Open Source Secure Socket Layer Protocol တစ်ခုဖြစ်သော OpenSSL ၏ ' 'so_ssl3_write()' Function
Open Source Secure Socket Layer Protocol တစ်ခုဖြစ်သော OpenSSL ၏ ' 'so_ssl3_write()' Function တွင် NULL Pointer Dereference Denial of Service Vulnerability တွေ့ရှိကြောင်းကို ၈.၉.၂ဝ၁၄ တွင် Security Focus မှ ထုတ်ပြန်ခဲ့ပါသည်။ Attacker များသည် အဆင်သင့်အသုံးပြုနိုင်သော Attack Tools များ ဖြင့် ၄င်းအားနည်းချက်ကို Exploit ပြုလုပ်၍ အောင်မြင်သွားပါက Application များကို crash ဖြစ်အောင်ပြုလုပ်ပြီး Denial-of-Service ဖြစ်သွားစေမည် ဖြစ်ပါသည်။ အသေးစိတ်ကို အောက်ပါ Link တွင် လေ့လာနိုင်ပါသည်။
http://www.securityfocus.com/bid/67899/discuss
http://xforce.iss.net/xforce/xfdb/93000
http://www.scip.ch/en/?vuldb.13136
Analysis
OpenSSL is vulnerable to a denial of service, caused by a NULL pointer dereference in the do_ssl3_write() function. If SSL_MODE_RELEASE_BUFFERS is enabled, a remote attacker could exploit this vulnerability to cause the application to crash..
The vulnerability will be addressed with the following lines of code:
if (wb->buf == NULL)
if (!ssl3_setup_write_buffer(s))
return -1;
