OpenSSL 1.1.1j, wolfSSL 4.7.0 ืื•ืŸ LibreSSL 3.2.4 ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ

ื ื•ื™ืฉืึทืœื˜ ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ื™ OpenSSL ืงืจื™ืคึผื˜ืึธื’ืจืึทืคื™ืง ื‘ื™ื‘ืœื™ืึธื˜ืขืง 1.1.1j ืื™ื– ื‘ืืจืขื›ื˜ื™ื’ื˜, ื•ื•ืึธืก ืคื™ืงืกื™ื– ืฆื•ื•ื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–:

  • CVE-2021-23841 ืื™ื– ืึท NULL ื˜ื™ื™ึทื˜ืœ ื“ืขืจืคืขืจืึทื ืก ืื™ืŸ ื“ื™ X509_issuer_and_serial_hash () ืคึฟื•ื ืงืฆื™ืข, ื•ื•ืึธืก ืงืขื ืขืŸ ืงืจืึทืš ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื•ื•ืึธืก ืจื•ืคืŸ ื“ืขื ืคึฟื•ื ืงืฆื™ืข ืฆื• ืฉืขืคึผืŸ X509 ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืžื™ื˜ ืึท ืคืึทืœืฉ ื•ื•ืขืจื˜ ืื™ืŸ ื“ื™ ื™ืฉื•ืขืจ ืคืขืœื“.
  • CVE-2021-23840 ืื™ื– ืึทืŸ ื™ื ื˜ืึทื“ื–ืฉืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ืื™ืŸ ื“ื™ EVP_CipherUpdate, EVP_EncryptUpdate ืื•ืŸ EVP_DecryptUpdate ืคืึทื ื’ืงืฉืึทื ื– ื•ื•ืึธืก ืงืขื ืขืŸ ืจืขื–ื•ืœื˜ืึทื˜ ืื™ืŸ ืฆื•ืจื™ืงืงื•ืžืขืŸ ืึท ื•ื•ืขืจื˜ ืคื•ืŸ 1, ื™ื ื“ืึทืงื™ื™ื˜ื™ื ื’ ืึท ื’ืขืจืึธื˜ืŸ ืึธืคึผืขืจืึทืฆื™ืข ืื•ืŸ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ ื’ืจื™ื™ืก ืฆื• ืึท ื ืขื’ืึทื˜ื™ื•ื• ื•ื•ืขืจื˜, ื•ื•ืึธืก ืงืขื ืขืŸ ืึธื ืžืึทื›ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ืฆื• ืงืจืึทืš ืึธื“ืขืจ ืฆืขืฉื˜ืขืจืŸ. ื ืึธืจืžืึทืœ ื ืึทื˜ื•ืจ.
  • CVE-2021-23839 ืื™ื– ืึท ืคืœืึธ ืื™ืŸ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ืจืึธื•ืœื‘ืึทืง ืฉื•ืฅ ืคึฟืึทืจ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ื“ื™ SSLv2 ืคึผืจืึธื˜ืึธืงืึธืœ. ืื ื˜ืคืœืขืงื˜ ื‘ืœื•ื™ื– ืื™ืŸ ื“ื™ ืึทืœื˜ ืฆื•ื•ื™ื™ึทื’ 1.0.2.

ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ื™ LibreSSL 3.2.4 ืคึผืขืงืœ ืื™ื– ืื•ื™ืš ืืจื•ื™ืก, ืื™ืŸ ื•ื•ืึธืก ื“ื™ OpenBSD ืคึผืจื•ื™ืขืงื˜ ืื™ื– ื“ืขื•ื•ืขืœืึธืคึผื™ื ื’ ืึท ื’ืึธืคึผืœ ืคื•ืŸ OpenSSL ืึทื™ืžืขื“ ืฆื• ืฆื•ืฉื˜ืขืœืŸ ืึท ื”ืขื›ืขืจ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื“ืจื’ื”. ื“ื™ ืžืขืœื“ื•ื ื’ ืื™ื– ื ืึธื•ื˜ืึทื‘ืึทืœ ืคึฟืึทืจ ืจื™ื•ื•ืขืจื˜ื™ื ื’ ืฆื• ื“ื™ ืึทืœื˜ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ืงืึธื“ ื’ืขื ื™ืฆื˜ ืื™ืŸ LibreSSL 3.1.x ืจืขื›ื˜ ืฆื• ืึท ื‘ืจืขื›ืŸ ืื™ืŸ ืขื˜ืœืขื›ืข ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ืžื™ื˜ ื‘ื™ื™ื ื“ื™ื ื’ื– ืฆื• ืึทืจื‘ืขื˜ืŸ ืึทืจื•ื ื‘ืึทื’ื– ืื™ืŸ ื“ื™ ืึทืœื˜ ืงืึธื“. ืฆื•ื•ื™ืฉืŸ ื“ื™ ื™ื ืึธื•ื•ื•ื™ื™ืฉืึทื ื–, ื“ื™ ืึทื“ื™ืฉืึทืŸ ืคื•ืŸ ื™ืžืคึผืœืึทืžืึทื ืฅ ืคื•ืŸ ื“ื™ ืขืงืกืคึผืึธืจื˜ืขืจ ืื•ืŸ ืึทื•ื˜ืึธื˜ืฉืึทื™ืŸ ืงืึทืžืคึผืึธื•ื ืึทื ืฅ ืฆื• TLSv1.3 ืฉื˜ื™ื™ื˜ ืื•ื™ืก.

ืื™ืŸ ืึทื“ื™ืฉืึทืŸ, ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ืึท ื ื™ื™ึทืข ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ื™ ืกืึธืœื™ื“ ืงืจื™ืคึผื˜ืึธื’ืจืึทืคื™ืง ื‘ื™ื‘ืœื™ืึธื˜ืขืง wolfSSL 4.7.0, ืึธืคึผื˜ื™ืžื™ื–ืขื“ ืคึฟืึทืจ ื ื•ืฆืŸ ืื•ื™ืฃ ืขืžื‘ืขื“ื™ื“ ื“ืขื•ื•ื™ืกืขืก ืžื™ื˜ ืœื™ืžื™ื˜ืขื“ ืคึผืจืึทืกืขืกืขืจ ืื•ืŸ ื–ื™ืงืึธืจืŸ ืจืขืกื•ืจืกืŸ, ืึทื–ืึท ื•ื•ื™ ืื™ื ื˜ืขืจื ืขื˜ ืคื•ืŸ ื˜ื”ื™ื ื’ืก ื“ืขื•ื•ื™ืกืขืก, ืกืžืึทืจื˜ ื”ื™ื™ื ืกื™ืกื˜ืขืžืขืŸ, ืึธื˜ืึทืžืึธื•ื˜ื™ื•ื• ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืกื™ืกื˜ืขืžืขืŸ, ืจืึธื•ื˜ืขืจืก ืื•ืŸ ืจื™ืจืขื•ื•ื“ื™ืง ืคืึธื ืขืก. . ื“ืขืจ ืงืึธื“ ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ C ืฉืคึผืจืึทืš ืื•ืŸ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืื•ื ื˜ืขืจ ื“ื™ GPLv2 ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ.

ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข ื›ื•ืœืœ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ RFC 5705 (ืงื™ื™ืŸ ืžืึทื˜ืขืจื™ืึทืœ ืขืงืกืคึผืึธืจื˜ืขืจืก ืคึฟืึทืจ TLS) ืื•ืŸ S/MIME (ื–ื™ื›ืขืจ / ืžื•ืœื˜ื™ืคึผื•ืจืคึผืึธืกืข ืื™ื ื˜ืขืจื ืขื˜ ืžืขื™ืœ ื™ืงืกื˜ืขื ืฉืึทื ื–). ืฆื•ื’ืขื’ืขื‘ืŸ "--enable-reproducible-build" ืคืึธืŸ ืฆื• ืขื ืฉื•ืจ ืจืขืคึผืจืึธื“ื•ืกื™ื‘ืœืข ื‘ื•ื™ืขืŸ. ื“ื™ SSL_get_verify_mode API, X509_VERIFY_PARAM API ืื•ืŸ X509_STORE_CTX ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ื“ื™ ืฉื™ื›ื˜ืข ืฆื• ืขื ืฉื•ืจ ืงืึทืžืคึผืึทื˜ืึทื‘ื™ืœืึทื˜ื™ ืžื™ื˜ OpenSSL. ื™ืžืคึผืœืขืžืขื ื˜ืขื“ ืžืึทืงืจืึธื• WOLFSSL_PSK_IDENTITY_ALERT. ืฆื•ื’ืขื’ืขื‘ืŸ ืึท ื ื™ื™ึทืข ืคื•ื ืงืฆื™ืข _CTX_NoTicketTLSv12 ืฆื• ื“ื™ืกื™ื™ื‘ืึทืœ TLS 1.2 ืกืขืกื™ืข ื˜ื™ืงื™ืฅ, ืึธื‘ืขืจ ื•ืคื”ื™ื˜ืŸ ื–ื™ื™ ืคึฟืึทืจ TLS 1.3.

ืžืงื•ืจ: opennet.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster