¡¾·ì϶¹«¸æ¡¿OpenSSLÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-2274£©

°ä²¼¹¦·ò 2022-07-05

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2022-2274

·¢ÏÖ¹¦·ò

2022-07-04

Àà    ÐÍ

RCE

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


¹¥»÷¸´ÔÓ¶È


Óû§½»»¥


PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ·ì϶ÏêÇé

OpenSSLÊÇÒ»¸ö׳´óµÄ¡¢Ã³Ò×¼¶µÄ¡¢Ö°ÄÜÆëÈ«µÄ¹¤¾ß°ü£¬£¬ £¬£¬£¬£¬£¬ÓÃÓÚͨÓüÓÃܺͰ²È«Í¨Ñ¶¡£¡£¡£¡£¡£¡£¡£

½üÈÕ£¬£¬ £¬£¬£¬£¬£¬OpenSSL±»Åû¶´æÔÚÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-2274£©£¬£¬ £¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËOpenSSL 3.0.4 °æ±¾¡£¡£¡£¡£¡£¡£¡£

OpenSSL 3.0.4 °æ±¾ÖУ¬£¬ £¬£¬£¬£¬£¬ÔÚÖ§³Ö AVX512IFMA Ö¸ÁîµÄ X86_64 CPU µÄ RSA ʵÏÖÖдæÔÚ°²È«ÎÊÌ⣬£¬ £¬£¬£¬£¬£¬µ¼ÖÂʹÓÃ2048 λ˽ԿµÄRSAÔÚ´ËÀà·þÎñÆ÷ÉÏÔËÐÐÃýÎ󣬣¬ £¬£¬£¬£¬£¬ÔÚÍÆËã¹ý³ÌÖлá²úÉúÄÚ´æ°Ü»µ£¬£¬ £¬£¬£¬£¬£¬¿ÉÀûÓô˷ì϶ÔÚÖ¸±êϵͳÉÏ´¥·¢´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£

 

Ó°ÏìÁìÓò

OpenSSL 3.0.4°æ±¾

×¢£ºÔÚÖ§³ÖX86_64¼Ü¹¹AVX512IFMAÖ¸ÁîµÄ·þÎñÆ÷ÉÏÔËÐеÄSSL/TLS ·þÎñÆ÷»òÆäËüʹÓÃ2048λRSA˽ԿµÄ·þÎñÆ÷ÈÝÒ×ÊÜ´Ë·ì϶ӰÏì¡£¡£¡£¡£¡£¡£¡£

 

0x02 °²È«½¨Òé

OpenSSLÏîÄ¿ÒÑÔÚ7ÔÂ5ÈÕ°ä²¼µÄ3.0.5 °æ±¾Öн¨¸´ÁË´Ë·ì϶¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬£¬OpenSSLÏîÄ¿»¹½¨¸´ÁËAES OCB¼ÓÃÜ·ì϶£¨(CVE-2022-2097£¬£¬ £¬£¬£¬£¬£¬ÖÐΣ)£¬£¬ £¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§Äܹ»Éý¼¶µ½ÒÔϰ汾£º

OpenSSL 3.0.0-3.0.4°æ±¾£ºÉý¼¶µ½ 3.0.5

OpenSSL 1.1.1-1.1.1p °æ±¾£ºÉý¼¶µ½ 1.1.1q

ÏÂÔØÁ´½Ó£º

https://www.openssl.org/source/

 

0x03 ²Î¿¼Á´½Ó

https://www.openssl.org/news/secadv/20220705.txt

https://github.com/openssl/openssl/issues/18625

https://www.cve.org/CVERecord?id=CVE-2022-2274

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

Åú¸ÄÄÚÈÝ

V1.0

2022-07-05

³õ´Î°ä²¼

 

0x05 ¸½Â¼

8827Ì«Ñô¼¯Íżò½é

8827Ì«Ñô¼¯ÍųÉÁ¢ÓÚ1996Ä꣬£¬ £¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢°²È«¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢°²È«²úÆ·¡¢°²È«·þÎñ½â¾ö¹æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°8827Ì«Ñô¼¯ÍÅ´óÏ㬣¬ £¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤½ü4000ÈË£¬£¬ £¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬ £¬£¬£¬£¬£¬Õ¼Óи²¸ÇÈ«¹úµÄÏúÊÛϵͳ¡¢Çþ·ϵͳºÍ¼¼ÊõÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÀö½­ÖÐÓ×°å¹ÒÅÆÉÏÊÓ×£¡£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬ £¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬£¬ £¬£¬£¬£¬£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬£¬ £¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£¡£¡£¡£¡£¡£¡£

 

¹ØÓÚ8827Ì«Ñô¼¯ÍÅ

8827Ì«Ñô¼¯ÍŰ²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£¡£¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«¼ÒºÅ£¬£¬ £¬£¬£¬£¬£¬»ñȡȫÇò×îа²È«×ÊѶ£º

image.png