Ãë¾àÁ¡ID |
22247 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç À¥ ¼¹ö´Â 0.9.6m ȤÀº 0.9.7d º¸´Ù ´õ ¿À·¡µÈ OpenSSL ¹öÀüÀ» °¡µ¿Çϰí ÀÖ´Ù. ¹ß°ßµÈ ¹öÀü¿¡ ÀÖ´Â ¼ö °³ÀÇ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â È£½ºÆ®¿¡ ´ëÇØ ¼ºñ½º °ÅºÎ¸¦ ÀÏÀ¸Å³ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. OpenSSLÀº SSL (Secure Sockets Layer) ±×¸®°í TLS (Transport Layer Security) ÇÁ·ÎÅäÄݵéÀÇ °ø°³ ¼Ò½º ±¸ÇöÀÌ´Ù. ´ÙÀ½°ú °°Àº OpenSSL¿¡ ¿µÇâÀ» ¹ÌÄ¡´Â ¼¼ °¡ÁöÀÇ Ãë¾àÁ¡µéÀÌ º¸°íµÇ¾î ÀÖ´Ù:
1. ù¹øÂ° Ãë¾àÁ¡Àº SSL/TLS Á¢¼Ó(handshake) ±³È¯ ½Ã °ø°ÝÀڵ鿡 ÀÇÇØ ÀÌ¿ë´çÇÒ ¼ö ÀÖ´Â NULL Æ÷ÀÎÅÍ ÇÒ´çÀÌ´Ù. ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ CVE ÇÒ´ç ¸íÀº CVE-2004-0079ÀÌ´Ù. 0.9.6c¿¡¼ 0.9.6k±îÁö ±×¸®°í 0.9.7a¿¡¼ 0.9.7c ±îÁöÀÇ ¹öÀüµéÀº Ãë¾àÇÏ´Ù. 2. µÎ¹øÂ° Ãë¾àÁ¡µµ SSL/TLS Á¢¼Ó(handshake) ½Ã µµ¿ëµÉ ¼ö ÀÖ´Ù. ÀÌ °æ¿ì¿¡ À־ Kerberos ¾ÏÈ£È ¸ðµâ(ciphersuite)µéÀÌ »ç¿ëµÇ°í ÀÖÀ» ¶§·Î¸¸ ÇÑÁ¤µÇ¾î Áø´Ù. ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ CVE ÇÒ´ç ¸íÀº CVE-2004-0112ÀÌ´Ù. 0.9.7a, 0.9.7b, ±×¸®°í 0.9.7c ¹öÀüµéÀº Ãë¾àÇÏ´Ù. 3. ¼¼¹øÂ° ¼ºñ½º °ÅºÎ Ãë¾àÁ¡Àº 0.9.6¿¡ ¿µÇâÀ» ¹ÌÄ¡´Â °ÍÀ¸·Î 0.9.6d¿¡¼ ±³Á¤µÇ¾ú´Ù. ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ CVE ÇÒ´ç ¸íÀº CVE-2004-0081ÀÌ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç FTP ¼¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.kb.cert.org/vuls/id/288574 http://www.kb.cert.org/vuls/id/484726 http://www.kb.cert.org/vuls/id/465542
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: OpenSSL Project OpenSSL 0.9.6m ¹Ì¸¸ OpenSSL Project OpenSSL 0.9.7d ¹Ì¸¸ Linux Any version Unix Any version Microsoft Windows Any version Cisco Systems »çÀÇ Cisco Á¦Ç°µé |
ÇØ°áÃ¥ |
´ÙÀ½ OpenSSL º¸¾È ±Ç°í¾È [2004³â 3¿ù 17ÀÏÀÚ]¸¦ ÂüÁ¶ÇÏ¿© OpenSSLÀÇ °¡Àå ÃֽйöÀü(0.9.6m ȤÀº 0.9.7d ȤÀº ÀÌÈÄ)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.openssl.org/news/secadv_20040317.txt
CiscoÀÇ °æ¿ì: ´ÙÀ½ Cisco º¸¾È ±Ç°í¾È ¹®¼ ID: 49898À» ÂüÁ¶ÇÏ¿© ¿µÇâÀ» ¹Þ´Â Àåºñ¿¡ ´ëÇÑ °¡Àå ÃÖ½ÅÀÇ ¼ÒÇÁÆ®¿þ¾î ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.cisco.com/warp/public/707/cisco-sa-20040317-openssl.shtml
Red Hat Linux 9ÀÇ °æ¿ì: ´ÙÀ½ Red Hat º¸¾È ±Ç°í¾È RHSA-2004:121-01À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ openssl ÆÐŰÁö(0.9.7a-20.2 ȤÀº ÀÌÈÄ)·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.linuxsecurity.com/content/view/105849/170/
Mandrake LinuxÀÇ °æ¿ì: ´ÙÀ½ MandrakeSoft º¸¾È ±Ç°í¾È MDKSA-2004:023:opensslÀ» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ openssl ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.mandriva.com/en/support/security/advisories/
SuSE LinuxÀÇ °æ¿ì: ´ÙÀ½ SuSE º¸¾È °øÁö SuSE-SA:2004:007À» ÂüÁ¶ÇÏ¿© °¡Àå ÃÖ½ÅÀÇ openssl ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.suse.com/support/security/advisories/2004_07_openssl.html
±âŸ: ÇØ´ç Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵å ȤÀº ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù. ȤÀº ÀÌ ¹®¼ÀÇ "ÂüÁ¶ »çÀÌÆ®" ¶õ¿¡ ÀÖ´Â CERT Vulnerability Note VU#288574, VU#484726, ±×¸®°í VU#465542¸¦ ÂüÁ¶ÇÑ´Ù. |
°ü·Ã URL |
CVE-2004-0079,CVE-2004-0081,CVE-2004-0112 (CVE) |
°ü·Ã URL |
9899 (SecurityFocus) |
°ü·Ã URL |
15505,15508,15509 (ISS) |
|