OpenSSL CAÖ¤ÊéÈÆ¹ý·ì϶£¨CVE-2021-3450£©

°ä²¼¹¦·ò 2021-03-26

0x00 ·ì϶¸ÅÊö

CVE  ID

CVE-2021-3450

ʱ    ¼ä

2021-03-26

Àà   ÐÍ


µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

image.png

 

OpenSSLÊÇÒ»¸öÊ¢¿ªÔ´´úÂëµÄÈí¼þ¿â°ü£¬ £¬ £¬£¬£¬£¬ £¬£¬ÀûÓ÷¨Ê½Äܹ»Ê¹ÓÃÕâ¸ö°üÀ´½øÐа²È«Í¨Ñ¶£¬ £¬ £¬£¬£¬£¬ £¬£¬Ô¤·ÀÇÔÌý£¬ £¬ £¬£¬£¬£¬ £¬£¬Í¬Ê±È·ÈÏÁíÒ»¶ËÏνÓÕßµÄÉí·Ý£¬ £¬ £¬£¬£¬£¬ £¬£¬Ëü±»¿í·ºÀûÓÃÔÚ»¥ÁªÍøµÄÍøÒ³·þÎñÆ÷ÉÏ¡£¡£¡£¡£¡£¡£¡£

2021Äê03ÔÂ25ÈÕ£¬ £¬ £¬£¬£¬£¬ £¬£¬OpenSSLÏîÄ¿°ä²¼°²È«²¼¸æ£¬ £¬ £¬£¬£¬£¬ £¬£¬¹«¿ªÁËOpenSSL²úÆ·ÖеÄÒ»¸ö»Ø¾ø·þÎñ·ì϶ºÍÒ»¸öÖ¤ÊéÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-3449ºÍCVE-2021-3450£©¡£¡£¡£¡£¡£¡£¡£

 

OpenSSL »Ø¾ø·þÎñ·ì϶£¨CVE-2021-3449£©

¸Ã·ì϶ÊÇÓÉÓÚNULLÖ¸ÕëÈ¡µÞÒýÓõ¼ÖµĻؾø·þÎñ(DoS)·ì϶£¬ £¬ £¬£¬£¬£¬ £¬£¬½öÓ°ÏìOpenSSL·þÎñÆ÷Ê·ý£¬ £¬ £¬£¬£¬£¬ £¬£¬¶ø²»Ó°Ïì¿Í»§¶Ë¡£¡£¡£¡£¡£¡£¡£

ÈôÊÇ´Ó¿Í»§¶Ë·¢ËÍÁ˶ñÒâµÄ³ÁÐÂЭÉÌClientHelloÐÂÎÅ£¬ £¬ £¬£¬£¬£¬ £¬£¬ÔòOpenSSL TLS·þÎñÆ÷¿ÉÄÜ»á±ÀÀ£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇTLSv1.2³ÁÐÂЭÉÌClientHelloÊ¡ÂÔÁËsignature_algorithmsÀ©´óÃû£¨ÔÚ×î³õµÄClientHelloÖдæÔÚ£©£¬ £¬ £¬£¬£¬£¬ £¬£¬µ«Ô̺¬ÁËsignature_algorithms_certÀ©´óÃû£¬ £¬ £¬£¬£¬£¬ £¬£¬Ôò½«µ¼ÖÂNULLÖ¸ÕëÈ¡µÞÒýÓ㬠£¬ £¬£¬£¬£¬ £¬£¬´Ó¶øµ¼Ö±ÀÀ£ºÍ»Ø¾ø·þÎñ¹¥»÷¡£¡£¡£¡£¡£¡£¡£

ÒÔÏÂÊÇGitHubÉ϶Ը÷ì϶µÄ½¨¸´£º

image.png


Ó°ÏìÁìÓò

ÔËÐдøÓÐTLS 1.2²¢ÆôÓÃÁ˳ÁÐÂЭÉÌ£¨Ä¬ÈÏÅäÖ㩵ÄOpenSSL 1.1.1

 

OpenSSL CAÖ¤ÊéÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2021-3450£©

¸Ã·ì϶ÊÇÖ¤ÊéÐû¸æ»ú¹¹£¨CA£©Ö¤ÊéÑéÖ¤ÈÆ¹ý·ì϶£¬ £¬ £¬£¬£¬£¬ £¬£¬Ó°Ïì·þÎñÆ÷ºÍ¿Í»§¶ËÊ·ý¡£¡£¡£¡£¡£¡£¡£

X509_V_FLAG_X509_STRICT±êÖ¾¿É¶ÔÖ¤ÊéÁ´ÖдæÔÚµÄÖ¤Êé½øÐÐÆäËü°²È«²é³­£¬ £¬ £¬£¬£¬£¬ £¬£¬Ä¬ÈÏÇé¿öÏÂδÉèÖᣡ£¡£¡£¡£¡£¡£´ÓOpenSSL°æ±¾1.1.1hÆðÍ·£¬ £¬ £¬£¬£¬£¬ £¬£¬Ôö³¤ÁËÒ»Ïî²é³­ÒÔ²»ÈÝÔÚÁ´ÖÐÏÔʽ±àÂëÍÖÔ²ÇúÏß²ÎÊýµÄÖ¤Ê飬 £¬ £¬£¬£¬£¬ £¬£¬ÕâÊǸ½¼ÓµÄÑϸñ²é³­¡£¡£¡£¡£¡£¡£¡£Ö´Ðд˲鳭ʱ³öÏÖÒ»¸öÃýÎó£¬ £¬ £¬£¬£¬£¬ £¬£¬ÕâÒâζ×ÅÏÈǰ²é³­µÄÁ˾ֻᱻ¸²¸Ç£¬ £¬ £¬£¬£¬£¬ £¬£¬¸Ã²é³­ÓÃÓÚÈ·ÈÏÁ´ÖеÄÖ¤ÊéÊÇÓÐЧµÄCAÖ¤Êé¡£¡£¡£¡£¡£¡£¡£

Ó°ÏìÁìÓò

OpenSSL 1.1.1h¼°¸ü¸ß°æ±¾

 

´Ë±í£¬ £¬ £¬£¬£¬£¬ £¬£¬½ñÄê2Ô£¬ £¬ £¬£¬£¬£¬ £¬£¬OpenSSL ÏîĿҲ°ä²¼Á˰²È«¸üУ¬ £¬ £¬£¬£¬£¬ £¬£¬½¨¸´ÁËOpenSSLÖеÄ2¸ö»Ø¾ø·þÎñ£¨DoS£©·ì϶ºÍ1¸ö²»ÕýÈ·µÄSSLv2»Ø¹ö± £»£»£» £»£»£»£»¤·ì϶¡£¡£¡£¡£¡£¡£¡£

 

0x02 ´ëÖý¨Òé

Ŀǰ¹Ù·½Òѽ¨¸´ÁËÕâÁ½¸ö·ì϶£¬ £¬ £¬£¬£¬£¬ £¬£¬½¨Òéʵʱ¸üÐÂÖÁOpenSSL 1.1.1k£¨OpenSSL 1.0.2²»ÊÜÕâÁ½¸ö·ì϶ӰÏ죩¡£¡£¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://openssl.en.softonic.com/


0x03 ²Î¿¼Á´½Ó

https://www.openssl.org/news/secadv/20210325.txt

https://www.bleepingcomputer.com/news/security/openssl-fixes-severe-dos-certificate-validation-vulnerabilities/

https://securityaffairs.co/wordpress/115968/security/openssl-flaws-2.html?

https://github.com/openssl/openssl/commit/2a40b7bc7b94dd7de897a74571e7024f0cf0d63b

 

0x04 ¹¦·òÏß

2021-03-25  OpenSSL°ä²¼°²È«²¼¸æ

2021-03-26  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png