ื ื™ื• ื–ื™ื™ึทื˜ ื˜ืฉืึทื ื ืขืœ ืึทื˜ืึทืง ื˜ืขื›ื ื™ืง ืฆื• ืฆื•ืจื™ืงืงืจื™ื’ืŸ ECDSA ืงื™ื–

ืคืึธืจืฉืขืจ ืคื•ืŸ ื“ืขืจ ืื•ื ื™ื•ื•ืขืจืกื™ื˜ืขื˜. ืžืกืจื™ืง ืึทื ื˜ื“ืขืงื˜ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ืคืึทืจืฉื™ื“ืŸ ื™ืžืคึผืœืึทืžืึทื ืฅ ืคื•ืŸ ื“ื™ ECDSA / EdDSA ื“ื™ื’ื™ื˜ืึทืœ ื›ืกื™ืžืข ืฉืึทืคื•ื ื’ ืึทืœื’ืขืจื™ื“ืึทื, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื•ืžืงืขืจืŸ ื“ื™ ื•ื•ืขืจื˜ ืคื•ืŸ ืึท ืคึผืจื™ื•ื•ืึทื˜ ืฉืœื™ืกืœ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ืึทืŸ ืึทื ืึทืœื™ืกื™ืก ืคื•ืŸ ืœื™ืงืก ืคื•ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื™ื—ื™ื“ ื‘ื™ื˜ืŸ ื•ื•ืึธืก ื™ืžืขืจื“ื–ืฉื“ ื•ื•ืขืŸ ื ื™ืฆืŸ ื“ืจื™ื˜-ืคึผืึทืจื˜ื™ื™ ืึทื ืึทืœื™ืกื™ืก ืžืขื˜ื”ืึธื“ืก. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ืงืึธื“ืขื ืึทืžืขื“ ืžื™ื ืขืจื•ื•ืึท.

ื“ื™ ืžืขืจืกื˜ ื‘ืึทื•ื•ื•ืกื˜ ืคึผืจืึทื“ื–ืฉืขืงืก ื•ื•ืึธืก ื–ืขื ืขืŸ ืึทืคืขืงื˜ืึทื“ ื“ื•ืจืš ื“ื™ ืคืืจื’ืขืœื™ื™ื’ื˜ ื‘ืึทืคืึทืœืŸ ืื•ืคึฟืŸ ื–ืขื ืขืŸ OpenJDK / OracleJDK (CVE-2019-2894) ืื•ืŸ ื“ื™ ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืœื™ื‘ื’ืงืจื™ืคึผื˜ (CVE-2019-13627) ื’ืขื ื™ืฆื˜ ืื™ืŸ GnuPG. ืื•ื™ืš ืกืึทืกืขืคึผื˜ืึทื‘ืึทืœ ืฆื• ื“ืขื ืคึผืจืึธื‘ืœืขื ืžืึทื˜ืจื™ืงืกืกืœ, ืงืจื™ืคึผื˜ืึธ ++, wolfCrypt, ื™ืœื™ืคึผื˜ื™ืฉ, jsrsasign, ืคึผื™ื˜ื”ืึธืŸ-ืขืงื“ืกืึท, ruby_ecdsa, fastecdsa, ื’ืจื™ื ื’-ืขืงืง ืื•ืŸ Athena IDProtect ืงืœื•ื’ ืงืึทืจื“ืก. ื ื™ื˜ ื˜ืขืกื˜ืขื“, ืึธื‘ืขืจ ื’ื™ืœื˜ื™ืง S/A IDflex V, SafeNet eToken 4300 ืื•ืŸ TecSec ืึทืจืžืขืจื“ ืงืึทืจื“ ืงืึทืจื“ืก, ื•ื•ืึธืก ื ื•ืฆืŸ ืึท ื ืึธืจืžืึทืœ ECDSA ืžืึธื“ื•ืœืข, ื–ืขื ืขืŸ ืื•ื™ืš ื“ืขืจืงืœืขืจื˜ ื•ื•ื™ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง.

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ืฉื•ื™ืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื“ื™ ืจื™ืœื™ืกื™ื– ืคื•ืŸ libgcrypt 1.8.5 ืื•ืŸ wolfCrypt 4.1.0, ื“ื™ ืจื•ืขืŸ ืคึผืจืึทื“ื–ืฉืขืงืก ื”ืึธื‘ืŸ ื ื™ืฉื˜ ื ืึธืš ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ. ืื™ืจ ืงืขื ืขืŸ ืฉืคึผื•ืจ ื“ื™ ืคืึทืจืจื™ื›ื˜ืŸ ืคึฟืึทืจ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ libgcrypt ืคึผืขืงืœ ืื™ืŸ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ืื•ื™ืฃ ื“ื™ ื‘ืœืขื˜ืขืจ: ื“ืขื‘ื™ืึทืŸ, ื•ื‘ื•ื ื˜ื•, rhel, ืคืขื“ืึธืจืึท, openSUSE / SUSE, FreeBSD, ืึทืจื˜ืฉ.

ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื ื™ื˜ ืกืึทืกืขืคึผื˜ืึทื‘ืึทืœ OpenSSL, Botan, mbedTLS ืื•ืŸ BoringSSL. ื ื™ื˜ ื ืึธืš ื˜ืขืกื˜ืขื“ ืžืึธื–ื™ืœืœืึท NSS, LibreSSL, Nettle, BearSSL, cryptlib, OpenSSL ืื™ืŸ FIPS ืžืึธื“ืข, Microsoft .NET ืงืจื™ืคึผื˜ืึธ,
libkcapi ืคึฟื•ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ, ืกืึธื“ื™ื•ื ืื•ืŸ GnuTLS.

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื‘ืึทืฉื˜ื™ืžืขืŸ ื“ื™ ื•ื•ืึทืœื•ืขืก ืคื•ืŸ ื™ื—ื™ื“ ื‘ื™ื˜ืŸ ื‘ืขืฉืึทืก ืกืงืึทืœืึทืจ ืงื™ื™ืคืœ ืื™ืŸ ื™ืœื™ืคึผื˜ื™ืงืึทืœ ื•ื™ืกื‘ื™ื™ื’ ืึทืคึผืขืจื™ื™ืฉืึทื ื–. ื•ืžื“ื™ืจืขืงื˜ ืžืขื˜ื”ืึธื“ืก, ืึทื–ืึท ื•ื•ื™ ืขืกื˜ื™ืžืึทื˜ื™ื ื’ ืงืึทืžืคึผื™ื•ื˜ื™ื™ืฉืึทื ืึทืœ ืคืึทืจื”ืึทืœื˜ืŸ, ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜ ืฆื• ืขืงืกื˜ืจืึทืงื˜ ื‘ื™ืกืœ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข. ืึท ื‘ืึทืคืึทืœืŸ ืจื™ืงื•ื•ื™ื™ืขืจื– ืึทื ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื“ ืึทืงืกืขืก ืฆื• ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืื•ื™ืฃ ื•ื•ืึธืก ื“ื™ ื“ื™ื’ื™ื˜ืึทืœ ื›ืกื™ืžืข ืื™ื– ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ (ื ื™ื˜ ื•ื™ืกืฉืœื™ืกืŸ ืื•ืŸ ืึท ื•ื•ื™ื™ึทื˜ ื‘ืึทืคืึทืœืŸ, ืึธื‘ืขืจ ืขืก ืื™ื– ื–ื™ื™ืขืจ ืงืึธืžืคึผืœื™ืฆื™ืจื˜ ืื•ืŸ ืจื™ืงื•ื•ื™ื™ืขืจื– ืึท ื’ืจื•ื™ืก ืกื•ืžืข ืคื•ืŸ โ€‹โ€‹ื“ืึทื˜ืŸ ืคึฟืึทืจ ืึทื ืึทืœื™ืกื™ืก, ืึทื–ื•ื™ ืขืก ืื™ื– ืึทื ืœื™ื™ืงืœื™. ืคึฟืึทืจ ืœืึธื•ื“ื™ื ื’ ื‘ื ื™ืžืฆื ืžื›ืฉื™ืจื™ื ื’ืขื ื™ืฆื˜ ืคึฟืึทืจ ื‘ืึทืคืึทืœืŸ.

ื˜ืจืึธืฅ ื“ื™ ื ื™ืฉื˜ื™ืง ื’ืจื™ื™ืก ืคื•ืŸ ื“ื™ ืจื™ื ืขืŸ, ืคึฟืึทืจ ECDSA ื“ื™ ื“ื™ื˜ืขืงืฉืึทืŸ ืคื•ืŸ ืืคื™ืœื• ืึท ื‘ื™ืกืœ ื‘ื™ื˜ืŸ ืžื™ื˜ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ื™ื ื™ื˜ื™ืึทืœื™ื–ืึทื˜ื™ืึธืŸ ื•ื•ืขืงื˜ืึธืจ (ื ืึธื ืก) ืื™ื– ื’ืขื ื•ื’ ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืึท ื‘ืึทืคืึทืœืŸ ืฆื• ืกืึทืงื•ื•ืขื ื˜ืฉืึทืœื™ ืฆื•ืจื™ืงืงืจื™ื’ืŸ ื“ื™ ื’ืื ืฆืข ืคึผืจื™ื•ื•ืึทื˜ ืฉืœื™ืกืœ. ืœื•ื™ื˜ ื“ื™ ืžื—ื‘ืจื™ื ืคื•ืŸ ื“ืขื ืื•ืคึฟืŸ, ืฆื• ื”ืฆืœื—ื” ืฆื•ืจื™ืงืงืจื™ื’ืŸ ืึท ืฉืœื™ืกืœ, ืึทืŸ ืึทื ืึทืœื™ืกื™ืก ืคื•ืŸ ืขื˜ืœืขื›ืข ื”ื•ื ื“ืขืจื˜ ืฆื• ืขื˜ืœืขื›ืข ื˜ื•ื™ื–ื ื˜ ื“ื™ื’ื™ื˜ืึทืœ ืกื™ื’ื ืึทื˜ืฉืขืจื– ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ืคึฟืึทืจ ืึทืจื˜ื™ืงืœืขืŸ ื‘ืืงืื ื˜ ืฆื• ื“ื™ ืึทื˜ืึทืงืขืจ ืื™ื– ื’ืขื ื•ื’. ืœืžืฉืœ, 90 ื˜ื•ื™ื–ื ื˜ ื“ื™ื’ื™ื˜ืึทืœ ืกื™ื’ื ืึทื˜ืฉืขืจื– ื–ืขื ืขืŸ ืึทื ืึทืœื™ื™ื–ื“ ืžื™ื˜ ื“ื™ secp256r1 ื™ืœื™ืคึผื˜ื™ืง ื•ื™ืกื‘ื™ื™ื’ ืฆื• ื‘ืึทืฉืœื™ืกืŸ ื“ื™ ืคึผืจื™ื•ื•ืึทื˜ ืฉืœื™ืกืœ ื’ืขื ื™ืฆื˜ ืื•ื™ืฃ ื“ื™ Athena IDProtect ืกืžืึทืจื˜ ืงืึทืจื˜ืœ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ Inside Secure AT11SC ืฉืคึผืึธืŸ. ื“ื™ ื’ืึทื ืฅ ืึทื˜ืึทืง ืฆื™ื™ื˜ ืื™ื– ื’ืขื•ื•ืขืŸ 30 ืžื™ื ื•ื˜.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’