ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ OpenSSL ืื•ืŸ LibreSSL ื•ื•ืึธืก ืคื™ืจื˜ ืฆื• ืึท ืฉืœื™ื™ืฃ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืคืึทืœืฉ ืกืขืจื˜ื™ืคื™ืงืึทืฅ

ื•ื™ืฉืึทืœื˜ ืจื™ืœื™ืกื™ื– ืคื•ืŸ ื“ื™ OpenSSL ืงืจื™ืคึผื˜ืึธื’ืจืึทืคื™ืง ื‘ื™ื‘ืœื™ืึธื˜ืขืง 3.0.2 ืื•ืŸ 1.1.1n ื–ืขื ืขืŸ ื‘ืืจืขื›ื˜ื™ื’ื˜. ื“ืขืจ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืคื™ืงืกื™ื– ืึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2022-0778) ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื ื•ืฆื˜ ืฆื• ืคืึทืจืฉืึทืคืŸ ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜ (ื™ื ืขื ื“ื™ืง ืœื•ืคึผื™ื ื’ ืคื•ืŸ ื“ื™ ื”ืึทื ื“ืœืขืจ). ืฆื• ื’ื•ื•ื•ืจืข ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ืขืก ืื™ื– ื’ืขื ื•ื’ ืฆื• ืคึผืจืึธืฆืขืก ืึท ืกืคึผืขืฉืœื™ ื“ื™ื–ื™ื™ื ื“ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืึทืงืขืจื– ืื™ืŸ ื‘ื™ื™ื“ืข ืกืขืจื•ื•ืขืจ ืื•ืŸ ืงืœื™ืขื ื˜ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื•ื•ืึธืก ืงืขื ืขืŸ ืคึผืจืึธืฆืขืก ื‘ืึทื ื™ืฆืขืจ-ืกืึทืคึผืœื™ื™ื“ ืกืขืจื˜ื™ืคื™ืงืึทืฅ.

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืึท ื–ืฉื•ืง ืื™ืŸ ื“ื™ BN_mod_sqrt() ืคึฟื•ื ืงืฆื™ืข, ื•ื•ืึธืก ืคื™ืจื˜ ืฆื• ืึท ืฉืœื™ื™ืฃ ื•ื•ืขืŸ ืงืึทืœืงื™ืึทืœื™ื™ื˜ื™ื ื’ ืึท ืงื•ื•ืึทื“ืจืึทื˜ ื•ื•ืึธืจืฆืœ ืžืึธื“ื•ืœืึธ ืขืคึผืขืก ืึทื ื“ืขืจืฉ ื•ื•ื™ ืึท ื”ื•ื™ืคึผื˜ ื ื•ืžืขืจ. ื“ื™ ืคึฟื•ื ืงืฆื™ืข ืื™ื– ื’ืขื ื™ืฆื˜ ื•ื•ืขืŸ ืคึผืึทืจืกื™ื ื’ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืžื™ื˜ ืฉืœื™ืกืœืขืŸ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื™ืœื™ืคึผื˜ื™ืงืึทืœ ืงื•ืจื•ื•ืขืก. ืึธืคึผืขืจืึทืฆื™ืข ืงื•ืžื˜ ืึทืจืึธืคึผ ืฆื• ืคืึทืจื‘ื™ื™ึทื˜ืŸ ืคืึทืœืฉ ื™ืœื™ืคึผื˜ื™ืงืึทืœ ื•ื™ืกื‘ื™ื™ื’ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืื™ืŸ ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ. ื•ื•ื™ื™ึทืœ ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืึทืงืขืจื– ืื™ื™ื“ืขืจ ื“ื™ ื“ื™ื’ื™ื˜ืึทืœ ื›ืกื™ืžืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื™ื– ื•ื•ืขืจืึทืคื™ื™ื“, ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ื“ื•ืจืš ืึทืŸ ืึทื ืึธื˜ืขื ื˜ื™ืงืึทื˜ืขื“ ื‘ืึทื ื™ืฆืขืจ ื•ื•ืึธืก ืงืขืŸ ืคืึทืจืฉืึทืคืŸ ื˜ืจืึทื ืกืžื™ื˜ื˜ืขื“ ืึท ืงืœื™ืขื ื˜ ืึธื“ืขืจ ืกืขืจื•ื•ืขืจ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืฆื• ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื ื™ืฆืŸ OpenSSL.

ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื•ื™ืš ืึทืคืขืงืฅ ื“ื™ LibreSSL ื‘ื™ื‘ืœื™ืึธื˜ืขืง ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื“ื•ืจืš ื“ื™ OpenBSD ืคึผืจื•ื™ืขืงื˜, ืึท ืคืึทืจืจื™ื›ื˜ืŸ ืคึฟืึทืจ ื•ื•ืึธืก ืื™ื– ื’ืขื•ื•ืขืŸ ืคืืจื’ืขืœื™ื™ื’ื˜ ืื™ืŸ ื“ื™ ืงืขืจืขืงื˜ื™ื•ื• ืจื™ืœื™ืกื™ื– ืคื•ืŸ LibreSSL 3.3.6, 3.4.3 ืื•ืŸ 3.5.1. ืื™ืŸ ื“ืขืจืฆื•, ืึทืŸ ืึทื ืึทืœื™ืกื™ืก ืคื•ืŸ ื“ื™ ื‘ืื“ื™ื ื’ื•ื ื’ืขืŸ ืคึฟืึทืจ ืขืงืกืคึผืœื•ื™ื˜ื™ื ื’ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืคืืจืขืคื ื˜ืœืขื›ื˜ (ืึท ื‘ื™ื™ืฉืคึผื™ืœ ืคื•ืŸ ืึท ื‘ื™ื™ื–ืข ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื•ื•ืึธืก ื– ื“ื™ ื™ื™ึทื– ืงืึทืœื˜ ืื™ื– ื ืึธืš ื ื™ืฉื˜ ืขืคื ื˜ืœืขืš ืคึผืึธืกื˜ืขื“).

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’