English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22247
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç À¥ ¼­¹ö´Â 0.9.6m ȤÀº 0.9.7d º¸´Ù ´õ ¿À·¡µÈ OpenSSL ¹öÀüÀ» °¡µ¿Çϰí ÀÖ´Ù. ¹ß°ßµÈ ¹öÀü¿¡ ÀÖ´Â ¼ö °³ÀÇ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â È£½ºÆ®¿¡ ´ëÇØ ¼­ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å³ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. OpenSSLÀº SSL (Secure Sockets Layer) ±×¸®°í TLS (Transport Layer Security) ÇÁ·ÎÅäÄݵéÀÇ °ø°³ ¼Ò½º ±¸ÇöÀÌ´Ù.
´ÙÀ½°ú °°Àº OpenSSL¿¡ ¿µÇâÀ» ¹ÌÄ¡´Â ¼¼ °¡ÁöÀÇ Ãë¾àÁ¡µéÀÌ º¸°íµÇ¾î ÀÖ´Ù:

1. ù¹øÂ° Ãë¾àÁ¡Àº SSL/TLS Á¢¼Ó(handshake) ±³È¯ ½Ã °ø°ÝÀڵ鿡 ÀÇÇØ ÀÌ¿ë´çÇÒ ¼ö ÀÖ´Â NULL Æ÷ÀÎÅÍ ÇÒ´çÀÌ´Ù. ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ CVE ÇÒ´ç ¸íÀº CVE-2004-0079ÀÌ´Ù. 0.9.6c¿¡¼­ 0.9.6k±îÁö ±×¸®°í 0.9.7a¿¡¼­ 0.9.7c ±îÁöÀÇ ¹öÀüµéÀº Ãë¾àÇÏ´Ù.
2. µÎ¹øÂ° Ãë¾àÁ¡µµ SSL/TLS Á¢¼Ó(handshake) ½Ã µµ¿ëµÉ ¼ö ÀÖ´Ù. ÀÌ °æ¿ì¿¡ À־´Â Kerberos ¾Ïȣȭ ¸ðµâ(ciphersuite)µéÀÌ »ç¿ëµÇ°í ÀÖÀ» ¶§·Î¸¸ ÇÑÁ¤µÇ¾î Áø´Ù. ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ CVE ÇÒ´ç ¸íÀº CVE-2004-0112ÀÌ´Ù. 0.9.7a, 0.9.7b, ±×¸®°í 0.9.7c ¹öÀüµéÀº Ãë¾àÇÏ´Ù.
3. ¼¼¹øÂ° ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡Àº 0.9.6¿¡ ¿µÇâÀ» ¹ÌÄ¡´Â °ÍÀ¸·Î 0.9.6d¿¡¼­ ±³Á¤µÇ¾ú´Ù. ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ CVE ÇÒ´ç ¸íÀº CVE-2004-0081ÀÌ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç FTP ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.kb.cert.org/vuls/id/288574
http://www.kb.cert.org/vuls/id/484726
http://www.kb.cert.org/vuls/id/465542


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
OpenSSL Project OpenSSL 0.9.6m ¹Ì¸¸
OpenSSL Project OpenSSL 0.9.7d ¹Ì¸¸
Linux Any version
Unix Any version
Microsoft Windows Any version
Cisco Systems »çÀÇ Cisco Á¦Ç°µé
ÇØ°áÃ¥ ´ÙÀ½ OpenSSL º¸¾È ±Ç°í¾È [2004³â 3¿ù 17ÀÏÀÚ]¸¦ ÂüÁ¶ÇÏ¿© OpenSSLÀÇ °¡Àå ÃֽйöÀü(0.9.6m ȤÀº 0.9.7d ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.openssl.org/news/secadv_20040317.txt

CiscoÀÇ °æ¿ì:
´ÙÀ½ Cisco º¸¾È ±Ç°í¾È ¹®¼­ ID: 49898À» ÂüÁ¶ÇÏ¿© ¿µÇâÀ» ¹Þ´Â Àåºñ¿¡ ´ëÇÑ °¡Àå ÃÖ½ÅÀÇ ¼ÒÇÁÆ®¿þ¾î ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml

Red Hat Linux 9ÀÇ °æ¿ì:
´ÙÀ½ Red Hat º¸¾È ±Ç°í¾È RHSA-2004:121-01À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ openssl ÆÐŰÁö(0.9.7a-20.2 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.linuxsecurity.com/content/view/105849/170/

Mandrake LinuxÀÇ °æ¿ì:
´ÙÀ½ MandrakeSoft º¸¾È ±Ç°í¾È MDKSA-2004:023:opensslÀ» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ openssl ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.mandriva.com/en/support/security/advisories/

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE º¸¾È °øÁö SuSE-SA:2004:007À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ openssl ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.suse.com/support/security/advisories/2004_07_openssl.html

±âŸ:
ÇØ´ç Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵å ȤÀº ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù. ȤÀº ÀÌ ¹®¼­ÀÇ "ÂüÁ¶ »çÀÌÆ®" ¶õ¿¡ ÀÖ´Â CERT Vulnerability Note VU#288574, VU#484726, ±×¸®°í VU#465542¸¦ ÂüÁ¶ÇÑ´Ù.
°ü·Ã URL CVE-2004-0079,CVE-2004-0081,CVE-2004-0112 (CVE)
°ü·Ã URL 9899 (SecurityFocus)
°ü·Ã URL 15505,15508,15509 (ISS)