OpenSSLÐÄÌø°üÔ½½ç¶ÁÃô¸ÐÐÅÏ¢×ß©Îó²î (Alert2014-04)
2014-04-09
ÐÎò£º
CVE ID£ºCVE-2014-0160ÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
====================
OpenSSL 1.0.1£OpenSSL 1.0.1f
OpenSSL 1.0.2-beta
OpenSSL 1.0.2-beta1
δÊÜÓ°ÏìµÄÈí¼þ¼°ÏµÍ³£º
======================
OpenSSL 0.9.8
OpenSSL 1.0.0
OpenSSL 1.0.1g
OpenSSL 1.0.2-beta2
======
OpenSSLÊÇÒ»ÖÖ¿ª·ÅÔ´ÂëµÄSSLʵÏÖ£¬ÓÃÀ´ÊµÏÖÍøÂçͨѶµÄ¸ßÇ¿¶È¼ÓÃÜ£¬ÏÖÔÚ±»ÆÕ±éµØÓÃÓÚÖÖÖÖÍøÂçÓ¦ÓóÌÐòÖС£
ÓÉÓÚOpenSSLÔÚ´¦Öóͷ£TLSÐÄÌøÀ©Õ¹ÖÐûÓоÙÐнçÏß¼ì²é£¬Õâ¿Éµ¼ÖÂ64KµÄÄÚ´æÐÅÏ¢×ß©¸øÒÑÅþÁ¬µÄ¿Í»§¶Ë»ò·þÎñÆ÷¡£Ö»ÓÐOpenSSLµÄ1.0.1¼°1.0.2-betaϵÁа汾Êܵ½Ó°Ï죬°üÀ¨£º1.0.1f¼°1.0.2-beta1°æ±¾¡£
¼øÓÚ´ËÎó²îµÄÑÏÖØË®Æ½£¬½¨ÒéÕýÔÚʹÓÃÊÜÓ°Ïì°æ±¾µÄÓû§Á¬Ã¦Éý¼¶µ½×îа汾¡£
======
TLSÐÄÌøÓÉÒ»¸öÇëÇó°ü×é³É£¬ÆäÖаüÀ¨ÓÐÓÃÔØºÉ£¨payload£©£¬Í¨Ñ¶µÄÁíÒ»·½½«¶ÁÈ¡Õâ¸ö°ü²¢·¢ËÍÒ»¸öÏìÓ¦£¬ÆäÖаüÀ¨Í¬ÑùµÄÔØºÉ¡£ÔÚ´¦Öóͷ£ÐÄÌøÇëÇóµÄ´úÂëÖУ¬ÔغɾÞϸÊÇ´Ó¹¥»÷Õ߿ɿصİüÖжÁÈ¡µÄ¡£ÓÉÓÚOpenSSL²¢Ã»Óмì²é¸ÃÔØºÉ¾Þϸֵ£¬´Ó¶øµ¼ÖÂÔ½½ç¶Á£¬Ôì³ÉÁËÃô¸ÐÐÅÏ¢×ß©¡£
×ß©µÄÐÅÏ¢ÄÚÈÝ¿ÉÄÜ»á°üÀ¨¼ÓÃܵÄ˽ԿºÍÆäËûÃô¸ÐÐÅÏ¢ÀýÈçÓû§Ãû¡¢¿ÚÁîµÈ¡£
½â¾öÒªÁ죺
NSFOCUS½¨ÒéÄúÉý¼¶µ½OpenSSL 1.0.1g¡£µ«ÈôÊÇÄú²»¿ÉÁ¬Ã¦×°Öò¹¶¡»òÕßÉý¼¶£¬Äú¿ÉÒÔ½ÓÄÉÒÔϲ½·¥ÒÔ½µµÍÍþв£º* ʹÓÃ-DOPENSSL_NO_HEARTBEATSÑ¡ÏîÖØ±àÒëOpenSSL¡£
==========
OpensslÒѾÐû²¼ÁËOpenssl 1.0.1gÐÞ¸´´ËÎÊÌ⣬:
³§ÉÌÇ徲ͨ¸æ£º
https://www.openssl.org/news/secadv_20140407.txt
¹ØÓÚOpenSSL 1.0.2 Releases, ³§ÉÌÌåÏÖ½«»áÔÚ1.0.2-beta2ÖÐÐÞ¸´¡£
Ö÷Á÷Linux¿¯ÐаæÒ²ÒѾÐû²¼Ïà¹Ø²¹¶¡£¬Ç뾡¿ìÉý¼¶¡£
==========
1. https://www.openssl.org/news/secadv_20140407.txt
2. http://heartbleed.com/

¾ÅÓÎÀϸçÔÆ





