OpenSSL 1.1.1g yakaburitswa negadziriso yeTLS 1.3 panjodzi

Inowanikwa kugadzirisa kuburitswa kwekriptographic library OpenSSL 1.1.1g, umo inobviswa vulnerability (CVE-2020-1967), zvichitungamira mukuramba sevhisi paunenge uchiedza kutaurirana neTLS 1.3 yekubatanidza neanorwisa-anodzorwa sevha kana mutengi. Kusagadzikana kwacho kunonzi kuomarara kwepamusoro.

Dambudziko rinongowanikwa mumashandisirwo anoshandisa SSL_check_chain () basa uye rinokonzera kuti maitiro acho aparadze kana iyo TLS yekuwedzera "signature_algorithms_cert" ikashandiswa zvisirizvo. Kunyanya, kana iyo yekubatanidza nzira yekutaurirana inogamuchira isingatsigirwe kana isiriyo kukosha kwedhijitari siginecha yekugadzirisa algorithm, NULL pointer dereference inoitika uye maitiro anoputsika. Dambudziko rinoonekwa kubva pakaburitswa OpenSSL 1.1.1d.

Source: opennet.ru

Voeg