漏洞描述
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
security.gentoo.orghttps://security.gentoo.org/glsa/201504-01↗www.oracle.comhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html↗my.opera.comhttp://my.opera.com/securitygroup/blog/2013/03/20/on-the-precariousness-of-rc4↗www.oracle.comhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html↗www.isg.rhul.ac.ukhttp://www.isg.rhul.ac.uk/tls/↗www.oracle.comhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html↗www.oracle.comhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html↗h20566.www2.hpe.comhttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888↗h20566.www2.hpe.comhttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935↗cr.yp.tohttp://cr.yp.to/talks/2013.03.12/slides.pdf↗www.mozilla.orghttp://www.mozilla.org/security/announce/2013/mfsa2013-103.html↗security.gentoo.orghttp://security.gentoo.org/glsa/glsa-201406-19.xml↗kb.juniper.nethttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705↗www.ubuntu.comhttp://www.ubuntu.com/usn/USN-2032-1↗www.ubuntu.comhttp://www.ubuntu.com/usn/USN-2031-1↗www.securityfocus.comhttp://www.securityfocus.com/bid/58796↗www.oracle.comhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html↗www.opera.comhttp://www.opera.com/docs/changelogs/unified/1215/↗blog.cryptographyengineering.comhttp://blog.cryptographyengineering.com/2013/03/attack-of-week-rc4-is-kind-of-broken-in.html↗www.opera.comhttp://www.opera.com/security/advisory/1046↗marc.infohttp://marc.info/?l=bugtraq&m=143039468003789&w=2↗