[ °ø Áö ] OpenSSL Ãë¾àÁ¡ º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í 2015-12-08

¾È³çÇϽʴϱî. È£½ºÆ®¸ÕÆ®ÀÔ´Ï´Ù.

¸ÕÀú È£½ºÆ®¸ÕÆ®¸¦ ¾Æ²¸ÁÖ½Ã°í »ç¶ûÇØ Áֽô °í°´ ¿©·¯ºÐ²²  Áø½ÉÀ¸·Î °¨»çµå¸®¸ç

OpenSSL Ãë¾àÁ¡ º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í°¡ ÀÖ¾î À̸¦ ¾Ë·Áµå¸®°íÀÚ ÇÕ´Ï´Ù.

---------------------------------------------------------------------------

¡à °³¿ä

   o OpenSSL¿¡¼­´Â ¼­ºñ½º °ÅºÎ °ø°Ý Ãë¾àÁ¡, Race condition Ãë¾àÁ¡ µî 5°³ÀÇ Ãë¾àÁ¡À» º¸¿ÏÇÑ º¸¾È¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥[1]




¡à ¼³¸í

   o NB_mod_exp ÇÔ¼ö¿¡¼­ °ªÀ» Á¦°ö ó¸® ÇÒ ¶§ ¹ß»ýÇÏ´Â Ãë¾àÁ¡ (CVE-2015-3193)

   o ÀÎÁõ¼­ °ËÁõ½Ã PSS ÆĶó¹ÌÅÍ ºÎÀç·Î ÀÎÇÑ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ (CVE-2015-3194)

   o X509_ATTRIBUTE ±¸Á¶Ã¼¿¡¼­ ¹ß»ýÇÏ´Â OpenSSL ¸Þ¸ð¸® ´©¼ö Ãë¾àÁ¡ (CVE-2015-3195)

   o PSK Identify hint ó¸® Áß ¹ß»ýÇÏ´Â Race condition Ãë¾àÁ¡ (CVE-2015-3196)

   o ServerKyExchangeÀÇ °ªÀ» ó¸® Áß¿¡ ¹ß»ýÇÏ´Â ¼­ºñ½º °ÅºÎ °ø°Ý Ãë¾àÁ¡ (CVE-2015-1794)




¡à ÇØ´ç ½Ã½ºÅÛ

   o ¿µÇâ ¹Þ´Â Á¦Ç° ¹× ¹öÀü

    - OpenSSL 1.0.2

    - OpenSSL 1.0.1

    - OpenSSL 1.0.0

    - OpenSSL 0.9.8




¡à ÇØ°á ¹æ¾È

   o ÇØ´ç Ãë¾àÁ¡¿¡ ¿µÇâ ¹Þ´Â ¹öÀüÀÇ »ç¿ëÀÚ´Â ¾Æ·¡ ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®[2]

    - OpenSSL 1.0.2 »ç¿ëÀÚ : 1.0.2e·Î ¾÷µ¥ÀÌÆ®

    - OpenSSL 1.0.1 »ç¿ëÀÚ : 1.0.1q·Î ¾÷µ¥ÀÌÆ®

    - OpenSSL 1.0.0 »ç¿ëÀÚ : 1.0.0t·Î ¾÷µ¥ÀÌÆ®

    - OpenSSL 0.9.8 »ç¿ëÀÚ : 0.9.8zh·Î ¾÷µ¥ÀÌÆ®




¡à ±âŸ ¹®ÀÇ»çÇ×

   o Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118




[Âü°í»çÀÌÆ®]

[1] https://www.openssl.org/news/secadv/20151203.txt

[2] https://www.openssl.org/

°¨»çÇÕ´Ï´Ù.

---------------------------------------------------------------------------

                    Áñ°Å¿òÀÌ Àִ ȣ½ºÆà ¼­ºñ½º  [ È£½ºÆ®¸ÕÆ® ]