I-OpenSSL 1.1.1g eshicilelwe ngokulungiswa kwe-TLS 1.3 sengozini

Iyatholakala ukukhishwa okulungisayo komtapo we-cryptographic I-OpenSSL 1.1.1g, lapho iqedwa khona ukuba sengozini (I-CVE-2020-1967), okuholela ekunqatshelweni kwesevisi lapho izama ukuxoxisana ngoxhumo lwe-TLS 1.3 neseva elawulwa umhlaseli noma iklayenti. Ukuba sengozini kukalwe njengobunzima obuphezulu.

Inkinga ivela kuphela ezinhlelweni ezisebenzisa umsebenzi we-SSL_check_chain() futhi ibangele ukuthi inqubo iphahlazeke uma isandiso se-TLS esithi β€œsignature_algorithms_cert” sisetshenziswa ngokungalungile. Ikakhulukazi, uma inqubo yezingxoxo zokuxhuma ithola inani elingasekelwe noma elingalungile le-algorithm yokucubungula isiginesha yedijithali, i-NULL pointer dereference iyenzeka futhi inqubo iyaphahlazeka. Inkinga ivela kusukela ekukhishweni kwe-OpenSSL 1.1.1d.

Source: opennet.ru

Engeza amazwana