OpenSSL 1.1.1g i whakaputaina me te whakatika mo te whakaraeraetanga TLS 1.3

Wātea tuku whakatika o te whare pukapuka cryptographic OpenSSL 1.1.1g, ka whakakorehia whakaraeraetanga (CVE-2020-1967), ka arahi ki te whakakore i te ratonga i te wa e ngana ana ki te whiriwhiri i tetahi hononga TLS 1.3 me tetahi tūmau, kiritaki ranei e whakahaerehia ana e te kaiwhaiwhai. Ko te whakaraeraetanga e kiia ana he tino taumaha.

Ka puta noa te raru i roto i nga tono e whakamahi ana i te mahi SSL_check_chain() ka pakaru te tukanga ki te he te whakamahi i te toronga TLS "signature_algorithms_cert". Ina koa, ki te whiwhi te tukanga whiriwhiringa hononga i te uara kore tautoko, he he ranei mo te hainatanga tukatuka algorithm, ka puta he whakakorenga tohu tohu NULL ka taka te tukanga. Ka puta te raruraru mai i te tukunga o OpenSSL 1.1.1d.

Source: opennet.ru

Tāpiri i te kōrero