CVE-2020-1971 | OpenSSL¾Ü¾øÐ§ÀÍÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-12-090x00 Îó²î¸ÅÊö
CVE ID | CVE-2020-1971 | ʱ ¼ä | 2020-12-09 |
Àà ÐÍ | ¾Ü¾øÐ§ÀÍ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | OpenSSL 1.1.1 - 1.1.1h OpenSSL 1.0.2 - 1.0.2w |
0x01 Îó²îÏêÇé
OpenSSLÊÇÒ»¸ö¿ª·ÅÔ´´úÂëµÄÈí¼þ¿â°ü£¬£¬£¬£¬£¬£¬£¬Ó¦ÓóÌÐò¿ÉÒÔʹËüÀ´¾ÙÐÐÇ徲ͨѶ£¬£¬£¬£¬£¬£¬£¬ÒÔ×èÖ¹±»ÇÔÌý£¬£¬£¬£¬£¬£¬£¬Í¬Ê±ËüÄܹ»È·ÈÏÁíÒ»¶ËÅþÁ¬ÕßµÄÉí·Ý£¬£¬£¬£¬£¬£¬£¬±»ÆÕ±é±»Ó¦ÓÃÔÚ»¥ÁªÍøµÄÍøÒ³Ð§ÀÍÆ÷ÉÏ¡£¡£¡£¡£¡£
2020Äê12ÔÂ08ÈÕ£¬£¬£¬£¬£¬£¬£¬OpenSSL¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬OpenSSL Öб£´æÒ»¸ö¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2020-1971£©¡£¡£¡£¡£¡£
µ±OpenSSL ʹÓõÄGENERAL_NAME_cmpº¯ÊýºÍGENERAL_NAME º¯Êý¶¼°üÀ¨Ò»¸öEDIPARTYNAMEʱ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚGENERAL_NAME_cmpº¯ÊýδÄÜ׼ȷ´¦Öóͷ££¬£¬£¬£¬£¬£¬£¬½«µ¼Ö¿ÕÖ¸ÕëÒýÓᣡ£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹ÃûÌùýʧµÄEDIPARTYNAMEÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬£¬£¬OpenSSLµÄÆÊÎöÆ÷½«½ÓÊܸÃÃûÌ㬣¬£¬£¬£¬£¬£¬×îÖÕ¿ÉÄܵ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£¡£
OpenSSLʹÓõÄGENERAL_NAME_cmpº¯ÊýÓÐÁ½¸ö×÷Óãº
½ÏÁ¿¿ÉÓõÄCRLºÍǶÈëÔÚX509Ö¤ÊéÖеÄCRL·Ö·¢µãÖ®¼äµÄCRL·Ö·¢µãÃû³Æ£»£»£»£»
Ñé֤ʱ¼ä´ÁÏìÓ¦ÁîÅÆÊðÃûÕßÊÇ·ñÓëʱ¼ä´ÁÊÚȨÃû³ÆÆ¥Å䣨ͨ¹ýAPIº¯ÊýTS_RESP_verify_responseºÍTS_RESP_verify_token£©¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚOpenSSLÒѾÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁ×îа汾¡£¡£¡£¡£¡£
OpenSSL 1.1.1i
OpenSSL 1.0.2x
£¨×¢£º×Ô2020Äê1ÔÂ1ÈÕÆð£¬£¬£¬£¬£¬£¬£¬OpenSSL 1.0.2²»ÔÙÊÜÖ§³Ö£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¹Ù·½²»ÔÙÎüÊÕ¸üУ¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁOpenSSL 1.1.1i£©
ÏÂÔØÁ´½Ó£º
https://www.openssl.org/source/openssl-1.1.1i.tar.gz
0x03 ²Î¿¼Á´½Ó
https://www.openssl.org/news/vulnerabilities-1.1.1.html#CVE-2020-1971
https://www.openssl.org/news/vulnerabilities-1.0.2.html#CVE-2020-1971
https://www.openssl.org/source/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1971
0x04 ʱ¼äÏß
2020-12-08 OpenSSLÐû²¼Ç徲ͨ¸æ
2020-12-09 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/