CVE-2020-1971 | OpenSSL»Ø¾ø·þÎñ·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-12-090x00 ·ì϶¸ÅÊö
CVE ID | CVE-2020-1971 | ʱ ¼ä | 2020-12-09 |
Àà ÐÍ | »Ø¾ø·þÎñ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | OpenSSL 1.1.1 - 1.1.1h OpenSSL 1.0.2 - 1.0.2w |
0x01 ·ì϶ÏêÇé

OpenSSLÊÇÒ»¸öÊ¢¿ªÔ´´úÂëµÄÈí¼þ¿â°ü£¬£¬£¬£¬£¬ÀûÓ÷¨Ê½Äܹ»Ê¹ËüÀ´½øÐа²È«Í¨Ñ¶£¬£¬£¬£¬£¬ÒÔÔ¤·À±»ÇÔÌý£¬£¬£¬£¬£¬Í¬Ê±Ëü¿ÉÄÜÈ·ÈÏÁíÒ»¶ËÏνÓÕßµÄÉí·Ý£¬£¬£¬£¬£¬±»¿í·º±»ÀûÓÃÔÚ»¥ÁªÍøµÄÍøÒ³·þÎñÆ÷ÉÏ¡£¡£¡£¡£¡£¡£¡£¡£
2020Äê12ÔÂ08ÈÕ£¬£¬£¬£¬£¬OpenSSL¹Ù·½°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬OpenSSL ÖдæÔÚÒ»¸ö»Ø¾ø·þÎñ·ì϶£¨CVE-2020-1971£©¡£¡£¡£¡£¡£¡£¡£¡£
µ±OpenSSL ʹÓõÄGENERAL_NAME_cmpº¯ÊýºÍGENERAL_NAME º¯Êý¶¼Ô̺¬Ò»¸öEDIPARTYNAMEʱ£¬£¬£¬£¬£¬ÓÉÓÚGENERAL_NAME_cmpº¯ÊýδÄÜÕýÈ·´¦Ö㬣¬£¬£¬£¬½«µ¼Ö¿ÕÖ¸ÕëÒýÓᣡ£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹ØÌåʽÃýÎóµÄEDIPARTYNAMEÀ´ÀûÓô˷ì϶£¬£¬£¬£¬£¬OpenSSLµÄ½âÎöÆ÷½«½ÓÊܸÃÌåʽ£¬£¬£¬£¬£¬×îÖÕ¿ÉÄܵ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£
OpenSSLʹÓõÄGENERAL_NAME_cmpº¯ÊýÓÐÁ½¸ö×÷Óãº
±ÈÁ¦¿ÉÓõÄCRLºÍǶÈëÔÚX509Ö¤ÊéÖеÄCRL·Ö·¢µãÖ®¼äµÄCRL·Ö·¢µãÃû³Æ£»£»£»£»£»£»
ÑéÖ¤¹¦·ò´ÁÏìÓ¦ÁîÅÆÊðÃûÕßÊÇ·ñÓ빦·ò´ÁÊÚȨÃû³ÆÆ¥Å䣨ͨ¹ýAPIº¯ÊýTS_RESP_verify_responseºÍTS_RESP_verify_token£©¡£¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
ĿǰOpenSSLÒѾ½¨¸´ÁË´Ë·ì϶£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁ×îа汾¡£¡£¡£¡£¡£¡£¡£¡£
OpenSSL 1.1.1i
OpenSSL 1.0.2x
£¨×¢£º×Ô2020Äê1ÔÂ1ÈÕÆð£¬£¬£¬£¬£¬OpenSSL 1.0.2²»ÔÙÊÜÖ§³Ö£¬£¬£¬£¬£¬²¢ÇÒ¹Ù·½²»ÔٽӹܸüУ¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁOpenSSL 1.1.1i£©
ÏÂÔØÁ´½Ó£º
https://www.openssl.org/source/openssl-1.1.1i.tar.gz
0x03 ²Î¿¼Á´½Ó
https://www.openssl.org/news/vulnerabilities-1.1.1.html#CVE-2020-1971
https://www.openssl.org/news/vulnerabilities-1.0.2.html#CVE-2020-1971
https://www.openssl.org/source/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1971
0x04 ¹¦·òÏß
2020-12-08 OpenSSL°ä²¼°²È«²¼¸æ
2020-12-09 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ