OpenSSL CAÖ¤ÊéÈÆ¹ý·ì϶£¨CVE-2021-3450£©

°ä²¼¹¦·ò 2021-03-26

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-3450

ʱ    ¼ä

2021-03-26

Àà   ÐÍ


µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

 

OpenSSLÊÇÒ»¸öÊ¢¿ªÔ´´úÂëµÄÈí¼þ¿â°ü£¬ÀûÓ÷¨Ê½Äܹ»Ê¹ÓÃÕâ¸ö°üÀ´½øÐа²È«Í¨Ñ¶£¬Ô¤·ÀÇÔÌý£¬Í¬Ê±È·ÈÏÁíÒ»¶ËÏνÓÕßµÄÉí·Ý£¬Ëü±»¿í·ºÀûÓÃÔÚ»¥ÁªÍøµÄÍøÒ³·þÎñÆ÷ÉÏ¡£

2021Äê03ÔÂ25ÈÕ£¬OpenSSLÏîÄ¿°ä²¼°²È«²¼¸æ£¬¹«¿ªÁËOpenSSL²úÆ·ÖеÄÒ»¸ö»Ø¾ø·þÎñ·ì϶ºÍÒ»¸öÖ¤ÊéÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-3449ºÍCVE-2021-3450£©¡£

 

OpenSSL »Ø¾ø·þÎñ·ì϶£¨CVE-2021-3449£©

¸Ã·ì϶ÊÇÓÉÓÚNULLÖ¸ÕëÈ¡µÞÒýÓõ¼ÖµĻؾø·þÎñ(DoS)·ì϶£¬½öÓ°ÏìOpenSSL·þÎñÆ÷Ê·ý£¬¶ø²»Ó°Ïì¿Í»§¶Ë¡£

ÈôÊÇ´Ó¿Í»§¶Ë·¢ËÍÁ˶ñÒâµÄ³ÁÐÂЭÉÌClientHelloÐÂÎÅ£¬ÔòOpenSSL TLS·þÎñÆ÷¿ÉÄÜ»á±ÀÀ£¡£ÈôÊÇTLSv1.2³ÁÐÂЭÉÌClientHelloÊ¡ÂÔÁËsignature_algorithmsÀ©´óÃû£¨ÔÚ×î³õµÄClientHelloÖдæÔÚ£©£¬µ«Ô̺¬ÁËsignature_algorithms_certÀ©´óÃû£¬Ôò½«µ¼ÖÂNULLÖ¸ÕëÈ¡µÞÒýÓ㬴Ӷøµ¼Ö±ÀÀ£ºÍ»Ø¾ø·þÎñ¹¥»÷¡£

ÒÔÏÂÊÇGitHubÉ϶Ը÷ì϶µÄ½¨¸´£º

image.png


Ó°ÏìÁìÓò

ÔËÐдøÓÐTLS 1.2²¢ÆôÓÃÁ˳ÁÐÂЭÉÌ£¨Ä¬ÈÏÅäÖ㩵ÄOpenSSL 1.1.1

 

OpenSSL CAÖ¤ÊéÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-3450£©

¸Ã·ì϶ÊÇÖ¤ÊéÐû¸æ»ú¹¹£¨CA£©Ö¤ÊéÑéÖ¤ÈÆ¹ý·ì϶£¬Ó°Ïì·þÎñÆ÷ºÍ¿Í»§¶ËÊ·ý¡£

X509_V_FLAG_X509_STRICT±êÖ¾¿É¶ÔÖ¤ÊéÁ´ÖдæÔÚµÄÖ¤Êé½øÐÐÆäËü°²È«²é³­£¬Ä¬ÈÏÇé¿öÏÂδÉèÖᣴÓOpenSSL°æ±¾1.1.1hÆðÍ·£¬Ôö³¤ÁËÒ»Ïî²é³­ÒÔ²»ÈÝÔÚÁ´ÖÐÏÔʽ±àÂëÍÖÔ²ÇúÏß²ÎÊýµÄÖ¤Ê飬ÕâÊǸ½¼ÓµÄÑϸñ²é³­¡£Ö´Ðд˲鳭ʱ³öÏÖÒ»¸öÃýÎó£¬ÕâÒâζ×ÅÏÈǰ²é³­µÄÁ˾ֻᱻ¸²¸Ç£¬¸Ã²é³­ÓÃÓÚÈ·ÈÏÁ´ÖеÄÖ¤ÊéÊÇÓÐЧµÄCAÖ¤Êé¡£

Ó°ÏìÁìÓò

OpenSSL 1.1.1h¼°¸ü¸ß°æ±¾

 

´Ë±í£¬½ñÄê2Ô£¬OpenSSL ÏîĿҲ°ä²¼Á˰²È«¸üУ¬½¨¸´ÁËOpenSSLÖеÄ2¸ö»Ø¾ø·þÎñ£¨DoS£©·ì϶ºÍ1¸ö²»ÕýÈ·µÄSSLv2»Ø¹ö±£»¤·ì϶¡£

 

0x02 ´ëÖý¨Òé

Ŀǰ¹Ù·½Òѽ¨¸´ÁËÕâÁ½¸ö·ì϶£¬½¨Òéʵʱ¸üÐÂÖÁOpenSSL 1.1.1k£¨OpenSSL 1.0.2²»ÊÜÕâÁ½¸ö·ì϶ӰÏ죩¡£

ÏÂÔØÁ´½Ó£º

https://openssl.en.softonic.com/


0x03 ²Î¿¼Á´½Ó

https://www.openssl.org/news/secadv/20210325.txt

https://www.bleepingcomputer.com/news/security/openssl-fixes-severe-dos-certificate-validation-vulnerabilities/

https://securityaffairs.co/wordpress/115968/security/openssl-flaws-2.html?

https://github.com/openssl/openssl/commit/2a40b7bc7b94dd7de897a74571e7024f0cf0d63b

 

0x04 ¹¦·òÏß

2021-03-25  OpenSSL°ä²¼°²È«²¼¸æ

2021-03-26  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png