CVE-2020-1971 | OpenSSL»Ø¾ø·þÎñ·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-12-09


0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2020-1971

ʱ      ¼ä

2020-12-09

Àà     ÐÍ

»Ø¾ø·þÎñ

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

OpenSSL 1.1.1 - 1.1.1h

OpenSSL 1.0.2 - 1.0.2w

 

0x01 ·ì϶ÏêÇé

 

image.png

OpenSSLÊÇÒ»¸öÊ¢¿ªÔ´´úÂëµÄÈí¼þ¿â°ü£¬ÀûÓ÷¨Ê½Äܹ»Ê¹ËüÀ´½øÐа²È«Í¨Ñ¶£¬ÒÔÔ¤·À±»ÇÔÌý£¬Í¬Ê±Ëü¿ÉÄÜÈ·ÈÏÁíÒ»¶ËÏνÓÕßµÄÉí·Ý£¬±»¿í·º±»ÀûÓÃÔÚ»¥ÁªÍøµÄÍøÒ³·þÎñÆ÷ÉÏ¡£

2020Äê12ÔÂ08ÈÕ£¬OpenSSL¹Ù·½°ä²¼°²È«²¼¸æ£¬OpenSSL ÖдæÔÚÒ»¸ö»Ø¾ø·þÎñ·ì϶£¨CVE-2020-1971£©¡£

µ±OpenSSL ʹÓõÄGENERAL_NAME_cmpº¯ÊýºÍGENERAL_NAME º¯Êý¶¼Ô̺¬Ò»¸öEDIPARTYNAMEʱ£¬ÓÉÓÚGENERAL_NAME_cmpº¯ÊýδÄÜÕýÈ·´¦Ö㬽«µ¼Ö¿ÕÖ¸ÕëÒýÓ᣹¥»÷ÕßÄܹ»Í¨¹ý»ú¹ØÌåʽÃýÎóµÄEDIPARTYNAMEÀ´ÀûÓô˷ì϶£¬OpenSSLµÄ½âÎöÆ÷½«½ÓÊܸÃÌåʽ£¬×îÖÕ¿ÉÄܵ¼Ö»ؾø·þÎñ¡£

OpenSSLʹÓõÄGENERAL_NAME_cmpº¯ÊýÓÐÁ½¸ö×÷Óãº

±ÈÁ¦¿ÉÓõÄCRLºÍǶÈëÔÚX509Ö¤ÊéÖеÄCRL·Ö·¢µãÖ®¼äµÄCRL·Ö·¢µãÃû³Æ£»

ÑéÖ¤¹¦·ò´ÁÏìÓ¦ÁîÅÆÊðÃûÕßÊÇ·ñÓ빦·ò´ÁÊÚȨÃû³ÆÆ¥Å䣨ͨ¹ýAPIº¯ÊýTS_RESP_verify_responseºÍTS_RESP_verify_token£©¡£

 

0x02 ´ëÖý¨Òé

ĿǰOpenSSLÒѾ­½¨¸´ÁË´Ë·ì϶£¬½¨ÒéÉý¼¶ÖÁ×îа汾¡£

OpenSSL 1.1.1i

OpenSSL 1.0.2x

£¨×¢£º×Ô2020Äê1ÔÂ1ÈÕÆð£¬OpenSSL 1.0.2²»ÔÙÊÜÖ§³Ö£¬²¢ÇÒ¹Ù·½²»ÔٽӹܸüУ¬½¨ÒéÉý¼¶ÖÁOpenSSL 1.1.1i£©

 

ÏÂÔØÁ´½Ó£º

https://www.openssl.org/source/openssl-1.1.1i.tar.gz

 

0x03 ²Î¿¼Á´½Ó

https://www.openssl.org/news/vulnerabilities-1.1.1.html#CVE-2020-1971

https://www.openssl.org/news/vulnerabilities-1.0.2.html#CVE-2020-1971

https://www.openssl.org/source/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1971

 

0x04 ¹¦·òÏß

2020-12-08  OpenSSL°ä²¼°²È«²¼¸æ

2020-12-09  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/


 

image.png