English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14201
À§Çèµµ 30
Æ÷Æ® 22
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù LSC
»ó¼¼¼³¸í ¿ø°Ý ½Ã½ºÅÛ¿¡´Â OpenSSL security updateÀÎ RHSA-2015-1072°¡ ÆÐÄ¡µÇ¾î ÀÖÁö ¾Ê´Ù. ÆÐÄ¡ Àü OpenSSLÀº DH Å° ±³È¯ ¹æ½Ä¿¡ ¿À·ù°¡ Á¸ÀçÇÑ´Ù. ÀÌ·Î ÀÎÇØ °ø°ÝÀÚ´Â Å°¸¦ ±³È¯ÇÏ´Â µ¿¾È 512ºñÆ®ÀÇ ¾àÇÑ ¾ÏÈ£ Å°¸¦ »ç¿ëÇÏ°Ô ÇÏ¿© ¸ðµç Æ®·¡ÇÈÀ» º¹È£È­ÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ¿ø°ÝÁö ¼­¹öÀÇ OpenSSL RPM ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
https://rhn.redhat.com/errata/RHSA-2015-1072.html
https://access.redhat.com/articles/1456263

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Red Hat Enterprise Linux Server (v. 6)
Red Hat Enterprise Linux Server (v. 7)
ÇØ°áÃ¥ ´ÙÀ½ ÀýÂ÷¿¡ µû¶ó ¿µÇâ¹Þ´Â ÆÐÅ°Áö¸¦ ¾÷µ¥ÀÌÆ® ÇÑ´Ù.
Applications -> System Tools -> Software Update

¶Ç´Â Ä¿¸Çµå¶óÀο¡¼­ ´ÙÀ½°ú °°ÀÌ OS¸¦ ¾÷µ¥ÀÌÆ® ÇÑ´Ù.
# yum update

OpenSSL ÆÐÅ°Áö ¼³Ä¡¸¦ À§Çؼ­ ´ÙÀ½°ú °°Àº ¸í·É¾î¸¦ »ç¿ëÇÑ´Ù.
# yum install openssl
°ü·Ã URL CVE-2015-4000 (CVE)
°ü·Ã URL 74733 (SecurityFocus)
°ü·Ã URL (ISS)