OpenSSL 1.1.1g e phatlalalitsoe ka tokiso bakeng sa ts'oaetso ea TLS 1.3

Fumaneha tokollo e nepahetseng ea laebrari ea li-cryptographic OpenSSL 1.1.1g, eo ho eona e felisitsoeng bofokodi (CVE-2020-1967), e lebisang ho hanetsoeng ha tšebeletso ha u leka ho buisana ka khokahanyo ea TLS 1.3 le seva se laoloang ke mohlaseli kapa moreki. Bofokoli bo lekantsoe joalo ka bokhopo bo phahameng.

Bothata bo hlaha feela lits'ebetsong tse sebelisang ts'ebetso ea SSL_check_chain () mme e etsa hore ts'ebetso e senyehe haeba katoloso ea TLS "signature_algorithms_cert" e sebelisoa hampe. Haholo-holo, haeba ts'ebetso ea puisano ea khokahanyo e fumana boleng bo sa tšehetsoeng kapa bo fosahetseng bakeng sa algorithm ea ts'ebetso ea signature ea dijithale, NULL pointer dereference e etsahala mme ts'ebetso ea senyeha. Bothata bo hlaha ho tloha ha ho lokolloa OpenSSL 1.1.1d.

Source: opennet.ru

Eketsa ka tlhaloso