安全公告/【CVE-2018-0739】
基本信息
漏洞描述
构造的具有递归定义的 ASN.1 类型(例如可以在 PKCS7 中找到)最终可能会在恶意输入过多递归的情况下超出堆栈。这可能会导致拒绝服务攻击。SSL/TLS 中没有使用来自不受信任来源的此类结构,因此这被认为是安全的。已在 OpenSSL 1.1.0h 中修复(受影响的 1.1.0-1.1.0g)。已在 OpenSSL 1.0.2o 中修复(受影响的 1.0.2b-1.0.2n)。
修复方式
软件包升级 dnf update shim
参考
https://www.openssl.org/news/secadv/20180327.txt
http://www.securitytracker.com/id/1040576
http://www.securityfocus.com/bid/103518
https://usn.ubuntu.com/3611-1/
https://www.debian.org/security/2018/dsa-4158
https://www.debian.org/security/2018/dsa-4157
https://security.netapp.com/advisory/ntap-20180330-0002/
https://lists.debian.org/debian-lts-announce/2018/03/msg00033.html
https://usn.ubuntu.com/3611-2/
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
https://www.tenable.com/security/tns-2018-04
https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/
https://www.tenable.com/security/tns-2018-07
https://www.tenable.com/security/tns-2018-06
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
https://security.netapp.com/advisory/ntap-20180726-0002/
https://securityadvisories.paloaltonetworks.com/Home/Detail/133
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
http://www.securityfocus.com/bid/105609
https://access.redhat.com/errata/RHSA-2018:3221
https://access.redhat.com/errata/RHSA-2018:3090
https://access.redhat.com/errata/RHSA-2018:3505
https://security.gentoo.org/glsa/201811-21
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
https://access.redhat.com/errata/RHSA-2019:0367
https://access.redhat.com/errata/RHSA-2019:0366
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://access.redhat.com/errata/RHSA-2019:1711
https://access.redhat.com/errata/RHSA-2019:1712
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://security.gentoo.org/glsa/202007-53
https://www.oracle.com//security-alerts/cpujul2021.html
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2ac4c6f7b2b2af20c0e2b0ba05367e454cd11b33
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9310d45087ae546e27e61ddf8f6367f29848220d