ืคื’ื™ืขื•ืช ื‘-strongSwan IPsec ื”ืžื•ื‘ื™ืœื” ืœื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง

ืœ-strongSwan, ื—ื‘ื™ืœืช VPN ืžื‘ื•ืกืกืช IPSec ื”ืžืฉืžืฉืช ื‘-Linux, Android, FreeBSD ื•-macOS, ื™ืฉ ืคื’ื™ืขื•ืช (CVE-2023-41913) ืฉื ื™ืชืŸ ืœื ืฆืœ ืœื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง ืขืœ ื™ื“ื™ ืชื•ืงืฃ. ื”ืคื’ื™ืขื•ืช ื ื•ื‘ืขืช ืžื‘ืื’ ื‘ืชื”ืœื™ืš charon-tkm ืขื ื”ื˜ืžืขืช ื”-TKMv2 (ืžื ื”ืœ ืžืคืชื— ืžื”ื™ืžืŸ) ืฉืœื• ื‘ืคืจื•ื˜ื•ืงื•ืœ Key Exchange (IKE), ื•ื›ืชื•ืฆืื” ืžื›ืš ื”ืฆืคืช ืžืื’ืจ ื‘ืขืช ืขื™ื‘ื•ื“ ืขืจื›ื™ ืกื›ื™ืžืช DH (Diffieโ€“Hellman) ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“. ื”ืคื’ื™ืขื•ืช ืžื•ืคื™ืขื” ืจืง ื‘ืžืขืจื›ื•ืช ื”ืžืฉืชืžืฉื•ืช ื‘ืžื”ื“ื•ืจื•ืช charon-tkm ื•-strongSwan ื”ื—ืœ ืž-5.3.0. ื”ื‘ืขื™ื” ืชื•ืงื ื” ื‘ืขื“ื›ื•ืŸ strongSwan 5.9.12. ื›ื“ื™ ืœืชืงืŸ ืืช ื”ืคื’ื™ืขื•ืช ื‘ืกื ื™ืคื™ื ื”ื—ืœ ืž-5.3.x, ื”ื•ื›ื ื• ื’ื ืชื™ืงื•ื ื™ื.

ื”ืฉื’ื™ืื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ืื™ ื‘ื“ื™ืงืช ื”ื’ื•ื“ืœ ืฉืœ ืขืจื›ื™ Diffie-Hellman ื”ืฆื™ื‘ื•ืจื™ื™ื ืœืคื ื™ ื”ืขืชืงืชื ืœืžืื’ืจ ื‘ื’ื•ื“ืœ ืงื‘ื•ืข ื‘ืขืจื™ืžื”. ื ื™ืชืŸ ืœื™ื–ื•ื ื”ืฆืคืช ื™ืชืจ ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื”ื•ื“ืขืช IKE_SA_INIT ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“ ื”ืžืขื•ื‘ื“ ืœืœื ืื™ืžื•ืช. ื‘ื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ ืฉืœ strongSwan, ื‘ื“ื™ืงืช ื”ื’ื•ื“ืœ ื‘ื•ืฆืขื” ื‘-KE (Key Exchange), ืืš ื‘ื’ืจืกื” 5.3.0 ื ื•ืกืคื• ืฉื™ื ื•ื™ื™ื ืฉื”ืขื‘ื™ืจื• ืืช ื‘ื“ื™ืงืช ื”ืขืจื›ื™ื ื”ืฆื™ื‘ื•ืจื™ื™ื ืœืฆื“ ืฉืœ ื”ืžื˜ืคืœ ื‘ืคืจื•ื˜ื•ืงื•ืœ DH ( Diffie-Hellman) ื•ื”ื•ืกื™ืคื• ืคื•ื ืงืฆื™ื•ืช ื’ื ืจื™ื•ืช ื›ื“ื™ ืœืคืฉื˜ ืืช ื‘ื“ื™ืงืช ื ื›ื•ื ื•ืชืŸ ืฉืœ ืงื‘ื•ืฆื•ืช ื™ื“ื•ืขื•ืช D.H. ืขืงื‘ ืคื™ืงื•ื—, ื”ื ืฉื›ื—ื• ืœื”ื•ืกื™ืฃ ืคื•ื ืงืฆื™ื•ืช ื‘ื“ื™ืงื” ื—ื“ืฉื•ืช ืœืชื”ืœื™ืš charon-tkm, ืฉืคื•ืขืœ ื›ืคืจื•ืงืกื™ ื‘ื™ืŸ ืชื”ืœื™ืš IKE ืœ-TKM (ืžื ื”ืœ ืžืคืชื— ืžื”ื™ืžืŸ), ื›ืชื•ืฆืื” ืžื›ืš ื”ืคื•ื ืงืฆื™ื” memcpy() ื”ื›ื™ืœื” ืขืจื›ื™ื ืœื ืžืกื•ืžื ื™ื ืฉืืคืฉืจ ืœื›ืชื•ื‘ ืขื“ 512 ื‘ืชื™ื ืœื ืชื•ื ื™ ื—ื™ืฅ ืฉืœ 10000 ื‘ืชื™ื.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”