CVE-2020-1971 | OpenSSL»Ø¾ø·þÎñ·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-12-090x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-1971 | ʱ ¼ä | 2020-12-09 |
Àà ÐÍ | »Ø¾ø·þÎñ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | OpenSSL 1.1.1 - 1.1.1h OpenSSL 1.0.2 - 1.0.2w |
0x01 ·ì϶ÏêÇé

OpenSSLÊÇÒ»¸öÊ¢¿ªÔ´´úÂëµÄÈí¼þ¿â°ü£¬ÀûÓ÷¨Ê½Äܹ»Ê¹ËüÀ´½øÐа²È«Í¨Ñ¶£¬ÒÔÔ¤·À±»ÇÔÌý£¬Í¬Ê±Ëü¿ÉÄÜÈ·ÈÏÁíÒ»¶ËÏνÓÕßµÄÉí·Ý£¬±»¿í·º±»ÀûÓÃÔÚ»¥ÁªÍøµÄÍøÒ³·þÎñÆ÷ÉÏ¡£
2020Äê12ÔÂ08ÈÕ£¬OpenSSL¹Ù·½°ä²¼°²È«²¼¸æ£¬OpenSSL ÖдæÔÚÒ»¸ö»Ø¾ø·þÎñ·ì϶£¨CVE-2020-1971£©¡£
µ±OpenSSL ʹÓõÄGENERAL_NAME_cmpº¯ÊýºÍGENERAL_NAME º¯Êý¶¼Ô̺¬Ò»¸öEDIPARTYNAMEʱ£¬ÓÉÓÚGENERAL_NAME_cmpº¯ÊýδÄÜÕýÈ·´¦Ö㬽«µ¼Ö¿ÕÖ¸ÕëÒýÓ᣹¥»÷ÕßÄܹ»Í¨¹ý»ú¹ØÌåʽÃýÎóµÄEDIPARTYNAMEÀ´ÀûÓô˷ì϶£¬OpenSSLµÄ½âÎöÆ÷½«½ÓÊܸÃÌåʽ£¬×îÖÕ¿ÉÄܵ¼Ö»ؾø·þÎñ¡£
OpenSSLʹÓõÄGENERAL_NAME_cmpº¯ÊýÓÐÁ½¸ö×÷Óãº
±ÈÁ¦¿ÉÓõÄCRLºÍǶÈëÔÚX509Ö¤ÊéÖеÄCRL·Ö·¢µãÖ®¼äµÄCRL·Ö·¢µãÃû³Æ£»
ÑéÖ¤¹¦·ò´ÁÏìÓ¦ÁîÅÆÊðÃûÕßÊÇ·ñÓ빦·ò´ÁÊÚȨÃû³ÆÆ¥Å䣨ͨ¹ýAPIº¯ÊýTS_RESP_verify_responseºÍTS_RESP_verify_token£©¡£
0x02 ´ëÖý¨Òé
ĿǰOpenSSLÒѾ½¨¸´ÁË´Ë·ì϶£¬½¨ÒéÉý¼¶ÖÁ×îа汾¡£
OpenSSL 1.1.1i
OpenSSL 1.0.2x
£¨×¢£º×Ô2020Äê1ÔÂ1ÈÕÆð£¬OpenSSL 1.0.2²»ÔÙÊÜÖ§³Ö£¬²¢ÇÒ¹Ù·½²»ÔٽӹܸüУ¬½¨ÒéÉý¼¶ÖÁOpenSSL 1.1.1i£©
ÏÂÔØÁ´½Ó£º
https://www.openssl.org/source/openssl-1.1.1i.tar.gz
0x03 ²Î¿¼Á´½Ó
https://www.openssl.org/news/vulnerabilities-1.1.1.html#CVE-2020-1971
https://www.openssl.org/news/vulnerabilities-1.0.2.html#CVE-2020-1971
https://www.openssl.org/source/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1971
0x04 ¹¦·òÏß
2020-12-08 OpenSSL°ä²¼°²È«²¼¸æ
2020-12-09 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ