ื›ืžื›ืœื•ืœ, ืืœื ื‘ืจืžื” ืฉืœ ืจื›ื™ื‘ื™ื ื‘ื•ื“ื“ื™ื. ืœืžืฉืœ, ื”ืงื•ื“ ืœืคื™ืขื ื•ื— DER ื•ืขื™ื‘ื•ื“ ืชืขื•ื“ื•ืช ื ื‘ื“ืง ื‘ื ืคืจื“ - ื‘ืžื”ืœืš ื”-fuzzing ื ื™ืชืŸ ื”ื™ื” ืœืงื‘ืœ ืชืขื•ื“ื” ืฉืชื•ื‘ื™ืœ ืœื‘ื™ื˜ื•ื™ ืฉืœ ื”ืคื’ื™ืขื•ืช ื”ืžื“ื•ื‘ืจืช, ืืš ื‘ื“ื™ืงืชื• ืœื ื”ื’ื™ืขื” ืœืงื•ื“ ื”ืื™ืžื•ืช ื•ื”ื‘ืขื™ื” ืœื ื”ื’ื™ืขื”. ืœื—ืฉื•ืฃ ืืช ืขืฆืžื•.
  • ื‘ืžื”ืœืš ื‘ื“ื™ืงื•ืช ืžื˜ื•ืฉื˜ืฉื•ืช, ื”ื•ื’ื“ืจื• ื”ื’ื‘ืœื•ืช ืงืคื“ื ื™ื•ืช ืขืœ ื’ื•ื“ืœ ื”ืคืœื˜ (10000 ื‘ืชื™ื) ื‘ื”ื™ืขื“ืจ ื”ื’ื‘ืœื•ืช ื“ื•ืžื•ืช ื‘-NSS (ืžื‘ื ื™ื ืจื‘ื™ื ื‘ืžืฆื‘ ืจื’ื™ืœ ื™ื›ื•ืœื™ื ืœื”ื™ื•ืช ื‘ื’ื•ื“ืœ ืฉืœ ื™ื•ืชืจ ืž-10000 ื‘ืชื™ื, ื•ืœื›ืŸ ื ื“ืจืฉื• ื™ื•ืชืจ ื ืชื•ื ื™ ืงืœื˜ ื›ื“ื™ ืœื–ื”ื•ืช ื‘ืขื™ื•ืช) . ืœืื™ืžื•ืช ืžืœืื”, ื”ืžื’ื‘ืœื” ื”ื™ื™ืชื” ืฆืจื™ื›ื” ืœื”ื™ื•ืช 224-1 ื‘ืชื™ื (16 ืžื’ื”-ื‘ื™ื™ื˜), ื”ืชื•ืืžืช ืืช ื’ื•ื“ืœ ื”ืื™ืฉื•ืจ ื”ืžืจื‘ื™ ื”ืžื•ืชืจ ื‘-TLS.
  • ืชืคื™ืกื” ืžื•ื˜ืขื™ืช ืœื’ื‘ื™ ื›ื™ืกื•ื™ ืงื•ื“ ื‘ื“ื™ืงื•ืช ืžื˜ื•ืฉื˜ืฉ. ื”ืงื•ื“ ื”ืคื’ื™ืข ื ื‘ื“ืง ื‘ืื•ืคืŸ ืคืขื™ืœ, ืืš ื‘ืืžืฆืขื•ืช fuzzers ืฉืœื ื”ืฆืœื™ื—ื• ืœื™ื™ืฆืจ ืืช ื ืชื•ื ื™ ื”ืงืœื˜ ื”ื“ืจื•ืฉื™ื. ืœื“ื•ื’ืžื”, fuzzer tls_server_target ื”ืฉืชืžืฉ ื‘ืงื‘ื•ืฆื” ืžื•ื’ื“ืจืช ืžืจืืฉ ืฉืœ ืื™ืฉื•ืจื™ื ืžื•ื›ื ื™ื, ืฉื”ื’ื‘ื™ืœื• ืืช ื‘ื“ื™ืงืช ืงื•ื“ ืื™ืžื•ืช ื”ืื™ืฉื•ืจ ืœื”ื•ื“ืขื•ืช TLS ื•ืฉื™ื ื•ื™ื™ ืžืฆื‘ ืคืจื•ื˜ื•ืงื•ืœ ื‘ืœื‘ื“.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”