Mbed TLSÔ¶³Ì´úÂëÖ´ÐÐÎó²î
2017-04-20
ÍâµØÊ±¼ä2017Äê4ÔÂ19ÈÕ£¨±±¾©Ê±¼ä2017Äê4ÔÂ20ÈÕ£©£¬ARM ÆìϵÄmbedTLS±»±¬³ö±£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2017-2784£©¡£ARM mbedTLS 2.4.0µÄx509Ö¤ÊéÆÊÎö´úÂëÖб£´æÎÞ¿ÉÓõÄÕ»Ö¸ÕëÎó²î¡£ ÓÉmbedTLS¿âÆÊÎöʱ£¬ÌØÖƵÄx509Ö¤Êé¿ÉÄÜÔì³ÉÎÞЧµÄÕ»Ö¸Õ룬´Ó¶øµ¼ÖÂDZÔÚµÄÔ¶³Ì´úÂëÖ´ÐС£
ʹÓôËÎó²î£¬¹¥»÷Õß¿ÉÒÔ³äµ±ÍøÂçÉϵĿͻ§¶Ë»ò·þÎñÆ÷£¬½«¶ñÒâx509Ö¤Êéת´ï¸øÒ×Êܹ¥»÷µÄÓ¦ÓóÌÐò¡£¹Ù·½ÒѾÐû²¼Ïà¹Ø²¹¶¡ÐÞ¸´Á˸ÃÎó²î¡£
²Î¿¼Á´½Ó£º
http://www.talosintelligence.com/reports/TALOS-2017-0274/
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2017-01
ÊÜÓ°ÏìµÄ°æ±¾
- mbed TLS Version >= 1.4
²»ÊÜÓ°ÏìµÄ°æ±¾
- mbed TLS Version >= 1.3.19
- mbed TLS Version >= 2.1.7
- mbed TLS Version >= 2.4.2
- ÒÔ¼°ÆäËû²»Ö§³Ösecp224k1ÇúÏß±àÒëµÄ°æ±¾
¹æ±Ü¼Æ»®
- ARM¹Ù·½ÒѾÐû²¼ÁËÏà¹ØÎó²îµÄÐÞ¸´²¹¶¡£¬ÈôÊÇÓû§Ê¹ÓÃÁËÊÜÓ°ÏìµÄ°æ±¾£¬Ç뾡¿ìÉý¼¶¸üе½²»ÊÜÓ°ÏìµÄ°æ±¾¡£ÏÂÔØÁ´½ÓÈçÏ£º
https://tls.mbed.org/download-archive
- ÈôÊÇÓû§ÔÝʱδ±ãÉý¼¶ÖÁа汾£¬Ò²¿ÉÒÔ½ÓÄÉÔÝʱÐÞ¸´¼Æ»®£º
ͨ¹ýեȡÔÚconfig.hÎļþϵÄMBEDTLS_ECP_DP_SECP224K1_ENABLEDÑ¡ÏîÀ´¹Ø±ÕʹÓÃsecp224k1ÇúÏߵıàÒ빦Ч£¬¿ÉÒÔÓÐÓ÷À»¤´ËÎó²î¡£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ





