|
 |
[ °ø Áö ] OpenSSL Ãë¾àÁ¡ º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í |
 |
2016-01-29 |
|
 |
¾È³çÇϽʴϱî. È£½ºÆ®¸ÕÆ®ÀÔ´Ï´Ù.
¸ÕÀú È£½ºÆ®¸ÕÆ®¸¦ ¾Æ²¸ÁÖ½Ã°í »ç¶ûÇØ Áֽô °í°´ ¿©·¯ºÐ²² Áø½ÉÀ¸·Î °¨»çµå¸®¸ç
OpenSSL Ãë¾àÁ¡ º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í°¡ ÀÖ¾î À̸¦ ¾Ë·Áµå¸®°íÀÚ ÇÕ´Ï´Ù.
---------------------------------------------------------------------------
¡à °³¿ä
o OpenSSL¿¡¼´Â Ű ±³È¯¿¡¼ Áß°£ÀÚ °ø°ÝÀÌ °¡´ÉÇÑ Ãë¾àÁ¡, SSLv2ÀÇ ÇÚµå¼ÎÀÌÅ© Àü¼Û¿¡¼ Áß°£ÀÚ °ø°ÝÀÌ °¡´ÉÇÑ Ãë¾àÁ¡ µî 2°³ÀÇ Ãë¾àÁ¡À»
º¸¿ÏÇÑ º¸¾È¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥[1]
¡à ¼³¸í
o TLS ÇÁ·ÎÅäÄÝÀÇ Diffie-Hellman Ű ±³È¯¿¡¼ ¼Ò¼ö °ª ó¸® Áß MITM(man-in-the-middle)°ø°ÝÀÌ °¡´ÉÇÑ Ãë¾àÁ¡(CVE-2016-0701)
o SSLv2À» »ç¿ëÇÒ °æ¿ì Á¶ÀÛµÈ ÇÚµå¼ÎÀÌÅ© Àü¼ÛÀ» ÅëÇÑ MITM(man-in-the-middle)°ø°ÝÀÌ °¡´ÉÇÑ Ãë¾àÁ¡(CVE-2015-3197)
¡à ÇØ´ç ½Ã½ºÅÛ
o ¿µÇâ ¹Þ´Â Á¦Ç° ¹× ¹öÀü
- OpenSSL 1.0.2 ´ë ¹öÀü
- OpenSSL 1.0.1 ´ë ¹öÀü
¡à ÇØ°á ¹æ¾È
o ÇØ´ç Ãë¾àÁ¡¿¡ ¿µÇâ ¹Þ´Â ¹öÀüÀÇ »ç¿ëÀÚ´Â ¾Æ·¡ ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®[2]
- OpenSSL 1.0.2 »ç¿ëÀÚ : 1.0.2f·Î ¾÷µ¥ÀÌÆ®
- OpenSSL 1.0.1 »ç¿ëÀÚ : 1.0.1r·Î ¾÷µ¥ÀÌÆ®
¡à ¿ë¾î ¼³¸í
o Diffie-Hellman Ű ±³È¯ : ¾ÏÈ£È µÇÁö ¾ÊÀº Åë½Å¸Á¿¡¼ÀÇ °øÅëÀÇ ºñ¹Ð Ű °øÀ¯¸¦ À§ÇÑ ¾Ë°í¸®Áò
¡à ±âŸ ¹®ÀÇ»çÇ×
o Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝÄ§ÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118
[Âü°í»çÀÌÆ®]
[1] https://www.openssl.org/news/secadv/20160128.txt
[2] https://www.openssl.org/
°¨»çÇÕ´Ï´Ù.
---------------------------------------------------------------------------
Áñ°Å¿òÀÌ Àִ ȣ½ºÆÃ ¼ºñ½º [ È£½ºÆ®¸ÕÆ® ]
|
|
|