漏洞信息详情
OpenSSL 加密问题漏洞
漏洞简介
OpenSSL是Openssl团队的一个开源的能够实现安全套接层(SSLv2/v3)和安全传输层(TLSv1)协议的通用加密库。该产品支持多种加密算法,包括对称密码、哈希算法、安全散列算法等。
OpenSSL 中存在加密问题漏洞。该漏洞源于DH Pre-master Secret Raccoon。攻击者可利用该漏洞绕过数据访问限制,获取敏感信息。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.openssl.org/news/secadv/20200909.txt
参考网址
来源:N/A
链接:https://www.oracle.com//security-alerts/cpujul2021.html
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20200911-0004/
来源:UBUNTU
链接:https://usn.ubuntu.com/4504-1/
来源:MISC
链接:https://www.oracle.com/security-alerts/cpujan2021.html
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2020/09/msg00016.html
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuoct2021.html
来源:CONFIRM
链接:https://www.openssl.org/news/secadv/20200909.txt
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuApr2021.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4371/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4371.3/
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpuoct2021.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-openssl-vulnerabilites-impacting-aspera-high-speed-transfer-server-aspera-high-speed-transfer-endpoint-aspera-desktop-client-4-0-and-earlier-cve-2020-1968/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-potential-tls-vulnerability-using-diffie-hellman-tls-ciphersuites-in-ibm-datapower-gateway-cve-2020-1968/
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2020-1968
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4298/
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6507573
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6486041
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3431
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021101319
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159195/Ubuntu-Security-Notice-USN-4504-1.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-openssl-vulnerability-cve-2020-1968-impacts-ibm-aspera-streaming-ibm-aspera-streaming-for-video-version-3-9-6-1-and-earlier/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-nx-os-firmware-used-by-ibm-c-type-san-directors-and-switches-2/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3318/
来源:www.oracle.com
链接:https://www.oracle.com/security-alerts/cpujan2021.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-openssl-affect-aix-cve-2020-1968-cve-2020-1971/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4371.2/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-cve-2020-1968-vulnerability-in-openssl-may-affect-ibm-workload-scheduler/
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/OpenSSL-information-disclosure-via-DH-Pre-master-Secret-Raccoon-33287
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-1968
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3170/
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6490375
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-appliance-affected-by-an-openssl-vulnerability-cve-2020-1968/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3493/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-fabric-os-used-by-ibm-b-type-san-directors-and-switches-4/
受影响实体
暂无
补丁
- OpenSSL 安全漏洞的修复措施<!--2020-9-9-->
还没有评论,来说两句吧...