Á¦¸ñ | OpenSSL Ãë¾àÁ¡ º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í |
---|---|
ÀÛ¼ºÀÏ | 2015-12-22 |
¡à °³¿ä o OpenSSL¿¡¼´Â ¼ºñ½º °ÅºÎ °ø°Ý Ãë¾àÁ¡, Race condition Ãë¾àÁ¡ µî 5°³ÀÇ Ãë¾àÁ¡À» º¸¿ÏÇÑ º¸¾È¾÷µ¥ÀÌÆ®¸¦ ¹ßÇ¥[1]
¡à ¼³¸í o NB_mod_exp ÇÔ¼ö¿¡¼ °ªÀ» Á¦°ö ó¸® ÇÒ ¶§ ¹ß»ýÇÏ´Â Ãë¾àÁ¡ (CVE-2015-3193) o ÀÎÁõ¼ °ËÁõ½Ã PSS ÆĶó¹ÌÅÍ ºÎÀç·Î ÀÎÇÑ ¼ºñ½º °ÅºÎ Ãë¾àÁ¡ (CVE-2015-3194) o X509_ATTRIBUTE ±¸Á¶Ã¼¿¡¼ ¹ß»ýÇÏ´Â OpenSSL ¸Þ¸ð¸® ´©¼ö Ãë¾àÁ¡ (CVE-2015-3195) o PSK Identify hint ó¸® Áß ¹ß»ýÇÏ´Â Race condition Ãë¾àÁ¡ (CVE-2015-3196) o ServerKyExchangeÀÇ °ªÀ» ó¸® Áß¿¡ ¹ß»ýÇÏ´Â ¼ºñ½º °ÅºÎ °ø°Ý Ãë¾àÁ¡ (CVE-2015-1794)
¡à ÇØ´ç ½Ã½ºÅÛ o ¿µÇâ ¹Þ´Â Á¦Ç° ¹× ¹öÀü - OpenSSL 1.0.2 - OpenSSL 1.0.1 - OpenSSL 1.0.0 - OpenSSL 0.9.8
¡à ÇØ°á ¹æ¾È o ÇØ´ç Ãë¾àÁ¡¿¡ ¿µÇâ ¹Þ´Â ¹öÀüÀÇ »ç¿ëÀÚ´Â ¾Æ·¡ ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ®[2] - OpenSSL 1.0.2 »ç¿ëÀÚ : 1.0.2e·Î ¾÷µ¥ÀÌÆ® - OpenSSL 1.0.1 »ç¿ëÀÚ : 1.0.1q·Î ¾÷µ¥ÀÌÆ® - OpenSSL 1.0.0 »ç¿ëÀÚ : 1.0.0t·Î ¾÷µ¥ÀÌÆ® - OpenSSL 0.9.8 »ç¿ëÀÚ : 0.9.8zh·Î ¾÷µ¥ÀÌÆ®
¡à ±âŸ ¹®ÀÇ»çÇ× o Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118
[Âü°í»çÀÌÆ®] [1] https://www.openssl.org/news/secadv/20151203.txt [2] https://www.openssl.org/ |
¡ã ÀÌÀü±Û | °¢Á¾ ºê¶ó¿ìÀú SHA-1 ¾Ë°í¸®Áò Áö¿ø ½ºÄÉÁì ¾È³» |
---|---|
¡å ´ÙÀ½±Û | OpenSSL Ãë¾àÁ¡ º¸¾È¾÷µ¥ÀÌÆ® ±Ç°í |