အဓိကအကြောင်းအရာသို့ သွားမည်
x

Open Source Secure Socket Layer Protocol တစ်ခုဖြစ်သော OpenSSL ၏ ' 'so_ssl3_write()' Function

Open Source Secure Socket Layer Protocol တစ်ခုဖြစ်သော OpenSSL ၏ ' 'so_ssl3_write()' Function တွင် NULL Pointer Dereference Denial of Service Vulnerability တွေ့ရှိကြောင်းကို ၁၁.၈.၂ဝ၁၄ တွင် Security Focus မှ ထုတ်ပြန်ခဲ့ပါသည်။ Attacker များသည် အဆင်သင့်အသုံးပြုနိုင်သော Attack Tools များ ဖြင့် ၄င်းအားနည်းချက်ကို Exploit ပြုလုပ်၍ အောင်မြင်သွားပါက Application များကို crash ဖြစ်အောင်ပြုလုပ်ပြီး Denial-of-Service ဖြစ်သွားစေမည် ဖြစ်ပါသည်။ အသေးစိတ်ကို အောက်ပါ Link တွင် လေ့လာနိုင်ပါသည်။

http://www.securityfocus.com/bid/67899/discuss

http://xforce.iss.net/xforce/xfdb/93000

http://www.scip.ch/en/?vuldb.13136

Analysis

OpenSSL is vulnerable to a denial of service, caused by a NULL pointer dereference in the do_ssl3_write() function. If SSL_MODE_RELEASE_BUFFERS is enabled, a remote attacker could exploit this vulnerability to cause the application to crash.

The vulnerability will be addressed with the following lines of code:

if (wb->buf == NULL)

if (!ssl3_setup_write_buffer(s))

return -1;