OpenSSL 1.1.1l ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืžื™ื˜ ืคื™ืงืกื™ื– ืคึฟืึทืจ ืฆื•ื•ื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–

ื ืงืขืจืขืงื˜ื™ื•ื• ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ื™ OpenSSL ืงืจื™ืคึผื˜ืึธื’ืจืึทืคื™ืง ื‘ื™ื‘ืœื™ืึธื˜ืขืง 1.1.1l ืื™ื– ื‘ืืจืขื›ื˜ื™ื’ื˜ ืžื™ื˜ ื“ื™ ื™ืœื™ืžืึทื ื™ื™ืฉืึทืŸ ืคื•ืŸ ืฆื•ื•ื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–:

  • CVE-2021-3711 ืื™ื– ืึท ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ืื™ืŸ ื“ื™ ืงืึธื“ ื™ืžืคึผืœืึทืžืขื ื™ื ื’ ื“ื™ SM2 ืงืจื™ืคึผื˜ืึธื’ืจืึทืคื™ืง ืึทืœื’ืขืจื™ื“ืึทื (ืคึผืจืึธืกื˜ ืื™ืŸ ื˜ืฉื™ื™ื ืึท), ื•ื•ืึธืก ืึทืœืึทื•ื– ืึทืจื•ื™ืฃ ืฆื• 62 ื‘ื™ื˜ืขืก ืฆื• ื–ื™ื™ืŸ ืึธื•ื•ื•ืขืจืจื™ื˜ืึทืŸ ืื™ืŸ ืึท ื’ืขื’ื ื˜ ื•ื•ื™ื™ึทื˜ืขืจ ืคื•ืŸ ื“ื™ ื‘ืึทืคืขืจ ื’ืจืขื ืขืฅ ืจืขื›ื˜ ืฆื• ืึท ื˜ืขื•ืช ืื™ืŸ ืงืึทืœืงื™ืึทืœื™ื™ื˜ื™ื ื’ ื“ื™ ื‘ืึทืคืขืจ ื’ืจื™ื™ืก. ืึท ืึทื˜ืึทืงืขืจ ืงืขืŸ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ื“ืขืจื’ืจื™ื™ื›ืŸ ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืึธื“ืขืจ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืงืจืึทืš ื“ื•ืจืš ืคืึธืจืŸ ืกืคึผืขืฆื™ืขืœ ืงืจืึทืคื˜ืขื“ ื“ื™ืงืึธื•ื“ื™ื ื’ ื“ืึทื˜ืŸ ืฆื• ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื•ื•ืึธืก ื ื•ืฆืŸ ื“ื™ EVP_PKEY_decrypt () ืคึฟื•ื ืงืฆื™ืข ืฆื• ื“ืขืงืจื™ืคึผื˜ SM2 ื“ืึทื˜ืŸ.
  • CVE-2021-3712 ืื™ื– ืึท ื‘ืึทืคืขืจ ืึธื•ื•ื•ืขืจืคืœืึธื• ืื™ืŸ ื“ื™ ASN.1 ืฉื˜ืจื™ืงืœ ืคึผืจืึทืกืขืกื™ื ื’ ืงืึธื“, ื•ื•ืึธืก ืงืขื ืขืŸ ืึธื ืžืึทื›ืŸ ืึท ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืงืจืึทืš ืึธื“ืขืจ ืึทื ื˜ื“ืขืงืŸ ื“ืขื ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ืคึผืจืึธืฆืขืก ื–ื›ึผืจื•ืŸ (ืœืžืฉืœ, ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ืฉืœื™ืกืœืขืŸ ืกื˜ืึธืจื“ ืื™ืŸ ื–ื›ึผืจื•ืŸ) ืื•ื™ื‘ ื“ื™ ืึทื˜ืึทืงืขืจ ืื™ื– ืขืคืขืก ืงืขื ืขืŸ ืฆื• ื“ื–ืฉืขื ืขืจื™ื™ื˜. ืึท ืฉื˜ืจื™ืงืœ ืื™ืŸ ื“ื™ ื™ื ืขืจืœืขืš ASN1_STRING ืกื˜ืจื•ืงื˜ื•ืจ. ื ื™ื˜ ื˜ืขืจืžืึทื ื™ื™ื˜ื™ื“ ื“ื•ืจืš ืึท ื ืึทืœ ื›ืึทืจืึทืงื˜ืขืจ, ืื•ืŸ ืคึผืจืึธืฆืขืก ืขืก ืื™ืŸ OpenSSL ืคืึทื ื’ืงืฉืึทื ื– ื•ื•ืึธืก ื“ืจื•ืงืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ, ืึทื–ืึท ื•ื•ื™ X509_aux_print(), X509_get1_email(), X509_REQ_get1_email() ืื•ืŸ X509_get1_ocsp().

ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜, ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ ื“ื™ LibreSSL ื‘ื™ื‘ืœื™ืึธื˜ืขืง 3.3.4 ืื•ืŸ 3.2.6 ื–ืขื ืขืŸ ื‘ืืคืจื™ื™ื˜, ื•ื•ืึธืก ื˜ืึธืŸ ื ื™ื˜ ื‘ืคื™ืจื•ืฉ ื“ืขืจืžืึธื ืขืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–, ืึธื‘ืขืจ ืื•ื™ื‘ ืžืฉืคื˜ืŸ ืœื•ื™ื˜ ื“ืขืจ ืจืฉื™ืžื” ืคื•ืŸ ืขื ื“ืขืจื•ื ื’ืขืŸ, ื“ื™ CVE-2021-3712 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื™ืœื™ืžืึทื ื™ื™ื˜ืึทื“.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’